Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
A74lw30K2g.exe

Overview

General Information

Sample name:A74lw30K2g.exe
renamed because original name is a hash value
Original sample name:80efe3fa59592ab4d895db396ced8d10.exe
Analysis ID:1589403
MD5:80efe3fa59592ab4d895db396ced8d10
SHA1:0a35c3b26b86188908cd3d60db68c43fa211f4b0
SHA256:69e0e00babc6365144a98c2866353ef973b7dfe69ae37068f807d4b12c017161
Tags:exeValleyRATuser-abuse_ch
Infos:

Detection

GhostRat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected GhostRat
AI detected suspicious sample
Contains functionality to capture and log keystrokes
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Creates an autostart registry key pointing to binary in C:\Windows
Found evasive API chain (may stop execution after checking mutex)
Found stalling execution ending in API Sleep call
Sample is not signed and drops a device driver
Sigma detected: Potentially Suspicious Malware Callback Communication
Tries to detect sandboxes / dynamic malware analysis system (QueryWinSAT)
AV process strings found (often used to terminate AV products)
Abnormal high CPU Usage
Checks for available system drives (often done to infect USB drives)
Contains functionality for read data from the clipboard
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to clear windows event logs (to hide its activities)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to enumerate process and check for explorer.exe or svchost.exe (often used for thread injection)
Contains functionality to modify clipboard data
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the clipboard data
Contains functionality to record screenshots
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a DirectInput object (often for capturing keystrokes)
Creates driver files
Detected non-DNS traffic on DNS port
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found decision node followed by non-executed suspicious APIs
Found evasive API chain checking for process token information
Installs a global mouse hook
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Sigma detected: CurrentVersion Autorun Keys Modification
Stores large binary data to the registry

Classification

  • System is w10x64
  • A74lw30K2g.exe (PID: 7496 cmdline: "C:\Users\user\Desktop\A74lw30K2g.exe" MD5: 80EFE3FA59592AB4D895DB396CED8D10)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
A74lw30K2g.exeJoeSecurity_GhostRatYara detected GhostRatJoe Security
    SourceRuleDescriptionAuthorStrings
    Process Memory Space: A74lw30K2g.exe PID: 7496JoeSecurity_GhostRatYara detected GhostRatJoe Security
      SourceRuleDescriptionAuthorStrings
      0.0.A74lw30K2g.exe.7ff6297d0000.0.unpackJoeSecurity_GhostRatYara detected GhostRatJoe Security
        0.2.A74lw30K2g.exe.7ff6297d0000.8.unpackJoeSecurity_GhostRatYara detected GhostRatJoe Security

          System Summary

          barindex
          Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 192.238.132.117, DestinationIsIpv6: false, DestinationPort: 4433, EventID: 3, Image: C:\Users\user\Desktop\A74lw30K2g.exe, Initiated: true, ProcessId: 7496, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49730
          Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: , EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\A74lw30K2g.exe, ProcessId: 7496, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CleanTempTrash
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2025-01-12T08:32:08.202281+010020528751A Network Trojan was detected192.168.2.449730192.238.132.1174433TCP
          2025-01-12T08:33:11.269672+010020528751A Network Trojan was detected192.168.2.449730192.238.132.1174433TCP
          2025-01-12T08:34:45.059992+010020528751A Network Trojan was detected192.168.2.461740192.238.132.1174433TCP
          2025-01-12T08:35:49.021455+010020528751A Network Trojan was detected192.168.2.461743192.238.132.11710443TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: A74lw30K2g.exeReversingLabs: Detection: 75%
          Source: A74lw30K2g.exeVirustotal: Detection: 70%Perma Link
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
          Source: A74lw30K2g.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: z:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: x:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: v:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: t:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: r:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: p:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: n:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: l:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: j:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: h:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: f:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: b:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: y:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: w:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: u:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: s:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: q:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: o:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: m:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: k:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: i:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: g:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: e:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile opened: [:Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018002262C FindFirstFileExW,0_3_000000018002262C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DF410 GetLastInputInfo,GetTickCount,wsprintfW,GetForegroundWindow,GetWindowTextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,SHGetFolderPathW,lstrcatW,CreateFileW,lstrlenW,WriteFile,CloseHandle,FindFirstFileW,FindClose,_invalid_parameter_noinfo_noreturn,0_2_00007FF6297DF410
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF629803EF0 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF629803EF0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:49730 -> 192.238.132.117:4433
          Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:61740 -> 192.238.132.117:4433
          Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:61743 -> 192.238.132.117:10443
          Source: global trafficTCP traffic: 192.168.2.4:61472 -> 1.1.1.1:53
          Source: Joe Sandbox ViewASN Name: LEASEWEB-USA-LAX-11US LEASEWEB-USA-LAX-11US
          Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D3B00 select,recv,timeGetTime,0_2_00007FF6297D3B00
          Source: global trafficDNS traffic detected: DNS query: huazai789.top

          Key, Mouse, Clipboard, Microphone and Screen Capturing

          barindex
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: [esc]0_2_00007FF6297DADB0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297E0E20 _invalid_parameter_noinfo_noreturn,lstrlenW,Sleep,OpenClipboard,GetClipboardData,GlobalLock,GlobalUnlock,CloseClipboard,CloseClipboard,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,CloseClipboard,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6297E0E20
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297E0E20 _invalid_parameter_noinfo_noreturn,lstrlenW,Sleep,OpenClipboard,GetClipboardData,GlobalLock,GlobalUnlock,CloseClipboard,CloseClipboard,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,CloseClipboard,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6297E0E20
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297E0E20 _invalid_parameter_noinfo_noreturn,lstrlenW,Sleep,OpenClipboard,GetClipboardData,GlobalLock,GlobalUnlock,CloseClipboard,CloseClipboard,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,CloseClipboard,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6297E0E20
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DFD10 GetVersion,GetDesktopWindow,GetDC,CreateCompatibleDC,GetDC,GetDeviceCaps,GetDeviceCaps,ReleaseDC,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,CreateCompatibleBitmap,SelectObject,SetStretchBltMode,GetSystemMetrics,GetSystemMetrics,StretchBlt,GetDIBits,DeleteObject,DeleteObject,ReleaseDC,DeleteObject,DeleteObject,ReleaseDC,_invalid_parameter_noinfo_noreturn,0_2_00007FF6297DFD10
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D7250 MultiByteToWideChar,MultiByteToWideChar,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,CreateMutexExW,GetLastError,Sleep,CreateMutexW,GetLastError,lstrlenW,lstrcmpW,SleepEx,GetModuleHandleW,GetConsoleWindow,SHGetFolderPathW,lstrcatW,CreateMutexW,WaitForSingleObject,CreateFileW,GetFileSize,CloseHandle,DeleteFileW,ReleaseMutex,DirectInput8Create,GetTickCount,GetKeyState,0_2_00007FF6297D7250
          Source: C:\Users\user\Desktop\A74lw30K2g.exeWindows user hook set: 0 mouse low level C:\Windows\SYSTEM32\DINPUT8.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeProcess Stats: CPU usage > 49%
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EC2E0: wsprintfW,CreateFileW,DeviceIoControl,DeviceIoControl,DeviceIoControl,DeviceIoControl,CloseHandle,CloseHandle,0_2_00007FF6297EC2E0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DE4EE GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF6297DE4EE
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DE46D GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF6297DE46D
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DE3E9 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,CloseHandle,0_2_00007FF6297DE3E9
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile created: C:\ProgramData\kernelquick.sysJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800241140_3_0000000180024114
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800181DC0_3_00000001800181DC
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180012A040_3_0000000180012A04
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180026A140_3_0000000180026A14
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180011A3C0_3_0000000180011A3C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800192A80_3_00000001800192A8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800212CC0_3_00000001800212CC
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180016AF00_3_0000000180016AF0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018001630C0_3_000000018001630C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018001B4200_3_000000018001B420
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180011C400_3_0000000180011C40
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800124F80_3_00000001800124F8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018001CCFC0_3_000000018001CCFC
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180019DBC0_3_0000000180019DBC
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800036000_3_0000000180003600
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018002262C0_3_000000018002262C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180011E440_3_0000000180011E44
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800156600_3_0000000180015660
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018001973C0_3_000000018001973C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018002579C0_3_000000018002579C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F00_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D72500_2_00007FF6297D7250
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D79E00_2_00007FF6297D79E0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EB5000_2_00007FF6297EB500
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D15000_2_00007FF6297D1500
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DFD100_2_00007FF6297DFD10
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F8C100_2_00007FF6297F8C10
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DF4100_2_00007FF6297DF410
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DCD400_2_00007FF6297DCD40
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EAD800_2_00007FF6297EAD80
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EA5A00_2_00007FF6297EA5A0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF629801DA80_2_00007FF629801DA8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D80400_2_00007FF6297D8040
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FD3200_2_00007FF6297FD320
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D93200_2_00007FF6297D9320
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297E92500_2_00007FF6297E9250
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FF21C0_2_00007FF6297FF21C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F62280_2_00007FF6297F6228
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF62980714C0_2_00007FF62980714C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F51680_2_00007FF6297F5168
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FA4F80_2_00007FF6297FA4F8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FC51C0_2_00007FF6297FC51C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF629805D340_2_00007FF629805D34
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FFD300_2_00007FF6297FFD30
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FAC800_2_00007FF6297FAC80
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DB4100_2_00007FF6297DB410
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DD4100_2_00007FF6297DD410
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F73400_2_00007FF6297F7340
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FB3500_2_00007FF6297FB350
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F536C0_2_00007FF6297F536C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297E2EC00_2_00007FF6297E2EC0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF629803EF00_2_00007FF629803EF0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D2E500_2_00007FF6297D2E50
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297FF6B00_2_00007FF6297FF6B0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F4D580_2_00007FF6297F4D58
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F55780_2_00007FF6297F5578
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6298085840_2_00007FF629808584
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DADB00_2_00007FF6297DADB0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F65AC0_2_00007FF6297F65AC
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297E78F00_2_00007FF6297E78F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297E09000_2_00007FF6297E0900
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6298020240_2_00007FF629802024
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6298027440_2_00007FF629802744
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F6F3C0_2_00007FF6297F6F3C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6298037600_2_00007FF629803760
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F4F5C0_2_00007FF6297F4F5C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F577C0_2_00007FF6297F577C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D97A00_2_00007FF6297D97A0
          Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@1/1@1/1
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EB500 SleepEx,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,AllocateAndInitializeSid,CheckTokenMembership,FreeSid,RegOpenKeyExW,RegDeleteValueW,RegSetValueExW,RegCloseKey,SleepEx,CreateEventA,Sleep,Sleep,CloseHandle,_invalid_parameter_noinfo_noreturn,IsDebuggerPresent,LoadLibraryW,GetProcAddress,FreeLibrary,GetLocalTime,wsprintfW,CreateFileW,FreeLibrary,GetCurrentThreadId,GetCurrentProcessId,GetCurrentProcess,CloseHandle,FreeLibrary,0_2_00007FF6297EB500
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D9320 GetSystemDirectoryA,CreateProcessA,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,GetModuleFileNameA,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,ResumeThread,0_2_00007FF6297D9320
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DE4EE GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF6297DE4EE
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DE46D GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF6297DE46D
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DE3E9 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,CloseHandle,0_2_00007FF6297DE3E9
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeMutant created: \Sessions\1\BaseNamedObjects\????
          Source: A74lw30K2g.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\A74lw30K2g.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: A74lw30K2g.exeReversingLabs: Detection: 75%
          Source: A74lw30K2g.exeVirustotal: Detection: 70%
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: dxgi.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: dinput8.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: inputhost.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: coremessaging.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: propsys.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: coreuicomponents.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: napinsp.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: pnrpnsp.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: wshbth.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: nlaapi.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: winrnr.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: resourcepolicyclient.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: devenum.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: devobj.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: msdmo.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeSection loaded: windowscodecs.dllJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62BE5D10-60EB-11d0-BD3B-00A0C911CE86}\InprocServer32Jump to behavior
          Source: A74lw30K2g.exeStatic PE information: Image base 0x140000000 > 0x60000000
          Source: A74lw30K2g.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
          Source: A74lw30K2g.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0

          Persistence and Installation Behavior

          barindex
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile created: C:\ProgramData\kernelquick.sysJump to behavior

          Boot Survival

          barindex
          Source: C:\Users\user\Desktop\A74lw30K2g.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run CleanTempTrashJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run CleanTempTrashJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run CleanTempTrashJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DE36A OpenEventLogW,ClearEventLogW,CloseEventLog,0_2_00007FF6297DE36A
          Source: C:\Users\user\Desktop\A74lw30K2g.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE VenkernalData_infoJump to behavior

          Malware Analysis System Evasion

          barindex
          Source: C:\Users\user\Desktop\A74lw30K2g.exeEvasive API call chain: CreateMutex,DecisionNodes,Sleepgraph_0-21452
          Source: C:\Users\user\Desktop\A74lw30K2g.exeStalling execution: Execution stalls by calling Sleepgraph_0-21758
          Source: C:\Users\user\Desktop\A74lw30K2g.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05DF8D13-C355-47F4-A11E-851B338CEFB8}Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeWindow / User API: threadDelayed 1448Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeWindow / User API: threadDelayed 3393Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeWindow / User API: threadDelayed 4599Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeDecision node followed by non-executed suspicious API: DecisionNode, Non Executed (send or recv or WinExec)graph_0-21483
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-21390
          Source: C:\Users\user\Desktop\A74lw30K2g.exe TID: 7556Thread sleep count: 1448 > 30Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exe TID: 7556Thread sleep time: -1448000s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exe TID: 7576Thread sleep count: 3393 > 30Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exe TID: 7576Thread sleep time: -33930s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exe TID: 7556Thread sleep count: 4599 > 30Jump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exe TID: 7556Thread sleep time: -4599000s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018002262C FindFirstFileExW,0_3_000000018002262C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DF410 GetLastInputInfo,GetTickCount,wsprintfW,GetForegroundWindow,GetWindowTextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,SHGetFolderPathW,lstrcatW,CreateFileW,lstrlenW,WriteFile,CloseHandle,FindFirstFileW,FindClose,_invalid_parameter_noinfo_noreturn,0_2_00007FF6297DF410
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF629803EF0 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF629803EF0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: A74lw30K2g.exe, 00000000.00000002.4141751919.0000020870307000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
          Source: C:\Users\user\Desktop\A74lw30K2g.exeProcess information queried: ProcessInformationJump to behavior
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018000C160 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_3_000000018000C160
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EC70C GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF6297EC70C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D62F0 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_00000001800239B8 GetProcessHeap,0_3_00000001800239B8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018000C160 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_3_000000018000C160
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018000C32C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_3_000000018000C32C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_0000000180013728 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_3_0000000180013728
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EBCD0 SetUnhandledExceptionFilter,GetConsoleWindow,ShowWindow,GetCurrentThreadId,PostThreadMessageA,GetInputState,CreateThread,WaitForSingleObject,CloseHandle,Sleep,0_2_00007FF6297EBCD0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EB500 SleepEx,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,AllocateAndInitializeSid,CheckTokenMembership,FreeSid,RegOpenKeyExW,RegDeleteValueW,RegSetValueExW,RegCloseKey,SleepEx,CreateEventA,Sleep,Sleep,CloseHandle,_invalid_parameter_noinfo_noreturn,IsDebuggerPresent,LoadLibraryW,GetProcAddress,FreeLibrary,GetLocalTime,wsprintfW,CreateFileW,FreeLibrary,GetCurrentThreadId,GetCurrentProcessId,GetCurrentProcess,CloseHandle,FreeLibrary,0_2_00007FF6297EB500
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297F3A6C RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6297F3A6C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EE6F4 SetUnhandledExceptionFilter,0_2_00007FF6297EE6F4
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EE54C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6297EE54C
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EE8E0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF6297EE8E0

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DCD40 GetSystemDirectoryA,CreateProcessA,VirtualAllocEx,WriteProcessMemory,GetThreadContext,SetThreadContext,ResumeThread,0_2_00007FF6297DCD40
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297D9320 GetSystemDirectoryA,CreateProcessA,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,GetModuleFileNameA,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,ResumeThread,0_2_00007FF6297D9320
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetSystemDirectoryA,CreateProcessA,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,GetModuleFileNameA,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,ResumeThread, Windows\System32\svchost.exe0_2_00007FF6297D9320
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297EB500 SleepEx,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,AllocateAndInitializeSid,CheckTokenMembership,FreeSid,RegOpenKeyExW,RegDeleteValueW,RegSetValueExW,RegCloseKey,SleepEx,CreateEventA,Sleep,Sleep,CloseHandle,_invalid_parameter_noinfo_noreturn,IsDebuggerPresent,LoadLibraryW,GetProcAddress,FreeLibrary,GetLocalTime,wsprintfW,CreateFileW,FreeLibrary,GetCurrentThreadId,GetCurrentProcessId,GetCurrentProcess,CloseHandle,FreeLibrary,0_2_00007FF6297EB500
          Source: A74lw30K2g.exe, 00000000.00000003.3694551319.0000020870389000.00000004.00000020.00020000.00000000.sdmp, A74lw30K2g.exe, 00000000.00000002.4141751919.0000020870389000.00000004.00000020.00020000.00000000.sdmp, A74lw30K2g.exe, 00000000.00000003.3273626053.0000020870389000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 0 minProgram Manager
          Source: A74lw30K2g.exe, 00000000.00000003.2568805479.000002087037E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018002A660 cpuid 0_3_000000018002A660
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_3_0000000180027808
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,0_3_00000001800278B8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_3_00000001800279EC
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,0_3_0000000180027300
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,0_3_000000018001D3B4
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,0_3_00000001800273D0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_3_0000000180027468
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,0_3_00000001800276B0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,0_3_000000018001D748
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_3_0000000180026FA4
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF6297D62F0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,0_2_00007FF629807B08
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,0_2_00007FF629807A38
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,0_2_00007FF629800D10
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF629807BA0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF6298076DC
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,0_2_00007FF629807DE8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF629808124
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: EnumSystemLocalesW,0_2_00007FF629800838
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,0_2_00007FF629807FF0
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF629807F40
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_3_000000018000C064 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_3_000000018000C064
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF629801DA8 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF629801DA8
          Source: C:\Users\user\Desktop\A74lw30K2g.exeCode function: 0_2_00007FF6297DFD10 GetVersion,GetDesktopWindow,GetDC,CreateCompatibleDC,GetDC,GetDeviceCaps,GetDeviceCaps,ReleaseDC,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,CreateCompatibleBitmap,SelectObject,SetStretchBltMode,GetSystemMetrics,GetSystemMetrics,StretchBlt,GetDIBits,DeleteObject,DeleteObject,ReleaseDC,DeleteObject,DeleteObject,ReleaseDC,_invalid_parameter_noinfo_noreturn,0_2_00007FF6297DFD10
          Source: A74lw30K2g.exe, 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmp, A74lw30K2g.exe, 00000000.00000000.1683836257.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: KSafeTray.exe

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: A74lw30K2g.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.A74lw30K2g.exe.7ff6297d0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.A74lw30K2g.exe.7ff6297d0000.8.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: Process Memory Space: A74lw30K2g.exe PID: 7496, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: A74lw30K2g.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.A74lw30K2g.exe.7ff6297d0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.A74lw30K2g.exe.7ff6297d0000.8.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: Process Memory Space: A74lw30K2g.exe PID: 7496, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire Infrastructure1
          Replication Through Removable Media
          12
          Native API
          1
          DLL Side-Loading
          1
          DLL Side-Loading
          1
          DLL Side-Loading
          121
          Input Capture
          2
          System Time Discovery
          Remote Services1
          Archive Collected Data
          1
          Ingress Tool Transfer
          Exfiltration Over Other Network Medium1
          System Shutdown/Reboot
          CredentialsDomainsDefault AccountsScheduled Task/Job1
          Windows Service
          1
          Access Token Manipulation
          1
          Modify Registry
          LSASS Memory11
          Peripheral Device Discovery
          Remote Desktop Protocol1
          Screen Capture
          1
          Encrypted Channel
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAt11
          Registry Run Keys / Startup Folder
          1
          Windows Service
          1
          Virtualization/Sandbox Evasion
          Security Account Manager2
          File and Directory Discovery
          SMB/Windows Admin Shares121
          Input Capture
          1
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook211
          Process Injection
          1
          Access Token Manipulation
          NTDS26
          System Information Discovery
          Distributed Component Object Model3
          Clipboard Data
          1
          Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script11
          Registry Run Keys / Startup Folder
          211
          Process Injection
          LSA Secrets151
          Security Software Discovery
          SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
          Indicator Removal
          Cached Domain Credentials1
          Virtualization/Sandbox Evasion
          VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync3
          Process Discovery
          Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
          Application Window Discovery
          Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          A74lw30K2g.exe75%ReversingLabsWin64.Backdoor.GhostRAT
          A74lw30K2g.exe70%VirustotalBrowse
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          huazai789.top
          192.238.132.117
          truetrue
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            192.238.132.117
            huazai789.topUnited States
            395954LEASEWEB-USA-LAX-11UStrue
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1589403
            Start date and time:2025-01-12 08:31:06 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 7m 29s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:5
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:A74lw30K2g.exe
            renamed because original name is a hash value
            Original Sample Name:80efe3fa59592ab4d895db396ced8d10.exe
            Detection:MAL
            Classification:mal100.troj.spyw.evad.winEXE@1/1@1/1
            EGA Information:
            • Successful, ratio: 100%
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 58
            • Number of non-executed functions: 187
            Cookbook Comments:
            • Found application associated with file extension: .exe
            • Override analysis time to 240000 for current running targets taking high CPU consumption
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
            • Excluded IPs from analysis (whitelisted): 20.12.23.50, 13.107.246.45
            • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtEnumerateKey calls found.
            • Report size getting too big, too many NtOpenKeyEx calls found.
            TimeTypeDescription
            02:32:34API Interceptor6515166x Sleep call for process: A74lw30K2g.exe modified
            No context
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            LEASEWEB-USA-LAX-11UShttps://199.188.109.181Get hashmaliciousUnknownBrowse
            • 192.238.129.52
            Fantazy.mips.elfGet hashmaliciousUnknownBrowse
            • 23.87.149.48
            arm7.elfGet hashmaliciousMiraiBrowse
            • 23.86.58.197
            sh4.elfGet hashmaliciousMiraiBrowse
            • 23.87.103.160
            6.elfGet hashmaliciousUnknownBrowse
            • 23.86.11.148
            WgnsGjhA3P.exeGet hashmaliciousGhostRatBrowse
            • 192.238.134.52
            WgnsGjhA3P.exeGet hashmaliciousGhostRatBrowse
            • 192.238.134.52
            Mes_Drivers_3.0.4.exeGet hashmaliciousUnknownBrowse
            • 23.83.76.85
            fuckunix.sh4.elfGet hashmaliciousMiraiBrowse
            • 23.85.171.227
            armv7l.elfGet hashmaliciousUnknownBrowse
            • 23.83.17.216
            No context
            No context
            Process:C:\Users\user\Desktop\A74lw30K2g.exe
            File Type:data
            Category:dropped
            Size (bytes):30
            Entropy (8bit):2.6616157143988106
            Encrypted:false
            SSDEEP:3:tblM6lEjln:tbhEZn
            MD5:AE50B29A0B8DCC411F24F1863B0EAFDE
            SHA1:D415A55627B1ADED8E4B2CBBA402F816B0461155
            SHA-256:6B4BBBCE480FBC50D39A8EC4B72CDB7D781B151921E063DD899FD9B736ADCF68
            SHA-512:D9A9BA42D99BE32D26667060BE1D523DCD20EAFA187A67F7919002CC6DA349FD058053C9C6F721D6FDB730EA02FBAA3013E51C0C653368BD6B3F57A4C0FCABA8
            Malicious:true
            Reputation:moderate, very likely benign file
            Preview:C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.
            File type:PE32+ executable (GUI) x86-64, for MS Windows
            Entropy (8bit):6.060222083682462
            TrID:
            • Win64 Executable GUI (202006/5) 92.65%
            • Win64 Executable (generic) (12005/4) 5.51%
            • Generic Win/DOS Executable (2004/3) 0.92%
            • DOS Executable Generic (2002/1) 0.92%
            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
            File name:A74lw30K2g.exe
            File size:389'632 bytes
            MD5:80efe3fa59592ab4d895db396ced8d10
            SHA1:0a35c3b26b86188908cd3d60db68c43fa211f4b0
            SHA256:69e0e00babc6365144a98c2866353ef973b7dfe69ae37068f807d4b12c017161
            SHA512:8a8d45c9e22d5f0f78057f2abcef3735877c609ef0f69e41c20033d3c5d165c907d73a6cc5b1a23dd316c5b842d82ffb48e4c47e1dfe6a768c72e07a1f556a35
            SSDEEP:6144:tKtL0RSVgMoEao8ItdKwzBFdYmT+xmyiRLBVhLhkM:ItwSqEao8It4wlDCxmPfx
            TLSH:DA848E49F79405F8E5678138C9634916EBB27C6D03A09BDF33A4866A2F237D0AD3E711
            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........A...A...A.......D...............@.......@...Q(..K...Q(..S...Q(..........U.......X...A...m....)..S....)..@...RichA..........
            Icon Hash:90cececece8e8eb0
            Entrypoint:0x14001e13c
            Entrypoint Section:.text
            Digitally signed:false
            Imagebase:0x140000000
            Subsystem:windows gui
            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
            Time Stamp:0x677A4401 [Sun Jan 5 08:34:09 2025 UTC]
            TLS Callbacks:
            CLR (.Net) Version:
            OS Version Major:6
            OS Version Minor:0
            File Version Major:6
            File Version Minor:0
            Subsystem Version Major:6
            Subsystem Version Minor:0
            Import Hash:d7444b6dc7c8cddb50fba5269ad57bce
            Instruction
            dec eax
            sub esp, 28h
            call 00007F79851849E0h
            dec eax
            add esp, 28h
            jmp 00007F7985184237h
            int3
            int3
            dec eax
            sub esp, 28h
            dec ebp
            mov eax, dword ptr [ecx+38h]
            dec eax
            mov ecx, edx
            dec ecx
            mov edx, ecx
            call 00007F79851843D2h
            mov eax, 00000001h
            dec eax
            add esp, 28h
            ret
            int3
            int3
            int3
            inc eax
            push ebx
            inc ebp
            mov ebx, dword ptr [eax]
            dec eax
            mov ebx, edx
            inc ecx
            and ebx, FFFFFFF8h
            dec esp
            mov ecx, ecx
            inc ecx
            test byte ptr [eax], 00000004h
            dec esp
            mov edx, ecx
            je 00007F79851843D5h
            inc ecx
            mov eax, dword ptr [eax+08h]
            dec ebp
            arpl word ptr [eax+04h], dx
            neg eax
            dec esp
            add edx, ecx
            dec eax
            arpl ax, cx
            dec esp
            and edx, ecx
            dec ecx
            arpl bx, ax
            dec edx
            mov edx, dword ptr [eax+edx]
            dec eax
            mov eax, dword ptr [ebx+10h]
            mov ecx, dword ptr [eax+08h]
            dec eax
            mov eax, dword ptr [ebx+08h]
            test byte ptr [ecx+eax+03h], 0000000Fh
            je 00007F79851843CDh
            movzx eax, byte ptr [ecx+eax+03h]
            and eax, FFFFFFF0h
            dec esp
            add ecx, eax
            dec esp
            xor ecx, edx
            dec ecx
            mov ecx, ecx
            pop ebx
            jmp 00007F79851843DAh
            int3
            int3
            int3
            int3
            int3
            int3
            int3
            int3
            int3
            int3
            int3
            nop word ptr [eax+eax+00000000h]
            dec eax
            cmp ecx, dword ptr [00036E59h]
            jne 00007F79851843D2h
            dec eax
            rol ecx, 10h
            test cx, FFFFh
            jne 00007F79851843C3h
            ret
            dec eax
            ror ecx, 10h
            jmp 00007F7985184ADBh
            int3
            int3
            dec eax
            mov dword ptr [esp+00h], ebx
            NameVirtual AddressVirtual Size Is in Section
            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IMPORT0x523b00x104.rdata
            IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x600000x3420.pdata
            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
            IMAGE_DIRECTORY_ENTRY_BASERELOC0x640000xc80.reloc
            IMAGE_DIRECTORY_ENTRY_DEBUG0x4c7b00x38.rdata
            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
            IMAGE_DIRECTORY_ENTRY_TLS0x4c9800x28.rdata
            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x4c6700x140.rdata
            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IAT0x3f0000x918.rdata
            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
            .text0x10000x3dbf00x3dc00d3f6189e43bbd290b28f7518c02b76a1False0.5461593813259109data6.462564110280856IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            .rdata0x3f0000x1519e0x152009e26fd4c3ae6978d53ec06e02524102fFalse0.41498705621301774data4.93197088749888IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .data0x550000xaa6c0x7c008f65573ed32594cbde8ff9ccb2da7eb9False0.10631930443548387DOS executable (block device driver \377\3)1.5564681329279173IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
            .pdata0x600000x34200x360020b7b9769859dd90801ea597a1d992beFalse0.4626736111111111data5.517914471579984IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .reloc0x640000xc800xe00316f5780e4a2c74c1946985bacab1ae4False0.4916294642857143data5.228910762857474IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
            DLLImport
            KERNEL32.dllQueryDosDeviceW, WriteProcessMemory, GetCommandLineW, GetCurrentProcess, WriteFile, OutputDebugStringA, GetModuleFileNameW, GetProcessId, CreateMutexW, GetLocaleInfoW, LocalAlloc, CreateFileW, GetVersionExW, K32GetProcessImageFileNameW, GetSystemDirectoryW, ResumeThread, GetModuleHandleA, OpenProcess, GetVersion, GetLogicalDriveStringsW, CreateToolhelp32Snapshot, MultiByteToWideChar, Process32NextW, GetDiskFreeSpaceExW, GetSystemDirectoryA, LoadLibraryA, lstrcatW, GlobalAlloc, Process32FirstW, GlobalFree, GetSystemInfo, LoadLibraryW, GetLocalTime, VirtualProtectEx, GetThreadContext, GetProcAddress, VirtualAllocEx, LocalFree, ExitProcess, GetCurrentProcessId, GlobalMemoryStatusEx, CreateProcessW, GetModuleHandleW, FreeLibrary, GetConsoleWindow, lstrcpyW, CreateRemoteThread, CreateProcessA, SetThreadContext, GetModuleFileNameA, GetTickCount, lstrcmpW, GetDriveTypeW, GetExitCodeProcess, SetFilePointer, ReleaseMutex, GlobalSize, DeleteFileW, GlobalLock, GetFileSize, GlobalUnlock, FindFirstFileW, ExpandEnvironmentStringsW, FindClose, GetFileAttributesW, TerminateThread, VirtualProtect, IsBadReadPtr, CreateThread, IsDebuggerPresent, SetUnhandledExceptionFilter, WriteConsoleW, GetCurrentThreadId, GetConsoleMode, GetConsoleOutputCP, FlushFileBuffers, SetFilePointerEx, SetStdHandle, SetEnvironmentVariableW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetOEMCP, GetACP, IsValidCodePage, FindNextFileW, FindFirstFileExW, GetTimeZoneInformation, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, LCMapStringW, CompareStringW, FlsFree, FlsSetValue, GetStartupInfoW, CreateWaitableTimerW, SetWaitableTimer, TryEnterCriticalSection, WideCharToMultiByte, ResetEvent, CreateEventW, lstrlenW, CancelIo, GetNativeSystemInfo, SetLastError, lstrcmpiW, CreateEventA, CloseHandle, SetEvent, Sleep, HeapFree, WaitForSingleObject, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, EnterCriticalSection, HeapCreate, GetProcessHeap, DeleteCriticalSection, HeapDestroy, DecodePointer, HeapAlloc, HeapReAlloc, GetLastError, HeapSize, InitializeCriticalSectionEx, VirtualAlloc, VirtualFree, FlsGetValue, FlsAlloc, GetFileType, GetCommandLineA, GetStdHandle, VirtualQuery, GetModuleHandleExW, FreeLibraryAndExitThread, ExitThread, LoadLibraryExW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, RtlPcToFileHeader, RtlUnwindEx, lstrcpyA, CreateFileA, GetSystemDefaultLangID, DeviceIoControl, TerminateProcess, InitializeSListHead, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsProcessorFeaturePresent, UnhandledExceptionFilter, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, SleepConditionVariableSRW, WakeAllConditionVariable, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, GetCPInfo, LCMapStringEx, EncodePointer, CompareStringEx, GetStringTypeW, RaiseException, OutputDebugStringW, SwitchToThread
            USER32.dllMsgWaitForMultipleObjects, GetWindowTextW, wsprintfW, GetForegroundWindow, GetLastInputInfo, GetClipboardData, CloseClipboard, OpenClipboard, GetKeyState, ReleaseDC, GetDesktopWindow, SetClipboardData, ExitWindowsEx, EmptyClipboard, GetSystemMetrics, GetDC, GetInputState, PostThreadMessageA, TranslateMessage, DispatchMessageW, PeekMessageW, ShowWindow
            GDI32.dllCreateCompatibleBitmap, SelectObject, CreateDIBSection, SetDIBColorTable, CreateCompatibleDC, StretchBlt, GetDIBits, GetDeviceCaps, GetObjectW, SetStretchBltMode, DeleteObject, DeleteDC
            ADVAPI32.dllOpenProcessToken, RegQueryValueExW, AllocateAndInitializeSid, FreeSid, CheckTokenMembership, ClearEventLogW, CloseEventLog, OpenEventLogW, LookupPrivilegeValueW, AdjustTokenPrivileges, GetCurrentHwProfileW, RegCloseKey, RegQueryInfoKeyW, GetSidSubAuthorityCount, GetSidSubAuthority, RegEnumKeyExW, RegSetValueExW, RegOpenKeyExW, RegCreateKeyW, RegDeleteValueW, LookupAccountSidW, GetTokenInformation
            SHELL32.dllSHGetFolderPathW
            ole32.dllCreateStreamOnHGlobal, GetHGlobalFromStream, CoInitialize, CoUninitialize, CoCreateInstance
            OLEAUT32.dllSysFreeString
            WS2_32.dllWSASetLastError, WSAEventSelect, WSAResetEvent, WSAWaitForMultipleEvents, WSAEnumNetworkEvents, WSAGetLastError, WSACleanup, WSAIoctl, closesocket, WSACreateEvent, select, WSAStartup, send, socket, connect, recv, htons, setsockopt, inet_ntoa, WSACloseEvent, gethostbyname, gethostname, shutdown
            WINMM.dlltimeGetTime
            gdiplus.dllGdipCreateBitmapFromStream, GdipBitmapUnlockBits, GdipCloneImage, GdipAlloc, GdiplusShutdown, GdipDrawImageI, GdipCreateBitmapFromScan0, GdipCreateBitmapFromHBITMAP, GdipGetImageWidth, GdipGetImagePalette, GdipDeleteGraphics, GdipGetImageEncodersSize, GdipGetImageGraphicsContext, GdipFree, GdipGetImagePixelFormat, GdipDisposeImage, GdipSaveImageToStream, GdipBitmapLockBits, GdipGetImagePaletteSize, GdiplusStartup, GdipGetImageHeight, GdipGetImageEncoders
            dxgi.dllCreateDXGIFactory
            DINPUT8.dllDirectInput8Create
            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
            2025-01-12T08:32:08.202281+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.449730192.238.132.1174433TCP
            2025-01-12T08:33:11.269672+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.449730192.238.132.1174433TCP
            2025-01-12T08:34:45.059992+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.461740192.238.132.1174433TCP
            2025-01-12T08:35:49.021455+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.461743192.238.132.11710443TCP
            TimestampSource PortDest PortSource IPDest IP
            Jan 12, 2025 08:32:06.107074022 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:06.111850977 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:06.111954927 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:07.559760094 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:07.564892054 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:07.564959049 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:07.564989090 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:07.565016985 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.108464956 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.159501076 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.197230101 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.202214956 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.202253103 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.202280998 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.202286005 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.207123041 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865739107 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865791082 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865828991 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865864038 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865895033 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865926981 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865941048 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.865966082 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.865989923 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.865995884 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.866024971 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.866045952 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.866072893 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.868964911 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.869106054 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:08.873948097 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.873977900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.874006033 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.874207973 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.874234915 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:08.874267101 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194207907 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194268942 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194304943 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194322109 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.194341898 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194396019 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.194453955 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194489956 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194525003 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194545984 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.194557905 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194591999 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194622993 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.194628954 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.194685936 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.195219994 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.195255995 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.195288897 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.195297003 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.195353985 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.195391893 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.195425987 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.196090937 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.196135044 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.196141958 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.237637043 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.417604923 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417654037 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417695999 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417730093 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417752028 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.417766094 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417789936 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.417804003 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417851925 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417855978 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.417907953 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417943001 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417975903 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.417988062 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.418010950 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.418045998 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.418050051 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.418092966 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.418812990 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.418864965 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.418899059 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.418919086 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.418931007 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.418966055 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.418977976 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.419001102 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.419055939 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.419709921 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.419744015 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.419776917 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.419790030 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.419811964 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.419847012 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.419867039 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.419882059 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.419929028 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.420567036 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.420603037 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.420649052 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.640073061 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640113115 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640147924 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640199900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640207052 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.640235901 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640264988 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640270948 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.640315056 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.640400887 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640434027 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640465975 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640486956 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.640499115 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640532970 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640549898 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.640566111 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640600920 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.640619993 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.641073942 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641124964 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.641127110 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641160965 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641192913 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641216040 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.641227007 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641261101 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641295910 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641295910 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.641350985 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.641885996 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641920090 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641952991 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.641969919 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.641987085 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642019987 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642030954 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.642055035 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642087936 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642100096 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.642122030 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642154932 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642169952 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.642756939 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642811060 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.642847061 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642896891 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642930031 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642950058 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.642961979 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.642997026 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643021107 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.643028975 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643064022 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643084049 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.643098116 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643141031 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.643806934 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643858910 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643893003 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643907070 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.643927097 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643959999 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.643971920 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.643994093 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.644026995 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.644042015 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.644062042 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.644108057 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863171101 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863234997 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863270044 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863302946 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863368034 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863380909 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863419056 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863435030 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863471031 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863490105 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863523006 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863557100 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863573074 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863590002 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863624096 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863641977 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863656998 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863691092 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863708019 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863723040 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863758087 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863774061 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863791943 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863825083 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863847017 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.863862038 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863895893 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.863912106 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.864406109 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864439964 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864459038 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.864474058 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864506960 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864521980 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.864542007 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864576101 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864592075 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.864609957 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864643097 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864675999 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864698887 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.864708900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864722013 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.864742994 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864779949 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.864794016 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.865364075 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865397930 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865417957 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.865433931 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865467072 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865487099 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.865500927 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865533113 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865552902 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.865567923 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865601063 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865622044 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.865634918 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865668058 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865688086 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.865701914 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865736961 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.865750074 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.866202116 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866250992 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.866252899 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866295099 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866329908 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866353989 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.866363049 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866396904 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866409063 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.866430998 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866465092 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866486073 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.866498947 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866532087 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866554022 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.866564989 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866600037 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.866622925 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.867178917 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867230892 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867233038 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.867265940 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867300034 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867319107 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.867351055 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867383003 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867398024 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.867418051 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867450953 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867464066 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.867485046 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867517948 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867531061 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.867551088 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867585897 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.867598057 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.868043900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868094921 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868094921 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.868129969 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868163109 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868180037 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.868196964 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868228912 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868259907 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.868263006 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868297100 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868321896 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.868334055 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868369102 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:09.868381023 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:09.909498930 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086188078 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086242914 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086294889 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086316109 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086330891 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086380959 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086414099 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086419106 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086466074 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086474895 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086499929 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086568117 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086572886 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086601019 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086633921 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086659908 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086668015 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086715937 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086716890 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086750984 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086805105 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086807013 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086853981 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086889029 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086903095 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.086922884 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086956978 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086990118 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.086993933 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087024927 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087057114 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087058067 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087093115 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087105036 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087126017 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087160110 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087186098 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087192059 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087228060 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087240934 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087261915 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087295055 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087323904 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087352037 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087384939 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087434053 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087435007 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087503910 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087507010 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087541103 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087574005 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087600946 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087609053 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087642908 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087673903 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087676048 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087712049 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087748051 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087764978 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087769985 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087800980 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087821960 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087833881 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087869883 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.087869883 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.087918997 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088084936 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088135958 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088170052 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088186026 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088205099 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088238955 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088270903 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088273048 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088305950 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088326931 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088342905 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088378906 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088408947 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088413000 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088447094 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088469982 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088481903 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088515997 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088551044 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088552952 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088584900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088608027 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088620901 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088654995 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088686943 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088721037 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088735104 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088753939 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.088761091 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.088819027 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.092771053 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.092802048 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.092835903 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.092850924 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.092964888 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.092998981 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093019009 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093033075 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093065023 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093084097 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093099117 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093131065 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093148947 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093166113 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093198061 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093214035 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093231916 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093265057 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093274117 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093300104 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093334913 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093348980 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093477011 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093506098 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093530893 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093555927 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093590021 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093606949 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093662024 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093712091 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093722105 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093741894 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093775034 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093786955 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093813896 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093847990 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093879938 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.093910933 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.093991041 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094024897 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094043016 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094074011 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094079018 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094121933 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094130993 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094165087 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094172001 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094198942 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094217062 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094233036 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094264984 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094288111 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094299078 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094332933 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094356060 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094367027 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094399929 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094424963 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094434023 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094466925 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094482899 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094500065 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094562054 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094801903 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094835043 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094866991 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094871998 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094901085 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094947100 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.094954014 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.094980955 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095015049 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095031023 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.095048904 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095082998 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095115900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095136881 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.095151901 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095165968 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.095185995 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095220089 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.095233917 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.103781939 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.108633995 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.111536980 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.116383076 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176713943 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176763058 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176814079 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176814079 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.176847935 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176882982 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176896095 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.176915884 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176968098 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.176969051 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177004099 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177051067 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177057028 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177107096 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177141905 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177166939 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177175045 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177211046 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177228928 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177246094 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177278996 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177294016 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177309990 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177344084 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177360058 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177382946 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177414894 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177433968 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177450895 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177484035 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177501917 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.177522898 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177573919 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.177580118 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.222003937 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309243917 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309273958 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309324980 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309325933 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309362888 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309412956 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309413910 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309449911 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309498072 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309500933 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309537888 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309586048 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309587955 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309653997 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309686899 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309701920 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309722900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309753895 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309770107 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309789896 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309838057 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309839964 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309873104 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309923887 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.309923887 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.309977055 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310009003 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310024023 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310044050 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310077906 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310091019 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310117006 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310165882 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310168028 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310204983 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310252905 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310260057 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310332060 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310364962 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310379028 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310416937 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310450077 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310467958 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310486078 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310518980 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310533047 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310554981 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310606003 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310606003 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310657978 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310709000 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310709000 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310745001 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310776949 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310792923 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310811996 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310846090 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310862064 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310880899 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310914993 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310928106 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.310949087 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310981989 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.310993910 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311016083 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311048985 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311062098 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311104059 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311151028 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311153889 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311188936 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311220884 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311233997 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311255932 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311289072 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311304092 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311343908 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311378002 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311389923 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311413050 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311444044 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311458111 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311477900 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311527967 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311532021 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311583042 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311615944 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311634064 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311650991 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311683893 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311697960 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311719894 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311768055 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311770916 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311803102 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311836004 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311849117 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311868906 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311903000 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311917067 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.311954975 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.311989069 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312000990 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312025070 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312067032 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312067986 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312119007 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312151909 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312165976 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312187910 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312220097 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312232971 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312254906 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312288046 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312300920 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312323093 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312356949 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312369108 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312396049 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312429905 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312443972 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312465906 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312499046 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312514067 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312582016 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312614918 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312628031 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312649012 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312681913 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312695026 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312717915 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312747002 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312762022 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312782049 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312815905 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312836885 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312849998 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312884092 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312899113 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312917948 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312951088 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.312980890 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.312983990 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313019991 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313026905 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313055038 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313088894 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313103914 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313122988 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313155890 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313169003 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313188076 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313220024 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313234091 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313256025 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313287973 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313316107 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313323975 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313358068 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313371897 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313393116 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313426971 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313446045 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313461065 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313492060 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313503981 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313527107 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313560963 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313572884 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313596010 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313628912 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313642979 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313663960 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313697100 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313710928 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313731909 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313766003 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313776016 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313801050 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313833952 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313846111 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.313868046 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.313916922 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400134087 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400172949 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400207043 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400238991 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400240898 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400274992 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400289059 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400307894 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400352001 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400367022 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400399923 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400433064 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400446892 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400485039 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400518894 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400532007 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400578022 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400610924 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400625944 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400680065 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400728941 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400731087 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400764942 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400798082 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400810957 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400832891 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400876999 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400885105 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400911093 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400944948 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.400960922 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.400974989 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401006937 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401014090 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401041031 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401073933 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401084900 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401108027 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401145935 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401150942 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401181936 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401213884 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401226997 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401247978 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401281118 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401299953 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401316881 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401350021 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401365042 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401385069 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401417971 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401431084 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401453018 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401487112 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401516914 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401521921 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401556015 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401566029 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:10.401591063 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:10.401637077 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:19.901254892 CET6147253192.168.2.41.1.1.1
            Jan 12, 2025 08:32:19.906234980 CET53614721.1.1.1192.168.2.4
            Jan 12, 2025 08:32:19.906316042 CET6147253192.168.2.41.1.1.1
            Jan 12, 2025 08:32:19.911252975 CET53614721.1.1.1192.168.2.4
            Jan 12, 2025 08:32:20.383785963 CET6147253192.168.2.41.1.1.1
            Jan 12, 2025 08:32:20.388933897 CET53614721.1.1.1192.168.2.4
            Jan 12, 2025 08:32:20.388994932 CET6147253192.168.2.41.1.1.1
            Jan 12, 2025 08:32:22.675349951 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:22.680331945 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:22.994316101 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:23.050239086 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:38.565959930 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:38.571105957 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:38.884982109 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:38.925254107 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:55.097237110 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:32:55.102264881 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:55.416117907 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:32:55.456571102 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:11.269671917 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:11.274528027 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:11.588386059 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:11.628386974 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:28.003571033 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:28.003674984 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:28.008538961 CET443349730192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:28.008636951 CET497304433192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:32.973053932 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:32.977979898 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:32.978065968 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:34.002747059 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:34.007710934 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.007745028 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.007771969 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.008025885 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.586107016 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.737997055 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:34.751467943 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:34.756333113 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.756387949 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.756417036 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:34.756417036 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:34.761272907 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.301228046 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.301255941 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.301270962 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.301285982 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.301363945 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.301382065 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.301393032 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.301393032 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.301445961 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.301574945 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.305480957 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.306462049 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.306487083 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.306595087 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.310355902 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.310369968 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.310498953 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625083923 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625101089 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625125885 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625142097 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625154972 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625161886 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.625173092 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625190020 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.625205040 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.625725031 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625741005 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625756979 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625771046 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625780106 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.625785112 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.625803947 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.626461983 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.626492977 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.626502037 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.626509905 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.626524925 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.626542091 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.626552105 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.626588106 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.627279043 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.630053997 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.630072117 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.630098104 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.737952948 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.848268986 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848337889 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848354101 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848378897 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848392963 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848395109 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.848408937 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848419905 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.848424911 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848439932 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848445892 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.848457098 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848470926 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.848803997 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848819971 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848834991 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848845959 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.848856926 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.848869085 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.849318981 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849344015 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849359989 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849359989 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.849375010 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849390030 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849395990 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.849406004 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849422932 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849425077 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.849438906 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849455118 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.849457026 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.849490881 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.850215912 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.850277901 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.850292921 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.850307941 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.850320101 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:35.850322008 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:35.850338936 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.050318003 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074350119 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074392080 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074431896 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074453115 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074508905 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074542046 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074553013 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074577093 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074615955 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074619055 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074650049 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074682951 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074690104 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074717045 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074748993 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074749947 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074784040 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074815035 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074820042 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074863911 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074897051 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074903965 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074929953 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.074963093 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.074965954 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075000048 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075032949 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075042009 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075069904 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075102091 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075103998 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075135946 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075166941 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075167894 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075201988 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075232983 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075237989 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075268984 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075335979 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075351954 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075392008 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075433969 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075448990 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075503111 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075536013 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075539112 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075570107 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075607061 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075608015 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075639963 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075673103 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075676918 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075707912 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075740099 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075752020 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075773954 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075808048 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075817108 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.075844049 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.075882912 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.076304913 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.076339960 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.076374054 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.076375008 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.076407909 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.076442957 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.076443911 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.076478004 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.076514006 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.076519966 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.237818003 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.294600964 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.294723988 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.294759035 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.294761896 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.294792891 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.294826031 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.294827938 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.294857979 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.294893026 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.294900894 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.294990063 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295025110 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295027971 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295123100 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295156956 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295159101 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295191050 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295222998 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295226097 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295255899 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295289040 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295291901 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295352936 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295387030 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295389891 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295423985 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295456886 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295456886 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295489073 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295522928 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295526028 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295557976 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295591116 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295593977 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.295625925 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.295660973 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.296101093 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296133995 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296166897 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296170950 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.296200991 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296233892 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296235085 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.296267033 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296299934 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296304941 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.296333075 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296365976 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296370983 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.296399117 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296432018 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296433926 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.296468019 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.296503067 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.296952963 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297005892 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297040939 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297041893 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.297074080 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297106028 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297108889 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.297139883 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297172070 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297174931 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.297205925 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297235966 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.297239065 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297272921 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297305107 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297308922 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.297341108 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297378063 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.297713041 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297777891 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297811031 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297818899 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.297846079 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297882080 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.297888041 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.347191095 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.381764889 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.381833076 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.381871939 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.381941080 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.381975889 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382009029 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382009983 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382042885 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382076025 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382076025 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382107973 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382141113 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382143974 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382174015 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382206917 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382206917 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382241011 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382272959 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382275105 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382307053 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382339954 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382343054 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382370949 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382402897 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382405996 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382437944 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382472038 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382474899 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382510900 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382546902 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382550955 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382585049 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382617950 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382625103 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382651091 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382683992 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382687092 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382718086 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382750988 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382751942 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382783890 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382817030 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382822037 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.382850885 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.382885933 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.517834902 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.517923117 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.517997026 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518068075 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518096924 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518096924 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518146992 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518173933 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518188953 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518307924 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518333912 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518377066 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518471003 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518472910 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518568039 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518594980 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518644094 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518697023 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518728971 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518757105 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518763065 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518798113 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518831015 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518853903 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518866062 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518899918 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518925905 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.518934011 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.518966913 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519000053 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519025087 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519032955 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519049883 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519064903 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519081116 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519088030 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519097090 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519114017 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519119978 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519129992 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519203901 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519220114 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519243002 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519277096 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519293070 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519309044 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519336939 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519352913 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519357920 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519370079 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519386053 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519402027 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519407988 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519418955 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519424915 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519435883 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519452095 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519467115 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519474030 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519483089 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519499063 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519515038 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519519091 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519531012 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519546986 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519562960 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519568920 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519579887 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.519603014 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.519675970 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.520159006 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520174980 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520190954 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520205021 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520220041 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520226955 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.520236015 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520251989 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520256996 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.520268917 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520275116 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.520284891 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520302057 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520318031 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520333052 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520348072 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520354986 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.520363092 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520379066 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520385027 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.520395994 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520401001 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.520415068 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.520436049 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521110058 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521126032 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521141052 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521156073 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521162987 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521173000 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521187067 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521193027 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521203041 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521208048 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521219015 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521234989 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521239996 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521250963 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521265984 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521270037 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521281958 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521297932 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521311998 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521317959 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521328926 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521334887 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.521347046 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.521363974 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522068977 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522083044 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522098064 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522113085 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522119999 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522130013 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522134066 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522146940 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522151947 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522165060 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522180080 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522195101 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522209883 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522216082 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522227049 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522242069 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522258043 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522265911 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522274017 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522289991 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522295952 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522306919 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522322893 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522330999 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522341967 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522897959 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522922039 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522937059 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522952080 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522967100 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522974014 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.522984028 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.522988081 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.523001909 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.523008108 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.523020029 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.523035049 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.523036957 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.523052931 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.523067951 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.523113012 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.523113012 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.534526110 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.539366007 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.601665974 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.604595900 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.604691982 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.604705095 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.604748011 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.604783058 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.604809046 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.604840040 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.604931116 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.604964972 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.604991913 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.605034113 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605086088 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605118990 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605144024 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.605154037 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605185986 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605212927 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.605221033 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605256081 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605288982 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605315924 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.605321884 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605360985 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605391026 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605416059 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.605423927 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605459929 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605490923 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605515957 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.605525970 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605559111 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605592012 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605618000 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.605624914 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605659962 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605694056 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.605719090 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.606781006 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.740994930 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741115093 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741149902 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741180897 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741183996 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741209030 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741291046 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741324902 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741353989 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741358995 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741394043 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741427898 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741452932 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741489887 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741518021 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741554022 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741589069 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741614103 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741622925 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741730928 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741764069 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741791964 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741797924 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741832972 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741857052 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741866112 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741902113 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741934061 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.741959095 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.741966009 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742069960 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742103100 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742129087 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742140055 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742242098 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742275953 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742280006 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742310047 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742343903 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742369890 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742377043 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742409945 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742441893 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742465973 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742475033 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742510080 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742536068 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742543936 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742580891 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742614985 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742628098 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742650986 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742683887 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742708921 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742716074 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742748976 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742774963 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742783070 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742815971 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742851019 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742875099 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742882967 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742916107 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742949009 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.742973089 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.742981911 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743015051 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743046045 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743077040 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.743081093 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743114948 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743139982 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.743146896 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743180990 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743207932 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.743215084 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743248940 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743273973 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.743283033 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743335962 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.743452072 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.748450994 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748572111 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748605967 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748639107 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748680115 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748707056 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.748754978 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748790026 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748822927 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748848915 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.748893976 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748944998 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.748970985 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749027014 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749061108 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749087095 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749094009 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749128103 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749161005 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749180079 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749193907 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749228001 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749252081 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749259949 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749293089 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749319077 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749325037 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749358892 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749386072 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749392986 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749425888 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749507904 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749532938 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749541998 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749576092 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749602079 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749609947 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749644041 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749670982 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749677896 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749712944 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749747038 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749758959 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749758959 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749782085 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749814987 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749833107 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749847889 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749881029 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749905109 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.749912977 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749947071 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.749979019 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750003099 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.750010967 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750044107 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750076056 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750102043 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.750108957 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750148058 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750180960 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750202894 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.750214100 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750248909 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750272036 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.750281096 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750314951 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750345945 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750370979 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.750377893 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750411987 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750443935 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750468016 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.750477076 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750507116 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750540972 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750565052 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.750574112 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750607967 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750641108 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.750664949 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.752659082 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.827744007 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.827817917 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.827871084 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.827903986 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.827945948 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.827974081 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828032017 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828068018 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828094006 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828102112 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828170061 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828222990 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828250885 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828300953 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828325987 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828362942 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828437090 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828460932 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828469992 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828506947 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828538895 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828563929 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828572035 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828608036 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828639984 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828664064 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828672886 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828707933 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828732967 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828741074 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828773975 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828808069 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828825951 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828841925 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828876019 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828902960 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828910112 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828938007 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.828944921 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828979015 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.828995943 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.829013109 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.829046965 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.829066992 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.829080105 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.829113007 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.829138994 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:36.829149008 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:36.829205036 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:49.130964994 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:33:49.136497021 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:49.445759058 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:33:49.487963915 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:06.003722906 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:06.008827925 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:06.318912029 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:06.362926006 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:22.519356966 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:22.524358988 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:22.834304094 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:22.878635883 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:38.488025904 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:38.488091946 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:38.493160009 CET1044361700192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:38.493228912 CET6170010443192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:43.441919088 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:43.447154045 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:43.447252035 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:44.402214050 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:44.407535076 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:44.407574892 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:44.407603979 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:44.407636881 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:44.978682995 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.019284010 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.054573059 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.059916019 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.059953928 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.059983015 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.059992075 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.064860106 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590213060 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590260983 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590296030 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590328932 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590363026 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590393066 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590426922 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.590465069 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.590466022 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.590466022 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.590581894 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.590682983 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.595530987 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.595701933 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.595730066 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.595756054 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.595782042 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.595808983 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.912938118 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.912976980 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.913009882 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.913122892 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.913156033 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.913172960 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.913204908 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.913220882 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.913238049 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.913258076 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.913271904 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.914060116 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.914093018 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.914117098 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.914128065 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.914136887 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.914160967 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.914194107 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.914241076 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.914946079 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.914978981 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.915011883 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.915028095 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.915045023 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.915051937 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:45.915076971 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:45.918688059 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.134119034 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134157896 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134191990 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134224892 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134257078 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134290934 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134336948 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.134336948 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.134336948 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.134526968 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134561062 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134593964 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134608984 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.134628057 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.134818077 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.135067940 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.135102034 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.135134935 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.135163069 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.135166883 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.135201931 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.135216951 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.135236025 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.135293007 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.136038065 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.136086941 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.136120081 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.136135101 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.136152983 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.136187077 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.136199951 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.136221886 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.136292934 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.136945009 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.136977911 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.137011051 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.137042046 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.137063980 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.137074947 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.137089968 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.191144943 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.355223894 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355333090 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355369091 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355403900 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355436087 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355472088 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355515957 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.355515957 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.355602980 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.355695963 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355729103 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355762959 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355794907 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355798006 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.355829000 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355860949 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355890989 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.355911016 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355912924 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.355943918 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.355993986 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.356720924 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.356784105 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.356817007 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.356839895 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.356848955 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.356883049 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.356910944 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.356914043 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.356949091 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.356961012 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.356977940 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357044935 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.357546091 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357578993 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357611895 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357645035 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357645988 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.357677937 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357700109 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.357711077 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357743979 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357763052 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.357778072 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.357835054 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.358551025 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358583927 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358618021 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358650923 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358654976 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.358684063 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358700037 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.358716965 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358750105 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358762980 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.358782053 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.358836889 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.359570980 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359605074 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359637976 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359669924 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359682083 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.359704018 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359718084 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.359736919 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359770060 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359802008 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.359808922 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.359848022 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.360428095 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.360457897 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.360507965 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576198101 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576231003 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576280117 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576354980 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576380968 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576387882 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576422930 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576458931 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576464891 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576520920 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576554060 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576586962 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576618910 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576652050 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576652050 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576672077 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576683998 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576718092 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576780081 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576865911 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576898098 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.576924086 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.576932907 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577169895 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577202082 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577229023 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.577234983 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577246904 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.577269077 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577301025 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577332973 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577358007 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.577366114 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577378035 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.577399015 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577662945 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577712059 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577722073 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.577745914 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577764988 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.577776909 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577810049 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577841043 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577866077 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.577872992 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.577884912 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.578221083 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578270912 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578304052 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578331947 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.578336000 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578352928 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.578370094 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578402042 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578434944 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578459978 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.578466892 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578476906 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.578499079 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578530073 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578562021 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578584909 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.578608036 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.578613043 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.578649044 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579258919 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579293013 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579322100 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.579338074 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.579344988 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579377890 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579410076 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579442024 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579468966 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.579473972 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579487085 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.579507113 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579539061 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579571009 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579596043 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.579603910 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579615116 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.579636097 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579672098 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.579730034 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.580153942 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580213070 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.580221891 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580271959 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580303907 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580337048 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580359936 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.580368996 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580382109 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.580403090 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580435038 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580468893 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580492973 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.580501080 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580513000 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.580533981 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580564976 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580599070 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.580620050 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.580642939 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.581187010 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581221104 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581254005 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581286907 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581317902 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581350088 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581352949 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.581382990 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581432104 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.581471920 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581505060 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.581653118 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.797494888 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797595978 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797630072 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797704935 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797756910 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797789097 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797811031 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.797811031 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.797869921 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797919035 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797934055 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.797952890 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.797972918 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.797990084 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798043966 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798074961 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798105001 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798106909 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798125029 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798141003 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798173904 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798233032 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798240900 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798293114 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798300982 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798327923 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798360109 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798393011 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798408031 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798424959 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798438072 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798458099 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798490047 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798522949 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798538923 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798554897 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798562050 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798588991 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798619986 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798654079 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798672915 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798686028 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798738003 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798798084 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798830986 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798852921 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798863888 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798894882 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798928022 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798945904 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798962116 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.798980951 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.798994064 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799025059 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799057007 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799074888 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799098015 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799153090 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799237013 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799284935 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799340963 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799345970 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799377918 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799400091 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799411058 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799443007 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799474955 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799498081 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799506903 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799515963 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799539089 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799570084 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799602985 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799622059 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799634933 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799644947 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799669981 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799701929 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799734116 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799766064 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799771070 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799792051 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799798965 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799830914 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799853086 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799861908 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799894094 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799926996 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799958944 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.799971104 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799971104 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.799993038 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800024986 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800050974 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800059080 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800208092 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800240993 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800272942 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800277948 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800297976 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800307989 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800340891 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800364017 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800374031 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800410986 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800429106 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800446033 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800477982 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800508976 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800517082 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800543070 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800543070 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800575018 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800606966 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800632000 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800638914 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800654888 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800674915 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800708055 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800741911 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800765038 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800775051 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800792933 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800806999 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800838947 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800873041 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.800893068 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.800930977 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801147938 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801197052 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801230907 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801264048 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801285028 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801304102 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801323891 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801337004 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801369905 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801402092 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801434994 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801435947 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801455975 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801465988 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801500082 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801532030 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801558971 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801565886 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801589966 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801598072 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801632881 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801661968 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801665068 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801698923 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801717043 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801731110 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801764011 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801796913 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801821947 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.801830053 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.801839113 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.802010059 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.802043915 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.802076101 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.802093983 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.802108049 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.802124023 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.802141905 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.802175045 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.802206039 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.802253962 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.802253962 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.817203999 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.822146893 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.839579105 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.844455957 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.884922028 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885011911 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885045052 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885077000 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885209084 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.885231972 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885267019 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885274887 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.885299921 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885332108 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885359049 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.885366917 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885379076 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.885396957 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885430098 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885462046 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885487080 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.885495901 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885513067 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.885529995 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885560989 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885591984 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:46.885615110 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:46.885634899 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018284082 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018338919 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018368006 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018399954 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018441916 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018517971 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018554926 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018554926 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018584013 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018631935 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018662930 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018666983 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018686056 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018699884 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018733025 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018764019 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018812895 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018835068 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018856049 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018891096 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018923998 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018954992 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.018963099 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.018987894 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019021034 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019030094 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019057989 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019123077 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019156933 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019191027 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019222021 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019277096 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019309998 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019335032 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019372940 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019407988 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019439936 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019463062 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019474983 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019500971 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019504070 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019534111 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019553900 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019566059 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019630909 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019675016 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019748926 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019782066 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019814968 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019846916 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019848108 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019881010 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019881964 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019916058 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019934893 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.019949913 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.019982100 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020015955 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020046949 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020047903 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.020080090 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020080090 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.020112991 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020133018 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.020145893 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020178080 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020209074 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020227909 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.020241976 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020272017 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.020276070 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020308018 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020330906 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.020342112 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020374060 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020405054 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020431042 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.020438910 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.020481110 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.026537895 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026571989 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026606083 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026638985 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026654959 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.026705027 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.026736021 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026781082 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026827097 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026843071 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.026859999 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026892900 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.026894093 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026926041 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026947021 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.026958942 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.026992083 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027043104 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027050018 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027097940 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027127028 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027132034 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027164936 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027194023 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027198076 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027304888 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027338028 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027380943 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027414083 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027446032 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027473927 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027496099 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027506113 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027535915 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027538061 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027561903 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027570963 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027604103 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027625084 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027635098 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027669907 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027702093 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027721882 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027734041 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027757883 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027766943 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027800083 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027832985 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027851105 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027867079 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.027888060 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.027899027 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028050900 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028100014 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028110027 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028134108 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028151035 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028166056 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028198957 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028230906 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028247118 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028264046 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028286934 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028295040 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028327942 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028361082 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028378963 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028393984 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028417110 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028425932 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028460026 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028491974 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028523922 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028532028 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028557062 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028569937 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028589010 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028624058 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028644085 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028659105 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028673887 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028692007 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028779030 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028829098 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028831005 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028862953 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028879881 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028896093 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028927088 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028959036 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.028980970 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.028991938 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.029015064 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.029023886 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.029057980 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.029089928 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.029117107 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.029153109 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.105900049 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.105987072 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106036901 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106113911 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106148005 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106179953 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106200933 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106213093 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106272936 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106272936 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106313944 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106347084 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106376886 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106379032 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106410980 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106441975 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106482983 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106528044 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106547117 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106595039 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106628895 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106662989 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106667995 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106695890 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106741905 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106792927 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106826067 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106857061 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106890917 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106903076 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106925011 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106941938 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.106957912 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106990099 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.106995106 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107023001 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107070923 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107095957 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107146025 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107163906 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107177973 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107211113 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107244015 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107275963 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107278109 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107306957 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107321978 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107363939 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107373953 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107398033 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107431889 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107460976 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107464075 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107496977 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107528925 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107561111 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107567072 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107594013 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107608080 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107626915 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107657909 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107660055 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107693911 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107726097 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107731104 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107758999 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107780933 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107790947 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107824087 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107856035 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107892990 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.107894897 CET443361740192.238.132.117192.168.2.4
            Jan 12, 2025 08:34:47.107935905 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:47.160001040 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:59.707026005 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:34:59.707132101 CET617404433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:04.707458019 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:04.731669903 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:04.731755972 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:05.612781048 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:05.618050098 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:05.618119001 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:05.618148088 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:05.618175983 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.197236061 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.238060951 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.299700022 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.304876089 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.304914951 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.304944038 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.304959059 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.309801102 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.842073917 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.842122078 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.842158079 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.842191935 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.842201948 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.842227936 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.842263937 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.842266083 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.842312098 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.842453957 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.842528105 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:06.847553015 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.847611904 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.847646952 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.847722054 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.847750902 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:06.847778082 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170371056 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170418978 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170456886 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170490026 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170512915 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.170527935 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170555115 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.170835018 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170870066 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170895100 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.170907021 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.170949936 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.171353102 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.171387911 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.171422005 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.171453953 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.171454906 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.171490908 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.171503067 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.172230959 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.172265053 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.172282934 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.172301054 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.172334909 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.172374010 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.212287903 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.404520035 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404570103 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404606104 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404639959 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404675007 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404680967 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.404714108 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.404768944 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404805899 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404839993 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404865980 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.404876947 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404907942 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.404942036 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.404959917 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.405250072 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405283928 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405318975 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405333996 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.405354023 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405386925 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405407906 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.405900002 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405935049 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405968904 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.405987978 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.406002998 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406038046 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406066895 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.406073093 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406109095 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.406805038 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406841040 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406858921 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.406877041 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406909943 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406929016 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.406944990 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.406979084 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.407030106 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.407691002 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.407726049 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.407779932 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.494776011 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.534939051 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.627454996 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.627505064 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.627542973 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.627578020 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.627605915 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.627648115 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.627892971 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.627927065 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.627963066 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.627978086 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.627999067 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628034115 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628067017 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628082991 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.628103018 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628134966 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628148079 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.628170013 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628181934 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.628396034 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628428936 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628444910 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.628464937 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628496885 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628514051 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.628530979 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628563881 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628597021 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628612995 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.628629923 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628664017 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.628680944 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.628704071 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.629234076 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629317999 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629353046 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629379034 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.629386902 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629421949 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629453897 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629472017 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.629491091 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629523993 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629539967 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.629559040 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.629570007 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.630260944 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630295038 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630328894 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630347967 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.630361080 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630394936 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630418062 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.630429029 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630441904 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.630465031 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630498886 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630517960 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.630534887 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.630584955 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.631097078 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631131887 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631165981 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631198883 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631217957 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.631232977 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631266117 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631283998 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.631300926 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631306887 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.631388903 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.631439924 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.631805897 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.675642967 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.850660086 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.850809097 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.850843906 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.850878000 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.850905895 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.850912094 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.850939989 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.850945950 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851015091 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851073980 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851142883 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851177931 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851211071 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851234913 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851247072 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851265907 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851284027 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851341963 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851353884 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851380110 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851414919 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851449013 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851468086 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851484060 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851521969 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851542950 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851555109 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851567030 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851706028 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851741076 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851763964 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851774931 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851809025 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851843119 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851866007 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851876020 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851886034 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851911068 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851944923 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.851972103 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.851979017 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852013111 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852025032 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852049112 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852082968 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852104902 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852117062 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852153063 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852169037 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852464914 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852515936 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852550983 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852571964 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852583885 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852619886 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852636099 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852653980 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852675915 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852691889 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852730989 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852744102 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852766037 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852799892 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852814913 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.852835894 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852866888 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852900982 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852935076 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.852962017 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.853185892 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853240013 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.853379011 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853413105 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853446960 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853481054 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853496075 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.853516102 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853549957 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853573084 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.853584051 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853593111 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.853619099 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853652954 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853672981 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.853689909 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853724957 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853740931 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.853760004 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853795052 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.853842974 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.854315996 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854351044 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854384899 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854403973 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.854418993 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854424953 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.854454041 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854487896 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854507923 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.854521990 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854556084 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854573965 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.854593039 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.854717970 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.941059113 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941106081 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941142082 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941226006 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.941239119 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941276073 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941310883 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941340923 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.941346884 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941361904 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.941381931 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941442966 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.941467047 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941500902 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941535950 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941565037 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941567898 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.941598892 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941633940 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941656113 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.941668987 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:07.941696882 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:07.988122940 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.073664904 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073710918 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073750019 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073777914 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.073785067 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073817015 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073852062 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073865891 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.073888063 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073924065 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.073950052 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.073975086 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082004070 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082057953 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082092047 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082115889 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082124949 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082159996 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082191944 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082214117 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082225084 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082233906 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082302094 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082354069 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082386971 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082398891 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082470894 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082519054 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082537889 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082571983 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082583904 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082607031 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082639933 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082654953 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082674026 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082709074 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082751036 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082758904 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082786083 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082818985 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082839966 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082853079 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082860947 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082885981 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082921028 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082940102 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.082953930 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.082987070 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083002090 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083024979 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083058119 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083090067 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083106995 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083123922 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083157063 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083169937 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083190918 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083199024 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083225012 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083259106 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083273888 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083420992 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083455086 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083472013 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083488941 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083520889 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083554029 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083570004 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083589077 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083621025 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083636999 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083655119 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083666086 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083692074 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083726883 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083739996 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083760977 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083796978 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083811045 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083831072 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083863974 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083895922 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083909988 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083930969 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083962917 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.083975077 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.083998919 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.084002972 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.084033012 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.084068060 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.084078074 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.084098101 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.084142923 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.089344025 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.089431047 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.089464903 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.089518070 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.089572906 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.089767933 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.089849949 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.089925051 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.089958906 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.089975119 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.089993000 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090025902 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090059042 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090122938 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090157986 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090176105 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090192080 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090250015 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090327024 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090359926 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090393066 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090409994 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090590954 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090639114 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090698004 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090730906 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090749979 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090800047 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090833902 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090883017 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.090943098 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.090986013 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091005087 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091028929 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091073036 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091128111 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091136932 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091170073 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091182947 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091219902 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091278076 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091341019 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091414928 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091449976 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091459036 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091499090 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091530085 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091578960 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091650009 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091682911 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091697931 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091718912 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091766119 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091814995 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091892958 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091937065 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091939926 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.091972113 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.091983080 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092015028 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092058897 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092118979 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092153072 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092186928 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092200041 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092226028 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092236996 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092277050 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092310905 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092325926 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092348099 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092380047 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092396975 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092396975 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092415094 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092420101 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092449903 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092461109 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092485905 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092518091 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092545033 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092552900 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092585087 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.092592001 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.092627048 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.097990990 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.106667995 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.111552954 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164248943 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164324045 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164396048 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164422035 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.164431095 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164464951 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164477110 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.164499044 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164556026 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.164589882 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164674044 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164710045 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164719105 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.164745092 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164778948 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164800882 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.164812088 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164845943 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164865017 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.164877892 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164911985 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164933920 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.164946079 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164978981 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.164999962 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.165041924 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165097952 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.165112972 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165148973 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165182114 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165198088 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.165216923 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165249109 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165282011 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165297031 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.165317059 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165338993 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.165349007 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165384054 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165416002 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165421009 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.165451050 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165479898 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.165496111 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.165529966 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.296852112 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297002077 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297060966 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297092915 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297168016 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297218084 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297230005 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297254086 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297308922 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297346115 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297398090 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297430992 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297489882 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297517061 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297569036 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297602892 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297626972 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297676086 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297699928 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297734976 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297766924 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297800064 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297807932 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297833920 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297868013 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297878027 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297900915 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297935009 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.297950029 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.297969103 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298002958 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298019886 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298036098 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298043013 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298070908 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298104048 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298137903 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298160076 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298183918 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298283100 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298335075 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298367023 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298398972 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298415899 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298432112 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298458099 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298468113 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298501015 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298516989 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298533916 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298568964 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298589945 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298602104 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298635006 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298651934 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298670053 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298705101 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298738003 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298752069 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298772097 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298784018 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298818111 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.298870087 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.298971891 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299022913 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299052954 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299086094 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299102068 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299122095 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299154997 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299177885 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299190044 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299223900 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299228907 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299257994 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299284935 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299293041 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299345970 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299357891 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299392939 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299426079 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299443007 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299459934 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299493074 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299509048 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299525976 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299560070 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299592972 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299595118 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299627066 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299664021 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299757957 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299810886 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299832106 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299881935 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299916983 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299933910 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.299951077 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.299983978 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300002098 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300015926 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300050974 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300064087 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300085068 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300117970 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300137997 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300152063 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300185919 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300219059 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300225973 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300251007 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300282955 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300291061 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300317049 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300331116 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300352097 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300384998 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300401926 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300417900 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300451040 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300468922 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300532103 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300565958 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300581932 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300600052 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300633907 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300662994 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300684929 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300698042 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300707102 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300733089 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300765991 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300779104 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300798893 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300831079 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300846100 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300865889 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300899029 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300931931 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.300946951 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.300968885 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301002026 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301002979 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301034927 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301048994 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301069975 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301104069 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301136971 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301147938 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301171064 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301188946 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301204920 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301237106 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301251888 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301270962 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301304102 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301325083 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301337957 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301372051 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301403999 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301414967 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301438093 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301455021 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301471949 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301505089 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301517010 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301538944 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301573038 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301590919 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301608086 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301640987 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301654100 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.301675081 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.301723957 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388236046 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388338089 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388390064 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388396025 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388425112 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388458967 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388511896 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388518095 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388552904 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388586044 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388606071 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388618946 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388632059 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388706923 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388741016 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388765097 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388776064 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388809919 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388828039 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388844967 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388879061 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388911009 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388935089 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388945103 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.388953924 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.388979912 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389014959 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389033079 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.389048100 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389081955 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389098883 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.389115095 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389149904 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389168978 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.389183044 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389215946 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389238119 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.389250040 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389282942 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:08.389302015 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:08.441195011 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:20.581964970 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:20.582056999 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:20.587198973 CET1044361741192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:20.587260962 CET6174110443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:25.535689116 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:25.540913105 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:25.541786909 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:26.979897976 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:26.985189915 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:26.985243082 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:26.985270977 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:26.985302925 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:27.339049101 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:27.394398928 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:27.617301941 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:27.622400999 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:27.622437000 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:27.622463942 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:27.622463942 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:27.627969027 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.156847954 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.156897068 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.156933069 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.156966925 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.156974077 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.157002926 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.157036066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.157047987 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.157160044 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.157258987 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.162081957 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.162112951 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.162164927 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.162267923 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.162319899 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.162352085 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479345083 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479489088 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479523897 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479557037 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479557037 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.479590893 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479624987 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479659081 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479660988 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.479684114 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.479696035 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.479744911 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.480288982 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.480323076 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.480357885 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.480375051 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.480391979 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.480746984 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.481173038 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.481206894 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.481240988 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.481275082 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.481290102 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.481869936 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.481920958 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.702413082 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702462912 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702498913 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702533007 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702567101 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702600956 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702625990 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.702626944 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.702747107 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.702826023 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702862024 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702896118 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702910900 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.702930927 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.702965975 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.703018904 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.703237057 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.703270912 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.703305006 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.703332901 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.703366041 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.703399897 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.703413010 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.703434944 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.703483105 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.704251051 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.704286098 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.704319954 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.704339981 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.704353094 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.704386950 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.704420090 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.704435110 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.705226898 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.705260038 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.705276012 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.705296993 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.705332041 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.705343962 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.769494057 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.925435066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925477028 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925533056 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925569057 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925601959 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925636053 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925672054 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925704956 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925774097 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.925775051 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.925795078 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925829887 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925848007 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.925868034 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925895929 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.925940037 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.926021099 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.926276922 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.926311970 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.926347017 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.926381111 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.926414013 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.926424026 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.926448107 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.926482916 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.926537991 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.927005053 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927040100 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927073956 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927100897 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.927108049 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927141905 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927175045 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927180052 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.927208900 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927241087 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927258968 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.927345037 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.927916050 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927952051 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.927987099 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928020000 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928055048 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928088903 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928122997 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928127050 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.928157091 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928172112 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.928190947 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.928265095 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.928852081 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928885937 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928920031 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928952932 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.928956985 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.928987980 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929020882 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929058075 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929065943 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.929092884 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929168940 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.929666996 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929683924 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929699898 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929717064 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929729939 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.929732084 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:28.929754019 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:28.930748940 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148178101 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148300886 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148332119 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148365974 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148400068 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148432970 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148467064 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148499012 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148539066 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148539066 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148539066 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148539066 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148617983 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148650885 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148684025 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148749113 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148802042 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148833990 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148866892 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148894072 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148900032 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.148932934 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.148935080 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149187088 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149219990 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149244070 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.149251938 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149267912 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.149285078 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149317026 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149348974 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149367094 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.149382114 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149388075 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.149415016 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149450064 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149497986 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.149905920 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149940014 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149974108 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.149991989 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150006056 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150038958 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150043011 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150072098 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150105000 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150135994 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150155067 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150168896 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150202036 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150223017 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150233984 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150266886 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150300980 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150314093 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150651932 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150707960 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150731087 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150801897 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150835037 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150850058 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150868893 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150903940 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150928020 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.150937080 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150969982 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.150975943 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.151002884 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151035070 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151057005 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.151068926 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151082039 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.151102066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151135921 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151153088 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.151721001 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151755095 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151777983 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.151788950 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151822090 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151842117 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.151854992 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151886940 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151902914 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.151921034 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151952982 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.151985884 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152003050 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.152019024 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152051926 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152085066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152103901 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.152118921 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152390957 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.152585030 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152617931 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152652025 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152683973 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152700901 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.152717113 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152724981 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.152750969 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152786970 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152802944 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.152821064 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152854919 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152872086 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.152888060 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.152945995 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.371548891 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371607065 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371639967 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371673107 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371711969 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.371743917 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371750116 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.371824026 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371875048 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371876955 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.371908903 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371942043 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.371962070 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.371973991 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372006893 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372030973 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372039080 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372072935 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372143030 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372145891 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372195959 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372227907 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372241974 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372263908 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372275114 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372296095 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372328997 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372350931 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372380018 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372415066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372446060 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372468948 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372478962 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372494936 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372512102 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372545958 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372561932 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372699022 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372734070 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372751951 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372773886 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372807026 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372823000 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372839928 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372874022 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372896910 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372906923 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372939110 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.372968912 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.372972012 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373007059 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373023987 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373039961 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373073101 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373105049 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373136997 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373158932 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373158932 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373219013 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373266935 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373270035 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373306036 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373430967 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373434067 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373486042 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373519897 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373534918 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373553991 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373586893 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373619080 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373636007 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373651028 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373683929 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373703957 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373716116 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373749018 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373750925 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373781919 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373816013 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373836994 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373847961 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373862028 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373881102 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373913050 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373924971 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.373945951 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.373979092 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374001026 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374013901 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374069929 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374408007 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374456882 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374490976 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374522924 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374541998 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374556065 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374562025 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374588966 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374620914 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374653101 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374670029 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374685049 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374699116 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374717951 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374752045 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374783993 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374800920 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374818087 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374825954 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374851942 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374886036 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374903917 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.374918938 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374952078 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.374984026 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375011921 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375016928 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375052929 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375380039 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375412941 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375447035 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375478029 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375509024 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375509977 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375543118 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375575066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375607014 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375626087 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375638962 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375670910 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375705004 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375724077 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375739098 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375754118 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375782013 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375813007 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375845909 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375861883 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375880957 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375914097 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375946045 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.375962019 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.375978947 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376024008 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.376171112 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376204014 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376236916 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376254082 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.376269102 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376301050 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376312971 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.376332998 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376365900 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376398087 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376425982 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.376430035 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376444101 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.376463890 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376497030 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.376513958 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.389301062 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.394146919 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.410896063 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.415792942 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459134102 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459239960 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459306955 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459352016 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.459357023 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459392071 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459424973 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459450006 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.459458113 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459491968 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459523916 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459537029 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.459537029 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.459558010 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.459609032 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.594599009 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594635010 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594686985 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.594706059 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594757080 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594789982 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594815016 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.594822884 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594856977 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594881058 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.594923973 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.594990969 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595022917 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595037937 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595057011 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595089912 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595115900 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595133066 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595141888 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595175982 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595228910 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595278025 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595326900 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595401049 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595457077 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595493078 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595541000 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595573902 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595591068 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595607042 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595640898 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595658064 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595673084 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595706940 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595721006 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595741034 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595774889 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595787048 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595807076 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595840931 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595863104 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595873117 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595889091 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.595905066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595937014 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.595954895 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596016884 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596051931 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596084118 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596101046 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596116066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596148014 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596151114 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596182108 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596199036 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596215010 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596246958 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596263885 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596281052 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596313000 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596327066 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596347094 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596379995 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596399069 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596411943 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596445084 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596477032 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596477032 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596508980 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596532106 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596543074 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596575022 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596609116 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596625090 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596642971 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596676111 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.596697092 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.596745968 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.601598978 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601634026 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601669073 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601722956 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.601764917 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601814032 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601846933 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601864100 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.601880074 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601886988 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.601934910 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.601969957 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602004051 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602020979 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602037907 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602070093 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602091074 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602102995 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602135897 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602149010 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602169037 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602200031 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602292061 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602324963 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602344990 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602356911 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602391005 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602407932 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602423906 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602456093 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602473974 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602507114 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602560043 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602592945 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602617979 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602626085 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602634907 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602659941 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602693081 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602722883 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602742910 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602844954 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602876902 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602905989 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602909088 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602922916 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.602942944 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602974892 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.602998018 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603008032 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603040934 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603060961 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603072882 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603107929 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603132963 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603141069 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603176117 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603203058 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603209019 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603241920 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603260040 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603420973 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603471994 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603475094 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603503942 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603535891 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603557110 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603568077 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603600979 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603632927 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603651047 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603666067 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603698015 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603720903 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603732109 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603769064 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603847027 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603882074 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603914976 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603934050 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.603948116 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603980064 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.603998899 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.604012012 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604044914 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604063988 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.604077101 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604109049 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604124069 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.604141951 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604173899 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604192019 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.604207039 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604239941 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604249001 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.604274035 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604306936 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.604324102 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.604374886 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.682598114 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.682699919 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.682751894 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.682766914 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.682802916 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.682837963 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.682854891 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.682950020 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.682984114 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.682998896 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683017969 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683049917 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683063984 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683084011 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683115959 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683129072 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683149099 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683196068 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683249950 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683357954 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683401108 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683406115 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683496952 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683530092 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683557034 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683562994 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683598042 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683609962 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683631897 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683665037 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683674097 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683698893 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683732986 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683747053 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683767080 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683799028 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683811903 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683834076 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683866024 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683880091 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683900118 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683932066 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683948994 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.683965921 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.683998108 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684012890 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684031010 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684065104 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684078932 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684098959 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684132099 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684145927 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684164047 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684195995 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684214115 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684230089 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684262991 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684277058 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684297085 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684329033 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684344053 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684361935 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684393883 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684421062 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684428930 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684462070 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684475899 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684494972 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684526920 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684540033 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684561014 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684595108 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684608936 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684628010 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684659958 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684675932 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684695005 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684727907 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684739113 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684761047 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684793949 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684801102 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684828043 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684860945 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684876919 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684894085 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684926033 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684938908 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.684958935 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.684992075 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.685004950 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.685025930 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.685059071 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.685069084 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:29.685095072 CET443361742192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:29.685142994 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:42.285187960 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:42.285275936 CET617424433192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:47.271001101 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:47.276354074 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:47.276452065 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:48.292141914 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:48.297317982 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:48.297357082 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:48.297384977 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:48.297416925 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:48.898060083 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:48.956927061 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.016315937 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.021358013 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.021389008 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.021414995 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.021455050 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.026345015 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.557315111 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.557362080 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.557399035 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.557434082 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.557440042 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.557471037 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.557518959 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.557631016 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.557826042 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.562576056 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.562607050 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.562635899 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.562848091 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.562875986 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.562903881 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888406038 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888580084 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888614893 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888648033 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888672113 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.888679981 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888714075 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888745070 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.888750076 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.888813019 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.889094114 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.889148951 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.889184952 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.889296055 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.889344931 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.889359951 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.889380932 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.889413118 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.889446020 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.889477968 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.889514923 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.890157938 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.890192032 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.890810013 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.893591881 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.893626928 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.893660069 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:49.893692970 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:49.941297054 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.112303019 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112340927 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112375021 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112407923 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112430096 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.112440109 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112473965 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112498045 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.112509966 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112555027 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.112616062 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112648964 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112679005 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.112765074 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112804890 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112859011 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.112879038 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.112916946 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.113159895 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.113193989 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.113228083 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.113256931 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.113260984 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.113296032 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.113326073 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.113328934 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.113365889 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.113428116 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.114047050 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114080906 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114111900 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114145994 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114161015 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.114180088 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114181995 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.114214897 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114248037 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114264965 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.114281893 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114311934 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.114886045 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114918947 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114953041 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114986897 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.114998102 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.115016937 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.115022898 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.115056992 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.115092039 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.115112066 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.115128994 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.115145922 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.160053968 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335134029 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335202932 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335239887 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335273027 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335306883 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335329056 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335393906 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335406065 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335432053 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335468054 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335503101 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335516930 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335537910 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335572958 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335573912 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335608959 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335618973 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335644007 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335661888 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335680962 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335716009 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335747957 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335779905 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335787058 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335817099 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.335824966 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.335877895 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.336030006 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336066008 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336100101 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336128950 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.336133003 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336169004 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336200953 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.336201906 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336239100 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336271048 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336302042 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.336306095 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336338997 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.336342096 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336395979 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.336936951 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.336971998 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337004900 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337037086 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337070942 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337069988 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.337109089 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337111950 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.337142944 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337167025 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.337177038 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337210894 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337244034 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337275028 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.337276936 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337313890 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.337821007 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337855101 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337888956 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337920904 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337920904 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.337954998 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.337960005 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.337990046 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338011026 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.338025093 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338057041 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338085890 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.338090897 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338126898 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338159084 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.338160992 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338219881 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.338702917 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338738918 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338777065 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338809967 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338843107 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338845968 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.338877916 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338879108 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.338915110 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.338936090 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.394470930 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.424381971 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424432039 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424468040 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424501896 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424529076 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.424537897 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424552917 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.424575090 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424609900 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424645901 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.424665928 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.424706936 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558096886 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558197975 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558233976 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558321953 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558343887 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558404922 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558439970 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558442116 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558479071 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558506966 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558512926 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558548927 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558603048 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558613062 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558638096 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558662891 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558739901 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558779001 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558811903 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558841944 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558845043 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558881044 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558887959 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558916092 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558936119 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.558950901 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.558984995 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559012890 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559016943 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559051037 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559083939 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559111118 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559118032 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559149027 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559149981 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559170008 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559185982 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559201002 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559216022 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559216976 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559232950 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559247971 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559256077 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559267044 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559277058 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559282064 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559300900 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559348106 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559412003 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559427977 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559442997 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559457064 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559472084 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559487104 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559495926 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559524059 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559530020 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559540987 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559552908 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559559107 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559575081 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559592009 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559596062 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559607983 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559623957 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559629917 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559639931 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559653044 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559658051 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559675932 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559690952 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.559710026 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.559752941 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.560422897 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560440063 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560456038 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560470104 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560484886 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560499907 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560516119 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560517073 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.560537100 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560549021 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.560554981 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560570955 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.560571909 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560589075 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560604095 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560620070 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560630083 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.560636044 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560653925 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560668945 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560678005 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.560686111 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.560700893 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.560748100 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.561400890 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561418056 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561431885 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561445951 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561461926 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561477900 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561481953 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.561495066 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561510086 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561525106 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561526060 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.561541080 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561558008 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561573029 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561575890 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.561589003 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561604977 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561614990 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.561620951 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561635971 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.561636925 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561655045 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.561665058 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.561685085 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562319040 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562335014 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562350988 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562365055 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562380075 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562387943 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562396049 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562412977 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562427044 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562428951 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562446117 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562460899 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562475920 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562477112 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562494040 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562509060 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562517881 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562525034 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562536955 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562542915 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562560081 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562560081 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562577009 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.562602997 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.562645912 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.563199997 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.563216925 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.563232899 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.563247919 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.563276052 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.563308001 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781024933 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781116009 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781198978 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781213045 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781254053 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781290054 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781322956 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781353951 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781356096 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781385899 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781394958 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781419039 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781445980 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781505108 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781558990 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781563997 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781610966 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781651974 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781707048 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781725883 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781759024 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781781912 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781794071 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781829119 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781863928 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.781891108 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781928062 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.781969070 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782103062 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782135010 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782166958 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782197952 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782207012 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782232046 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782244921 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782263994 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782280922 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782298088 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782330990 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782362938 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782362938 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782396078 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782428980 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782449961 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782460928 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782488108 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782495022 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782522917 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782556057 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782579899 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782593012 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782608986 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782629013 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782661915 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782694101 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782715082 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782727003 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782753944 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782761097 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782803059 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782834053 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782860041 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782867908 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782888889 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782901049 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782933950 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782965899 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.782985926 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.782999992 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783026934 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.783034086 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783067942 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783093929 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.783101082 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783134937 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783169031 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783188105 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.783202887 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783224106 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.783235073 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783268929 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783302069 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.783346891 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.783369064 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.788723946 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.788882017 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.788913965 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.788954020 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789011002 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789069891 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789098978 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789199114 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789247036 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789280891 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789313078 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789314985 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789355040 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789367914 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789410114 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789441109 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789475918 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789573908 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789608002 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789629936 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789639950 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789664984 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789674997 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789707899 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789741039 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789766073 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789774895 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789808035 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789809942 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789843082 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789875031 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789897919 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789906979 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789921045 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789942026 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.789942980 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789974928 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.789975882 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790004015 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790009022 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790028095 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790044069 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790057898 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790096998 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790155888 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790206909 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790220022 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790241003 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790268898 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790273905 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790309906 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790313959 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790343046 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790358067 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790379047 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790381908 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790405989 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790411949 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790426970 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790446043 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790479898 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790512085 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790513992 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790545940 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790554047 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790579081 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790596008 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790611982 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790621042 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790644884 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790646076 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790667057 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790678978 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790704012 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790712118 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790733099 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790745974 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790782928 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790801048 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790816069 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790844917 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790849924 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790884018 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790885925 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790906906 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790918112 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790947914 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790950060 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.790973902 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.790982962 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.791004896 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.791017056 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.791052103 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.791079044 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.791084051 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.791116953 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.791117907 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.791152954 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.791157007 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.791181087 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.791210890 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.796186924 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.804763079 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.809611082 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870448112 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870556116 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870608091 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870641947 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870670080 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.870675087 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870707989 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870733976 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.870752096 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870839119 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.870847940 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870883942 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870917082 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870923996 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.870951891 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.870985031 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871017933 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871018887 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871047974 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871064901 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871083021 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871109962 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871145010 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871203899 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871259928 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871289015 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871349096 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871438026 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871490955 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871531963 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871565104 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871593952 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871597052 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871629953 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871632099 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871665955 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871699095 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871720076 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871751070 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871786118 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871787071 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871819973 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871869087 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871912003 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871963978 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.871970892 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.871999979 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872033119 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872066021 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872092009 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872098923 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872134924 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872136116 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872169971 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872203112 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872205973 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872235060 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872256994 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872270107 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872303009 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872334003 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872364044 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872366905 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872400999 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872401953 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872436047 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872462988 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872469902 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872503042 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872535944 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872562885 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872569084 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872601986 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872602940 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872637033 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872661114 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872669935 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872704983 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872739077 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872766018 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872771978 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872813940 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872816086 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872845888 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872880936 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872910976 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872914076 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872944117 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.872947931 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.872982025 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873004913 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.873017073 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873049021 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873081923 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873111010 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.873115063 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873147964 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873155117 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.873182058 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873205900 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.873215914 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873249054 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873284101 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:50.873311043 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:50.873347998 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.004344940 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004396915 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004482985 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.004496098 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004532099 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004585981 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.004607916 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004659891 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004693031 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004725933 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004791975 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004818916 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.004870892 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004904985 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004939079 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004954100 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.004973888 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.004990101 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005008936 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005054951 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005089998 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005125999 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005155087 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005220890 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005285978 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005321026 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005345106 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005353928 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005388021 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005395889 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005422115 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005456924 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005490065 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005500078 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005523920 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005537987 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005558968 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005592108 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005625010 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005637884 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005660057 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005673885 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005693913 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005728006 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005759954 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005770922 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005798101 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005808115 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005831957 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005865097 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005897999 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005912066 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005930901 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005945921 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.005964041 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.005996943 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006028891 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006042004 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006062984 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006077051 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006095886 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006129026 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006160975 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006172895 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006196976 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006207943 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006230116 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006263971 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006290913 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006308079 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006325006 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006341934 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006357908 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006392002 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006424904 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006434917 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006459951 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006469965 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006494999 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006527901 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006561041 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006572008 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006594896 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006611109 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006628990 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006661892 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006695032 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006704092 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006728888 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006747007 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:35:51.006766081 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006797075 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:35:51.006841898 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:36:03.566396952 CET6174310443192.168.2.4192.238.132.117
            Jan 12, 2025 08:36:03.571675062 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:36:03.886297941 CET1044361743192.238.132.117192.168.2.4
            Jan 12, 2025 08:36:03.941458941 CET6174310443192.168.2.4192.238.132.117
            TimestampSource PortDest PortSource IPDest IP
            Jan 12, 2025 08:32:05.596870899 CET5034853192.168.2.41.1.1.1
            Jan 12, 2025 08:32:06.097454071 CET53503481.1.1.1192.168.2.4
            Jan 12, 2025 08:32:19.900764942 CET53567981.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Jan 12, 2025 08:32:05.596870899 CET192.168.2.41.1.1.10x5167Standard query (0)huazai789.topA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Jan 12, 2025 08:32:06.097454071 CET1.1.1.1192.168.2.40x5167No error (0)huazai789.top192.238.132.117A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to dive into process behavior distribution

            Target ID:0
            Start time:02:31:58
            Start date:12/01/2025
            Path:C:\Users\user\Desktop\A74lw30K2g.exe
            Wow64 process (32bit):false
            Commandline:"C:\Users\user\Desktop\A74lw30K2g.exe"
            Imagebase:0x7ff6297d0000
            File size:389'632 bytes
            MD5 hash:80EFE3FA59592AB4D895DB396CED8D10
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Reset < >

              Execution Graph

              Execution Coverage:8.8%
              Dynamic/Decrypted Code Coverage:0%
              Signature Coverage:39%
              Total number of Nodes:1184
              Total number of Limit Nodes:43
              execution_graph 21719 7ff6297edfc0 21742 7ff6297edc60 21719->21742 21722 7ff6297edfe1 21725 7ff6297ee121 21722->21725 21727 7ff6297edfff 21722->21727 21723 7ff6297ee117 21762 7ff6297ee54c 7 API calls 2 library calls 21723->21762 21763 7ff6297ee54c 7 API calls 2 library calls 21725->21763 21728 7ff6297ee024 21727->21728 21733 7ff6297ee041 __scrt_release_startup_lock 21727->21733 21748 7ff6297fcb44 21727->21748 21729 7ff6297ee12c BuildCatchObjectHelperInternal 21731 7ff6297ee0aa 21752 7ff6297fc44c 21731->21752 21733->21731 21759 7ff6297fbd34 47 API calls 21733->21759 21735 7ff6297ee0af 21758 7ff6297ebcd0 10 API calls 21735->21758 21737 7ff6297ee0cc 21760 7ff6297ee6a0 GetModuleHandleW 21737->21760 21740 7ff6297ee0d3 21740->21729 21761 7ff6297edde4 7 API calls 21740->21761 21741 7ff6297ee0ea 21741->21728 21743 7ff6297edc68 21742->21743 21744 7ff6297edc74 __scrt_dllmain_crt_thread_attach 21743->21744 21745 7ff6297edc81 21744->21745 21747 7ff6297edc7d 21744->21747 21745->21747 21764 7ff6297f0128 7 API calls 2 library calls 21745->21764 21747->21722 21747->21723 21749 7ff6297fcb7a 21748->21749 21750 7ff6297fcb49 21748->21750 21749->21733 21750->21749 21765 7ff6297d1000 WSAStartup 21750->21765 21753 7ff6297fc471 21752->21753 21754 7ff6297fc45c 21752->21754 21753->21735 21754->21753 21772 7ff6297fc108 50 API calls Concurrency::details::SchedulerProxy::DeleteThis 21754->21772 21756 7ff6297fc47a 21756->21753 21773 7ff6297fc2d8 12 API calls 3 library calls 21756->21773 21758->21737 21759->21731 21760->21740 21761->21741 21762->21725 21763->21729 21764->21747 21768 7ff6297ede4c 21765->21768 21771 7ff6297ede10 50 API calls 21768->21771 21770 7ff6297d103a 21770->21750 21771->21770 21772->21756 21773->21753 22443 7ff6297dbfc0 GdipDisposeImage GdipFree 22445 7ff62980ddd0 RegCloseKey RegCloseKey 22373 7ff6297d18d0 47 API calls Concurrency::cancel_current_task 22374 7ff6297dbcd0 LCMapStringEx __crtLCMapStringW 22447 7ff6297dbbd0 GetStringTypeW 22449 7ff6297f1dcc 61 API calls 5 library calls 22450 7ff6297de3c7 ExitProcess 22376 7ff6297de2c8 144 API calls BuildCatchObjectHelperInternal 22378 7ff6297e1ce0 48 API calls 22453 7ff6297db3e0 CloseHandle RtlPcToFileHeader RaiseException 22379 7ff6297ededc 59 API calls 2 library calls 22456 7ff6297deff2 188 API calls 22384 7ff629803ef0 54 API calls 6 library calls 22386 7ff6297ee0ee GetModuleHandleW BuildCatchObjectHelperInternal 22457 7ff6297d3ff0 WaitForSingleObject Sleep WaitForSingleObject WaitForSingleObject Sleep 22458 7ff6297d9df0 49 API calls 22388 7ff6297fc8e8 11 API calls 22459 7ff629807de8 55 API calls 4 library calls 22460 7ff6297de3e9 14 API calls 22389 7ff6297ee704 56 API calls 21011 7ff6297eb500 21065 7ff6297f9c1c 21011->21065 21014 7ff6297eb573 21017 7ff6297eb580 GetCurrentProcess OpenProcessToken 21014->21017 21018 7ff6297eb64f GetLocalTime wsprintfW SetUnhandledExceptionFilter 21014->21018 21015 7ff6297eb543 21016 7ff6297ede98 std::_Facet_Register 49 API calls 21015->21016 21022 7ff6297eb54d 21016->21022 21019 7ff6297eb5f4 GetModuleHandleA GetProcAddress 21017->21019 21020 7ff6297eb59f LookupPrivilegeValueW AdjustTokenPrivileges CloseHandle 21017->21020 21073 7ff6297f8940 21018->21073 21019->21018 21023 7ff6297eb619 GetCurrentProcessId OpenProcess 21019->21023 21020->21019 21025 7ff6297f8940 52 API calls 21022->21025 21023->21018 21027 7ff6297eb56a CloseHandle 21025->21027 21027->21014 21030 7ff6297eb6ec 21098 7ff6297ead80 RegOpenKeyExW 21030->21098 21033 7ff6297eb75b CheckTokenMembership 21036 7ff6297eb775 21033->21036 21037 7ff6297eb77c FreeSid 21033->21037 21034 7ff6297eb789 21035 7ff6297eb792 RegOpenKeyExW RegDeleteValueW RegSetValueExW RegCloseKey 21034->21035 21049 7ff6297eb80d 21034->21049 21035->21049 21036->21037 21037->21034 21038 7ff6297f87a0 47 API calls std::_Locinfo::_Locinfo_ctor 21038->21049 21039 7ff6297f9c1c ProcessCodePage 47 API calls 21040 7ff6297eb91d SleepEx 21039->21040 21041 7ff6297f9c1c ProcessCodePage 47 API calls 21040->21041 21041->21049 21042 7ff6297f9c1c ProcessCodePage 47 API calls 21042->21049 21043 7ff6297eb992 CreateEventA 21144 7ff6297f87a0 21043->21144 21046 7ff6297eba3c Sleep 21050 7ff6297eba30 21046->21050 21047 7ff6297eba72 Sleep 21047->21049 21048 7ff6297ebad5 CloseHandle 21048->21049 21049->21038 21049->21039 21049->21042 21049->21043 21049->21048 21049->21050 21051 7ff6297ebae9 21049->21051 21131 7ff6297d3820 ResetEvent timeGetTime socket 21049->21131 21153 7ff6297d62f0 21049->21153 21050->21046 21050->21047 21050->21048 21278 7ff6297f3d58 21051->21278 21066 7ff6297f9c4c 21065->21066 21283 7ff6297f9480 21066->21283 21069 7ff6297f9ca0 21071 7ff6297eb52b SleepEx 21069->21071 21303 7ff6297f394c 47 API calls 2 library calls 21069->21303 21071->21014 21071->21015 21074 7ff6297f8960 21073->21074 21075 7ff6297f8977 21073->21075 21319 7ff6297f8afc 11 API calls _get_daylight 21074->21319 21312 7ff6297f88dc 21075->21312 21079 7ff6297f8965 21320 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21079->21320 21080 7ff6297eb6ca CloseHandle 21091 7ff6297ede98 21080->21091 21081 7ff6297f898a CreateThread 21081->21080 21083 7ff6297f89ba GetLastError 21081->21083 21321 7ff6297f8a70 11 API calls 2 library calls 21083->21321 21085 7ff6297f89c7 21086 7ff6297f89d0 CloseHandle 21085->21086 21087 7ff6297f89d6 21085->21087 21086->21087 21088 7ff6297f89e5 21087->21088 21089 7ff6297f89df FreeLibrary 21087->21089 21322 7ff6297fe6bc 21088->21322 21089->21088 21092 7ff6297edea3 21091->21092 21092->21091 21093 7ff6297eb6dd 21092->21093 21338 7ff6297fca30 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 21092->21338 21339 7ff6297ecb90 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 21092->21339 21340 7ff6297d19d0 49 API calls Concurrency::cancel_current_task 21092->21340 21097 7ff6297d36e0 WSAStartup CreateEventW 21093->21097 21097->21030 21099 7ff6297eadbf RegQueryValueExW 21098->21099 21100 7ff6297eadec memcpy_s 21098->21100 21099->21100 21101 7ff6297eae22 RegQueryValueExW lstrlenW 21100->21101 21129 7ff6297eb471 AllocateAndInitializeSid 21100->21129 21341 7ff62980d7b0 21101->21341 21103 7ff6297eae70 lstrlenW lstrlenW 21104 7ff6297eaf18 lstrlenW 21103->21104 21112 7ff6297eae99 BuildCatchObjectHelperInternal 21103->21112 21105 7ff62980d7b0 memcpy_s 21104->21105 21106 7ff6297eaf3d lstrlenW lstrlenW 21105->21106 21107 7ff6297eafe8 lstrlenW lstrlenW 21106->21107 21117 7ff6297eaf6a BuildCatchObjectHelperInternal 21106->21117 21108 7ff6297eb07a lstrlenW 21107->21108 21113 7ff6297eb011 21107->21113 21109 7ff62980d7b0 memcpy_s 21108->21109 21110 7ff6297eb09f lstrlenW lstrlenW 21109->21110 21111 7ff6297eb148 lstrlenW 21110->21111 21124 7ff6297eb0cc BuildCatchObjectHelperInternal 21110->21124 21114 7ff62980d7b0 memcpy_s 21111->21114 21112->21104 21113->21108 21115 7ff6297eb16d lstrlenW lstrlenW 21114->21115 21116 7ff6297eb218 lstrlenW lstrlenW 21115->21116 21120 7ff6297eb19a BuildCatchObjectHelperInternal 21115->21120 21118 7ff6297eb2aa lstrlenW 21116->21118 21123 7ff6297eb241 21116->21123 21117->21107 21119 7ff62980d7b0 memcpy_s 21118->21119 21121 7ff6297eb2cf lstrlenW lstrlenW 21119->21121 21120->21116 21122 7ff6297eb378 lstrlenW 21121->21122 21128 7ff6297eb2fc BuildCatchObjectHelperInternal 21121->21128 21125 7ff62980d7b0 memcpy_s 21122->21125 21123->21118 21124->21111 21126 7ff6297eb39d lstrlenW lstrlenW 21125->21126 21127 7ff6297eb448 lstrlenW lstrlenW 21126->21127 21130 7ff6297eb3ca BuildCatchObjectHelperInternal 21126->21130 21127->21129 21128->21122 21129->21033 21129->21034 21130->21127 21132 7ff6297d3893 lstrlenW WideCharToMultiByte 21131->21132 21133 7ff6297d3ad9 21131->21133 21134 7ff6297eded4 21132->21134 21133->21049 21135 7ff6297d38d4 lstrlenW WideCharToMultiByte gethostbyname 21134->21135 21136 7ff6297d391d 21135->21136 21136->21133 21137 7ff6297d392e htons connect 21136->21137 21137->21133 21138 7ff6297d3971 setsockopt setsockopt setsockopt setsockopt 21137->21138 21139 7ff6297d3a86 21138->21139 21140 7ff6297d3a37 WSAIoctl 21138->21140 21141 7ff6297f8940 52 API calls 21139->21141 21140->21139 21142 7ff6297d3ab0 21141->21142 21143 7ff6297f8940 52 API calls 21142->21143 21143->21133 21145 7ff6297f87ad 21144->21145 21147 7ff6297f87b7 21144->21147 21145->21147 21151 7ff6297f87d3 21145->21151 21343 7ff6297f8afc 11 API calls _get_daylight 21147->21343 21148 7ff6297f87bf 21344 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21148->21344 21149 7ff6297f87cb 21149->21049 21151->21149 21345 7ff6297f8afc 11 API calls _get_daylight 21151->21345 21154 7ff6297d631d std::_Locinfo::_Locinfo_ctor 21153->21154 21155 7ff6297ede98 std::_Facet_Register 49 API calls 21154->21155 21157 7ff6297d632a memcpy_s 21155->21157 21156 7ff6297d635e memcpy_s 21159 7ff6297d6376 gethostname gethostbyname 21156->21159 21157->21156 21158 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21157->21158 21158->21156 21160 7ff6297d63b2 inet_ntoa 21159->21160 21161 7ff6297d644f 8 API calls 21159->21161 21485 7ff6297f8f58 47 API calls 2 library calls 21160->21485 21163 7ff6297d653e GetProcAddress 21161->21163 21164 7ff6297d665c GetSystemInfo wsprintfW 21161->21164 21167 7ff6297d6653 FreeLibrary 21163->21167 21168 7ff6297d6557 21163->21168 21165 7ff6297d66a0 GetDriveTypeW 21164->21165 21169 7ff6297d66c1 GetDiskFreeSpaceExW 21165->21169 21170 7ff6297d66f8 21165->21170 21166 7ff6297d63d5 21486 7ff6297f8f58 47 API calls 2 library calls 21166->21486 21167->21164 21346 7ff6297d3670 21168->21346 21169->21170 21170->21165 21172 7ff6297d66ff GlobalMemoryStatusEx 21170->21172 21174 7ff6297d3670 50 API calls 21172->21174 21176 7ff6297d6762 21174->21176 21175 7ff6297d65a0 21350 7ff6297d91a0 GetModuleHandleW GetProcAddress 21175->21350 21178 7ff6297d3670 50 API calls 21176->21178 21177 7ff6297d6400 inet_ntoa 21487 7ff6297f8f58 47 API calls 2 library calls 21177->21487 21180 7ff6297d6786 21178->21180 21354 7ff6297d8e00 CreateDXGIFactory 21180->21354 21181 7ff6297d63ed 21181->21161 21181->21177 21488 7ff6297f8f58 47 API calls 2 library calls 21181->21488 21186 7ff6297d6799 GetForegroundWindow 21188 7ff6297d67a4 GetWindowTextW 21186->21188 21189 7ff6297d67ba lstrlenW 21186->21189 21188->21189 21366 7ff6297d8cd0 21189->21366 21190 7ff6297d6622 21191 7ff6297d6640 RegCloseKey 21190->21191 21195 7ff6297f9248 std::_Locinfo::_Locinfo_ctor 47 API calls 21190->21195 21193 7ff6297ede64 21191->21193 21193->21167 21194 7ff6297d67fa 21196 7ff6297d6823 21194->21196 21197 7ff6297d67ff GetLocalTime wsprintfW 21194->21197 21195->21191 21198 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21196->21198 21197->21196 21199 7ff6297d683b lstrlenW 21198->21199 21200 7ff6297d8cd0 6 API calls 21199->21200 21201 7ff6297d685f 21200->21201 21202 7ff6297d6878 GetModuleHandleW GetProcAddress 21201->21202 21203 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21201->21203 21204 7ff6297d68b1 GetSystemInfo 21202->21204 21205 7ff6297d68ad GetNativeSystemInfo 21202->21205 21203->21202 21206 7ff6297d68b7 wsprintfW 21204->21206 21205->21206 21375 7ff6297d8ad0 21206->21375 21209 7ff6297d6906 GetCurrentProcessId 21210 7ff6297d6a5e CoInitializeEx CoCreateInstance 21209->21210 21211 7ff6297d691c OpenProcess 21209->21211 21212 7ff6297d6b8f 21210->21212 21242 7ff6297d6a95 21210->21242 21213 7ff6297d693d K32GetProcessImageFileNameW 21211->21213 21214 7ff6297d6a57 21211->21214 21218 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21212->21218 21215 7ff6297d6a4e CloseHandle 21213->21215 21216 7ff6297d695b GetLogicalDriveStringsW 21213->21216 21214->21210 21215->21214 21217 7ff6297d6a3e lstrcpyW 21216->21217 21234 7ff6297d6975 21216->21234 21217->21215 21219 7ff6297d6bab memcpy_s 21218->21219 21222 7ff6297d6bc6 RegOpenKeyExW 21219->21222 21220 7ff6297d6990 lstrcmpiW 21221 7ff6297d69b2 lstrcmpiW 21220->21221 21220->21234 21223 7ff6297d69c6 QueryDosDeviceW 21221->21223 21221->21234 21224 7ff6297d6d52 lstrlenW 21222->21224 21225 7ff6297d6bf5 RegQueryInfoKeyW 21222->21225 21223->21215 21228 7ff6297d6a00 lstrlenW 21223->21228 21226 7ff6297d6d82 21224->21226 21227 7ff6297d6d64 21224->21227 21225->21226 21248 7ff6297d6c55 memcpy_s 21225->21248 21404 7ff6297d79e0 21226->21404 21395 7ff6297f9248 21227->21395 21489 7ff6297f90ac 53 API calls 3 library calls 21228->21489 21231 7ff6297d6b7e CoUninitialize 21231->21212 21234->21217 21234->21220 21236 7ff6297d6e8d lstrcpyW lstrcatW 21234->21236 21235 7ff6297f9248 std::_Locinfo::_Locinfo_ctor 47 API calls 21237 7ff6297d6da1 GetTickCount 21235->21237 21236->21215 21422 7ff6297f8b9c GetSystemTimeAsFileTime 21237->21422 21238 7ff6297d6d47 RegCloseKey 21238->21224 21242->21212 21242->21231 21245 7ff6297d6b36 SysFreeString 21242->21245 21243 7ff6297d6cb4 RegEnumKeyExW lstrlenW 21246 7ff6297d6cf7 lstrlenW 21243->21246 21243->21248 21245->21242 21246->21248 21247 7ff6297d6e7f 21429 7ff6297d7250 21247->21429 21248->21224 21248->21238 21248->21243 21252 7ff6297f8b24 47 API calls std::_Locinfo::_Locinfo_ctor 21248->21252 21250 7ff6297d6ed1 lstrlenW 21251 7ff6297d8cd0 6 API calls 21250->21251 21253 7ff6297d6f0a 21251->21253 21252->21248 21254 7ff6297d6f13 6 API calls 21253->21254 21255 7ff6297d6fe7 CreateToolhelp32Snapshot 21253->21255 21256 7ff6297d6fda RegCloseKey 21254->21256 21257 7ff6297d6f98 lstrlenW RegSetValueExW 21254->21257 21258 7ff6297d7001 memcpy_s 21255->21258 21259 7ff6297d7088 CreateToolhelp32Snapshot 21255->21259 21256->21255 21257->21256 21261 7ff6297d6fcd RegCloseKey 21257->21261 21264 7ff6297d7015 Process32FirstW 21258->21264 21262 7ff6297d70ab memcpy_s 21259->21262 21263 7ff6297d7138 CreateToolhelp32Snapshot 21259->21263 21261->21256 21266 7ff6297d70bf Process32FirstW 21262->21266 21267 7ff6297d71e4 21263->21267 21268 7ff6297d715b memcpy_s 21263->21268 21264->21259 21272 7ff6297d7033 21264->21272 21266->21263 21274 7ff6297d70dd 21266->21274 21469 7ff6297d3e30 GetCurrentThreadId 21267->21469 21269 7ff6297d716f Process32FirstW 21268->21269 21269->21267 21276 7ff6297d718d 21269->21276 21270 7ff6297d721c 21270->21049 21271 7ff6297d7074 Process32NextW 21271->21259 21271->21272 21272->21259 21272->21271 21273 7ff6297d7124 Process32NextW 21273->21263 21273->21274 21274->21263 21274->21273 21275 7ff6297d71d0 Process32NextW 21275->21267 21275->21276 21276->21267 21276->21275 21718 7ff6297f3bd0 47 API calls _invalid_parameter_noinfo 21278->21718 21280 7ff6297f3d71 21281 7ff6297f3d88 _invalid_parameter_noinfo_noreturn 17 API calls 21280->21281 21282 7ff6297f3d86 21281->21282 21284 7ff6297f94ca 21283->21284 21285 7ff6297f94b8 21283->21285 21287 7ff6297f9514 21284->21287 21289 7ff6297f94d8 21284->21289 21304 7ff6297f8afc 11 API calls _get_daylight 21285->21304 21293 7ff6297f952f ProcessCodePage 21287->21293 21307 7ff6297f8160 47 API calls 2 library calls 21287->21307 21288 7ff6297f94bd 21305 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21288->21305 21306 7ff6297f3c6c 47 API calls 2 library calls 21289->21306 21294 7ff6297f98b5 21293->21294 21308 7ff6297f8afc 11 API calls _get_daylight 21293->21308 21301 7ff6297f94c8 21294->21301 21310 7ff6297f8afc 11 API calls _get_daylight 21294->21310 21297 7ff6297f98aa 21309 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21297->21309 21298 7ff6297f9b46 21311 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21298->21311 21301->21069 21302 7ff6297f394c 47 API calls 2 library calls 21301->21302 21302->21069 21303->21071 21304->21288 21305->21301 21306->21301 21307->21293 21308->21297 21309->21294 21310->21298 21311->21301 21328 7ff629800788 21312->21328 21315 7ff6297fe6bc Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21316 7ff6297f8908 21315->21316 21317 7ff6297f8911 GetModuleHandleExW 21316->21317 21318 7ff6297f890d 21316->21318 21317->21318 21318->21080 21318->21081 21319->21079 21320->21080 21321->21085 21323 7ff6297fe6c1 RtlFreeHeap 21322->21323 21324 7ff6297fe6f0 21322->21324 21323->21324 21325 7ff6297fe6dc GetLastError 21323->21325 21324->21080 21326 7ff6297fe6e9 Concurrency::details::SchedulerProxy::DeleteThis 21325->21326 21337 7ff6297f8afc 11 API calls _get_daylight 21326->21337 21333 7ff629800799 _get_daylight 21328->21333 21329 7ff6298007ea 21336 7ff6297f8afc 11 API calls _get_daylight 21329->21336 21330 7ff6298007ce HeapAlloc 21331 7ff6297f88fe 21330->21331 21330->21333 21331->21315 21333->21329 21333->21330 21335 7ff6297fca30 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 21333->21335 21335->21333 21336->21331 21337->21324 21338->21092 21340->21092 21342 7ff62980d7a0 21341->21342 21342->21103 21342->21342 21343->21148 21344->21149 21345->21148 21347 7ff6297d3695 21346->21347 21490 7ff6297f868c 21347->21490 21351 7ff6297d91e1 GetSystemInfo 21350->21351 21352 7ff6297d91dd GetNativeSystemInfo 21350->21352 21353 7ff6297d65c2 RegOpenKeyExW RegQueryValueExW 21351->21353 21352->21353 21353->21190 21353->21191 21356 7ff6297d9143 21354->21356 21360 7ff6297d8e5a 21354->21360 21355 7ff6297d9175 21355->21186 21356->21355 21357 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 21356->21357 21359 7ff6297d9196 21357->21359 21361 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 21359->21361 21364 7ff6297d8ed5 21360->21364 21504 7ff6297da4c0 49 API calls BuildCatchObjectHelperInternal 21360->21504 21362 7ff6297d919c 21361->21362 21364->21356 21364->21359 21365 7ff6297d3670 50 API calls 21364->21365 21505 7ff6297da4c0 49 API calls BuildCatchObjectHelperInternal 21364->21505 21365->21364 21367 7ff62980d7b0 memcpy_s 21366->21367 21368 7ff6297d8d11 RegOpenKeyExW 21367->21368 21371 7ff6297d8d46 21368->21371 21374 7ff6297d8d3c 21368->21374 21369 7ff6297d8dc8 RegCloseKey RegCloseKey 21369->21194 21370 7ff6297d8d54 RegQueryValueExW 21370->21369 21372 7ff6297d8d93 lstrcmpW 21370->21372 21371->21369 21371->21370 21373 7ff6297d8db0 lstrcpyW 21372->21373 21372->21374 21373->21369 21374->21369 21376 7ff6297eded4 21375->21376 21377 7ff6297d8ae8 GetCurrentProcessId wsprintfW 21376->21377 21506 7ff6297d8900 GetCurrentProcessId OpenProcess 21377->21506 21379 7ff6297d8b10 memcpy_s 21380 7ff6297d8b24 GetVersionExW 21379->21380 21381 7ff6297d8c92 21380->21381 21382 7ff6297d8b3f 21380->21382 21383 7ff6297d8c99 wsprintfW 21381->21383 21382->21381 21385 7ff6297d8b55 GetCurrentProcess OpenProcessToken 21382->21385 21384 7ff6297d8ca9 21383->21384 21384->21209 21385->21381 21386 7ff6297d8b81 GetTokenInformation 21385->21386 21387 7ff6297d8c3c CloseHandle 21386->21387 21388 7ff6297d8bb6 GetLastError 21386->21388 21387->21381 21392 7ff6297d8c4e 21387->21392 21388->21387 21389 7ff6297d8bc1 LocalAlloc 21388->21389 21390 7ff6297d8be3 GetTokenInformation 21389->21390 21391 7ff6297d8c34 21389->21391 21393 7ff6297d8c12 GetSidSubAuthorityCount GetSidSubAuthority 21390->21393 21394 7ff6297d8c2b LocalFree 21390->21394 21391->21387 21392->21383 21392->21384 21393->21394 21394->21391 21398 7ff6297f9265 21395->21398 21396 7ff6297f926a 21400 7ff6297f9280 21396->21400 21556 7ff6297f8afc 11 API calls _get_daylight 21396->21556 21398->21396 21398->21400 21401 7ff6297f92b6 21398->21401 21400->21226 21401->21400 21558 7ff6297f8afc 11 API calls _get_daylight 21401->21558 21403 7ff6297f9274 21557 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21403->21557 21407 7ff6297d7a13 memcpy_s 21404->21407 21405 7ff6297d7afc CoCreateInstance 21406 7ff6297d7d21 lstrlenW 21405->21406 21418 7ff6297d7b2d memcpy_s 21405->21418 21408 7ff6297d7d2e lstrcatW 21406->21408 21409 7ff6297d6d87 21406->21409 21407->21405 21410 7ff6297d7a64 CreateToolhelp32Snapshot 21407->21410 21414 7ff6297d7d65 CloseHandle 21407->21414 21415 7ff6297d7abf Process32NextW 21407->21415 21408->21409 21409->21235 21410->21407 21412 7ff6297d7a7a Process32FirstW 21410->21412 21411 7ff6297d7d0f 21411->21406 21412->21407 21413 7ff6297d7acd CloseHandle 21412->21413 21413->21407 21414->21407 21417 7ff6297d7d75 lstrcatW lstrcatW 21414->21417 21415->21407 21415->21413 21416 7ff6297d7bb5 wsprintfW RegOpenKeyExW 21416->21418 21417->21407 21418->21411 21418->21416 21419 7ff6297d7c77 RegQueryValueExW 21418->21419 21420 7ff6297d7ce0 RegCloseKey 21419->21420 21421 7ff6297d7cc0 lstrcatW lstrcatW 21419->21421 21420->21418 21421->21420 21423 7ff6297d6db2 21422->21423 21424 7ff6297f8f10 21423->21424 21559 7ff62980177c 21424->21559 21427 7ff6297d6dd2 wsprintfW GetLocaleInfoW GetSystemDirectoryW GetCurrentHwProfileW 21427->21247 21430 7ff6297d72b0 21429->21430 21430->21430 21432 7ff6297d72c6 BuildCatchObjectHelperInternal 21430->21432 21675 7ff6297da300 49 API calls 4 library calls 21430->21675 21434 7ff6297d7312 BuildCatchObjectHelperInternal 21432->21434 21676 7ff6297da300 49 API calls 4 library calls 21432->21676 21436 7ff6297d7381 BuildCatchObjectHelperInternal 21434->21436 21677 7ff6297da300 49 API calls 4 library calls 21434->21677 21438 7ff6297d73f4 BuildCatchObjectHelperInternal 21436->21438 21678 7ff6297da300 49 API calls 4 library calls 21436->21678 21440 7ff6297d744f BuildCatchObjectHelperInternal 21438->21440 21679 7ff6297da300 49 API calls 4 library calls 21438->21679 21442 7ff6297d74d0 BuildCatchObjectHelperInternal 21440->21442 21680 7ff6297da300 49 API calls 4 library calls 21440->21680 21444 7ff6297d7540 BuildCatchObjectHelperInternal 21442->21444 21681 7ff6297da300 49 API calls 4 library calls 21442->21681 21669 7ff6297e9b00 21444->21669 21447 7ff6297d7636 21448 7ff6297d76ad 21447->21448 21449 7ff6297d76d8 21447->21449 21451 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 21447->21451 21448->21250 21450 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 21449->21450 21452 7ff6297d76de CreateMutexExW GetLastError 21450->21452 21451->21449 21453 7ff6297d7749 21452->21453 21454 7ff6297d7719 21452->21454 21456 7ff6297d77f0 9 API calls 21453->21456 21459 7ff6297d7760 lstrlenW 21453->21459 21455 7ff6297d7720 Sleep CreateMutexW GetLastError 21454->21455 21455->21453 21455->21455 21457 7ff6297d78a4 DeleteFileW 21456->21457 21458 7ff6297d78ad ReleaseMutex DirectInput8Create 21456->21458 21457->21458 21460 7ff6297d7980 21458->21460 21465 7ff6297d78e3 21458->21465 21461 7ff6297d8cd0 6 API calls 21459->21461 21460->21250 21462 7ff6297d77be 21461->21462 21463 7ff6297d77c2 lstrcmpW 21462->21463 21464 7ff6297d77d8 SleepEx 21462->21464 21463->21456 21463->21464 21464->21456 21464->21459 21465->21460 21466 7ff6297d799f GetTickCount GetKeyState 21465->21466 21682 7ff6297dadb0 37 API calls 3 library calls 21466->21682 21470 7ff6297d3e5c 21469->21470 21699 7ff6297d1670 21470->21699 21472 7ff6297d3e9b 21473 7ff6297d1670 2 API calls 21472->21473 21474 7ff6297d3ec4 21473->21474 21706 7ff6297d1500 21474->21706 21476 7ff6297d3efa 21477 7ff6297d3f06 21476->21477 21483 7ff6297d3f1a 21476->21483 21478 7ff6297d3fa1 21477->21478 21479 7ff6297d3f80 send 21477->21479 21712 7ff6297d1730 21478->21712 21479->21477 21479->21478 21481 7ff6297d3f30 send 21481->21483 21482 7ff6297d3fba GetCurrentThreadId 21484 7ff6297d3fca 21482->21484 21483->21477 21483->21478 21483->21481 21484->21270 21485->21166 21486->21181 21487->21181 21488->21181 21489->21234 21492 7ff6297f86c5 21490->21492 21491 7ff6297f8708 21494 7ff6297f8747 21491->21494 21501 7ff6297f3c6c 47 API calls 2 library calls 21491->21501 21492->21491 21500 7ff6297f3fe0 50 API calls 3 library calls 21492->21500 21496 7ff6297f876d 21494->21496 21502 7ff6297f394c 47 API calls 2 library calls 21494->21502 21498 7ff6297d36b4 21496->21498 21503 7ff6297f394c 47 API calls 2 library calls 21496->21503 21498->21175 21500->21491 21501->21494 21502->21496 21503->21498 21504->21360 21505->21364 21507 7ff6297d893a OpenProcessToken 21506->21507 21515 7ff6297d8967 21506->21515 21508 7ff6297d895e CloseHandle 21507->21508 21509 7ff6297d8971 21507->21509 21508->21515 21537 7ff6297d8690 21509->21537 21511 7ff6297d89bb BuildCatchObjectHelperInternal 21512 7ff6297d89e8 CloseHandle CloseHandle 21511->21512 21513 7ff6297d8a14 21512->21513 21514 7ff6297d8aba 21513->21514 21513->21515 21518 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 21513->21518 21516 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 21514->21516 21515->21379 21517 7ff6297d8ac0 21516->21517 21519 7ff6297d8ae8 GetCurrentProcessId wsprintfW 21517->21519 21518->21514 21520 7ff6297d8900 58 API calls 21519->21520 21521 7ff6297d8b10 memcpy_s 21520->21521 21522 7ff6297d8b24 GetVersionExW 21521->21522 21523 7ff6297d8c92 21522->21523 21524 7ff6297d8b3f 21522->21524 21525 7ff6297d8c99 wsprintfW 21523->21525 21524->21523 21527 7ff6297d8b55 GetCurrentProcess OpenProcessToken 21524->21527 21526 7ff6297d8ca9 21525->21526 21526->21379 21527->21523 21528 7ff6297d8b81 GetTokenInformation 21527->21528 21529 7ff6297d8c3c CloseHandle 21528->21529 21530 7ff6297d8bb6 GetLastError 21528->21530 21529->21523 21536 7ff6297d8c4e 21529->21536 21530->21529 21531 7ff6297d8bc1 LocalAlloc 21530->21531 21532 7ff6297d8be3 GetTokenInformation 21531->21532 21533 7ff6297d8c34 21531->21533 21534 7ff6297d8c12 GetSidSubAuthorityCount GetSidSubAuthority 21532->21534 21535 7ff6297d8c2b LocalFree 21532->21535 21533->21529 21534->21535 21535->21533 21536->21525 21536->21526 21538 7ff6297d86c1 21537->21538 21539 7ff6297d86f3 GetTokenInformation 21538->21539 21540 7ff6297d87e8 21538->21540 21541 7ff6297d8715 GetLastError 21539->21541 21542 7ff6297d874e GetTokenInformation 21539->21542 21540->21511 21541->21540 21543 7ff6297d8724 GetProcessHeap HeapAlloc 21541->21543 21544 7ff6297d877c LookupAccountSidW 21542->21544 21553 7ff6297d87e3 BuildCatchObjectHelperInternal 21542->21553 21543->21540 21543->21542 21546 7ff6297d87c0 GetLastError 21544->21546 21549 7ff6297d87ef 21544->21549 21545 7ff6297d88c4 GetProcessHeap HeapFree 21545->21540 21546->21540 21547 7ff6297d87cd 21546->21547 21548 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21547->21548 21548->21553 21551 7ff6297d881a BuildCatchObjectHelperInternal 21549->21551 21554 7ff6297da1a0 49 API calls 4 library calls 21549->21554 21551->21553 21555 7ff6297da1a0 49 API calls 4 library calls 21551->21555 21553->21540 21553->21545 21554->21551 21555->21553 21556->21403 21557->21400 21558->21403 21599 7ff6297febe8 GetLastError 21559->21599 21561 7ff629801787 21562 7ff6298017ab 21561->21562 21564 7ff6297f8f27 21561->21564 21616 7ff6297fedd0 21561->21616 21562->21564 21623 7ff6297f8afc 11 API calls _get_daylight 21562->21623 21564->21427 21568 7ff6297f8c10 21564->21568 21567 7ff6297fe6bc Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21567->21562 21569 7ff6297f8c41 21568->21569 21570 7ff6297f8c26 21568->21570 21569->21570 21572 7ff6297f8c5a 21569->21572 21644 7ff6297f8afc 11 API calls _get_daylight 21570->21644 21574 7ff6297f8c60 21572->21574 21577 7ff6297f8c7d 21572->21577 21573 7ff6297f8c2b 21645 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21573->21645 21646 7ff6297f8afc 11 API calls _get_daylight 21574->21646 21627 7ff62980233c 21577->21627 21582 7ff6297f8ef7 21640 7ff6297f3d88 IsProcessorFeaturePresent 21582->21640 21586 7ff6297f8f0c 21587 7ff62980177c 12 API calls 21586->21587 21589 7ff6297f8f27 21587->21589 21591 7ff6297f8f3c 21589->21591 21593 7ff6297f8c10 61 API calls 21589->21593 21591->21427 21592 7ff6297f8cc1 21594 7ff6297f8d3a 21592->21594 21595 7ff6297f8cda 21592->21595 21593->21591 21598 7ff6297f8c37 21594->21598 21660 7ff629802380 47 API calls _isindst 21594->21660 21595->21598 21659 7ff629802380 47 API calls _isindst 21595->21659 21598->21427 21600 7ff6297fec29 FlsSetValue 21599->21600 21605 7ff6297fec0c 21599->21605 21601 7ff6297fec3b 21600->21601 21606 7ff6297fec19 21600->21606 21602 7ff629800788 _get_daylight 5 API calls 21601->21602 21604 7ff6297fec4a 21602->21604 21603 7ff6297fec95 SetLastError 21603->21561 21607 7ff6297fec68 FlsSetValue 21604->21607 21608 7ff6297fec58 FlsSetValue 21604->21608 21605->21600 21605->21606 21606->21603 21610 7ff6297fec74 FlsSetValue 21607->21610 21611 7ff6297fec86 21607->21611 21609 7ff6297fec61 21608->21609 21612 7ff6297fe6bc Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 21609->21612 21610->21609 21624 7ff6297fe820 11 API calls _get_daylight 21611->21624 21612->21606 21614 7ff6297fec8e 21615 7ff6297fe6bc Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 21614->21615 21615->21603 21617 7ff6297fee1b 21616->21617 21622 7ff6297feddf _get_daylight 21616->21622 21626 7ff6297f8afc 11 API calls _get_daylight 21617->21626 21619 7ff6297fee02 HeapAlloc 21620 7ff6297fee19 21619->21620 21619->21622 21620->21567 21622->21617 21622->21619 21625 7ff6297fca30 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 21622->21625 21623->21564 21624->21614 21625->21622 21626->21620 21628 7ff62980234b 21627->21628 21629 7ff6297f8c82 21627->21629 21661 7ff6297faba4 EnterCriticalSection 21628->21661 21634 7ff629801464 21629->21634 21631 7ff629802353 21632 7ff629802364 21631->21632 21633 7ff6298021ac 61 API calls 21631->21633 21633->21632 21635 7ff6297f8c97 21634->21635 21636 7ff62980146d 21634->21636 21635->21582 21647 7ff629801494 21635->21647 21662 7ff6297f8afc 11 API calls _get_daylight 21636->21662 21638 7ff629801472 21663 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21638->21663 21641 7ff6297f3d9b 21640->21641 21664 7ff6297f3a6c 14 API calls 2 library calls 21641->21664 21643 7ff6297f3db6 GetCurrentProcess TerminateProcess 21644->21573 21645->21598 21646->21598 21648 7ff62980149d 21647->21648 21652 7ff6297f8ca8 21647->21652 21665 7ff6297f8afc 11 API calls _get_daylight 21648->21665 21650 7ff6298014a2 21666 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21650->21666 21652->21582 21653 7ff6298014c4 21652->21653 21654 7ff6297f8cb9 21653->21654 21655 7ff6298014cd 21653->21655 21654->21582 21654->21592 21667 7ff6297f8afc 11 API calls _get_daylight 21655->21667 21657 7ff6298014d2 21668 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 21657->21668 21659->21598 21660->21598 21662->21638 21663->21635 21664->21643 21665->21650 21666->21652 21667->21657 21668->21654 21671 7ff6297e9b2d 21669->21671 21683 7ff6297e9d20 21671->21683 21672 7ff6297e9c2f 21673 7ff6297e9e70 49 API calls 21672->21673 21674 7ff6297d75dd MultiByteToWideChar MultiByteToWideChar 21672->21674 21673->21672 21674->21447 21675->21432 21676->21434 21677->21436 21678->21438 21679->21440 21680->21442 21681->21444 21684 7ff6297e9e65 21683->21684 21687 7ff6297e9d49 21683->21687 21698 7ff6297d61c0 49 API calls 21684->21698 21689 7ff6297e9da1 21687->21689 21690 7ff6297e9ddd 21687->21690 21695 7ff6297e9d94 BuildCatchObjectHelperInternal 21687->21695 21688 7ff6297ede98 std::_Facet_Register 49 API calls 21688->21695 21689->21688 21691 7ff6297e9e5f 21689->21691 21692 7ff6297ede98 std::_Facet_Register 49 API calls 21690->21692 21697 7ff6297d19d0 49 API calls Concurrency::cancel_current_task 21691->21697 21692->21695 21694 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 21694->21691 21695->21694 21696 7ff6297e9e27 BuildCatchObjectHelperInternal 21695->21696 21696->21672 21697->21684 21700 7ff6297d167e 21699->21700 21701 7ff6297d1686 21699->21701 21700->21472 21702 7ff6297d16ac VirtualAlloc 21701->21702 21703 7ff6297d16d6 BuildCatchObjectHelperInternal 21702->21703 21704 7ff6297d1704 21703->21704 21705 7ff6297d16f6 VirtualFree 21703->21705 21704->21472 21705->21704 21707 7ff6297d152a 21706->21707 21708 7ff6297d155b VirtualAlloc 21707->21708 21709 7ff6297d15b5 BuildCatchObjectHelperInternal 21707->21709 21710 7ff6297d1587 BuildCatchObjectHelperInternal 21708->21710 21709->21476 21710->21709 21711 7ff6297d15a7 VirtualFree 21710->21711 21711->21709 21713 7ff6297d174b 21712->21713 21714 7ff6297d17fb 21713->21714 21715 7ff6297d177c VirtualAlloc 21713->21715 21714->21482 21716 7ff6297d17a8 BuildCatchObjectHelperInternal 21715->21716 21717 7ff6297d17be VirtualFree 21716->21717 21717->21482 21718->21280 22390 7ff6297f0100 10 API calls 2 library calls 22391 7ff6297d5300 115 API calls 22462 7ff6297d5200 8 API calls BuildCatchObjectHelperInternal 22463 7ff62980ce0c RtlUnwindEx __GSHandlerCheck_SEH __GSHandlerCheckCommon 22392 7ff6297e1300 8 API calls 22393 7ff6297fa4f8 60 API calls 5 library calls 22394 7ff62980cf14 57 API calls 2 library calls 22465 7ff6297fcc10 GetCommandLineA GetCommandLineW 22466 7ff6297d5410 36 API calls 22467 7ff6297dd410 360 API calls 6 library calls 22396 7ff62980070c 57 API calls _isindst 21774 7ff6297f8808 21775 7ff6297f8825 21774->21775 21776 7ff6297f8816 GetLastError ExitThread 21774->21776 21790 7ff6297fea70 GetLastError 21775->21790 21781 7ff6297f8843 21787 7ff6297d7250 116 API calls 21781->21787 21816 7ff6297d3da0 21781->21816 21824 7ff6297dcd40 21781->21824 21877 7ff6297d3b00 21781->21877 21783 7ff6297f8862 21894 7ff6297f8a1c 21783->21894 21787->21783 21791 7ff6297fea94 FlsGetValue 21790->21791 21792 7ff6297feab1 FlsSetValue 21790->21792 21793 7ff6297feaab 21791->21793 21810 7ff6297feaa1 21791->21810 21794 7ff6297feac3 21792->21794 21792->21810 21793->21792 21796 7ff629800788 _get_daylight 11 API calls 21794->21796 21795 7ff6297feb1d SetLastError 21797 7ff6297feb3d 21795->21797 21798 7ff6297f882a 21795->21798 21799 7ff6297fead2 21796->21799 21899 7ff6297f3dd8 47 API calls BuildCatchObjectHelperInternal 21797->21899 21812 7ff62980137c 21798->21812 21801 7ff6297feaf0 FlsSetValue 21799->21801 21802 7ff6297feae0 FlsSetValue 21799->21802 21803 7ff6297feb0e 21801->21803 21804 7ff6297feafc FlsSetValue 21801->21804 21806 7ff6297feae9 21802->21806 21898 7ff6297fe820 11 API calls _get_daylight 21803->21898 21804->21806 21808 7ff6297fe6bc Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21806->21808 21808->21810 21809 7ff6297feb16 21811 7ff6297fe6bc Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21809->21811 21810->21795 21811->21795 21813 7ff6297f8836 21812->21813 21814 7ff62980138b 21812->21814 21813->21781 21897 7ff6298010b0 5 API calls std::_Locinfo::_Locinfo_ctor 21813->21897 21814->21813 21900 7ff629800ac8 5 API calls std::_Locinfo::_Locinfo_ctor 21814->21900 21817 7ff6297d3e22 21816->21817 21821 7ff6297d3db4 21816->21821 21817->21783 21818 7ff6297d3e15 21818->21783 21819 7ff6297d3dc8 SleepEx 21819->21821 21820 7ff6297d3df1 timeGetTime 21820->21821 21821->21818 21821->21819 21822 7ff6297d3e30 10 API calls 21821->21822 21901 7ff6297d37a0 21821->21901 21822->21820 21825 7ff6297dd233 21824->21825 21830 7ff6297dcd78 21824->21830 21908 7ff6297ea5a0 21825->21908 21829 7ff6297dce26 21831 7ff6297dce8f memcpy_s 21829->21831 21842 7ff6297ede98 std::_Facet_Register 49 API calls 21829->21842 21830->21829 21833 7ff6297dd092 21830->21833 21834 7ff6297dcf09 GetSystemDirectoryA 21831->21834 21836 7ff6297ede98 std::_Facet_Register 49 API calls 21833->21836 21904 7ff6297d9e10 21834->21904 21835 7ff6297ede98 std::_Facet_Register 49 API calls 21839 7ff6297dd393 memcpy_s 21835->21839 21840 7ff6297dd09f memcpy_s 21836->21840 21837 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21841 7ff6297dd27f 21837->21841 21851 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21839->21851 21852 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21840->21852 21844 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21841->21844 21845 7ff6297dd0eb memcpy_s 21842->21845 21848 7ff6297dd291 21844->21848 21854 7ff6297f9248 std::_Locinfo::_Locinfo_ctor 47 API calls 21845->21854 21846 7ff6297dd1ae 21849 7ff6297ede98 std::_Facet_Register 49 API calls 21846->21849 21847 7ff6297dcf7c VirtualAllocEx 21847->21846 21850 7ff6297dcfa9 WriteProcessMemory 21847->21850 21853 7ff6297ede98 std::_Facet_Register 49 API calls 21848->21853 21855 7ff6297dd1bf memcpy_s 21849->21855 21850->21846 21856 7ff6297dcfca GetThreadContext 21850->21856 21866 7ff6297dd080 21851->21866 21852->21866 21857 7ff6297dd2a2 memcpy_s 21853->21857 21854->21831 21860 7ff6297d3670 50 API calls 21855->21860 21856->21846 21858 7ff6297dcfee SetThreadContext 21856->21858 21862 7ff6297d3670 50 API calls 21857->21862 21858->21846 21859 7ff6297dd00f ResumeThread 21858->21859 21861 7ff6297ede98 std::_Facet_Register 49 API calls 21859->21861 21860->21866 21864 7ff6297dd02b memcpy_s 21861->21864 21863 7ff6297dd2df 21862->21863 21868 7ff6297dd2f9 21863->21868 21876 7ff6297d3e30 10 API calls 21863->21876 21865 7ff6297d3670 50 API calls 21864->21865 21867 7ff6297dd067 21865->21867 21866->21783 21867->21866 21875 7ff6297d3e30 10 API calls 21867->21875 21952 7ff6297eac60 21868->21952 21871 7ff6297ede98 std::_Facet_Register 49 API calls 21872 7ff6297dd339 memcpy_s 21871->21872 21873 7ff6297d3670 50 API calls 21872->21873 21874 7ff6297dd375 21873->21874 21874->21835 21875->21866 21876->21868 21886 7ff6297d3b18 21877->21886 21878 7ff6297d3c54 21878->21783 21879 7ff6297d3be0 select 21879->21878 21879->21886 21880 7ff6297d3c08 recv 21880->21886 21881 7ff6297d1500 VirtualAlloc VirtualFree 21881->21886 21882 7ff6297d1730 2 API calls 21882->21886 21883 7ff6297f8afc 11 API calls _get_daylight 21883->21886 21884 7ff6297d3d04 timeGetTime 21885 7ff6297d1730 2 API calls 21884->21885 21885->21886 21886->21878 21886->21879 21886->21880 21886->21881 21886->21882 21886->21883 21886->21884 21996 7ff6297ddbef 21886->21996 22004 7ff6297dde3f 21886->22004 22017 7ff6297deed0 21886->22017 22024 7ff6297ddc4d 21886->22024 22039 7ff6297de29b 21886->22039 22043 7ff6297dd9c0 21886->22043 22058 7ff6297d1810 VirtualAlloc VirtualFree BuildCatchObjectHelperInternal 21886->22058 22358 7ff6297f8878 21894->22358 21897->21781 21898->21809 21900->21813 21902 7ff6297d37af setsockopt CancelIo closesocket SetEvent 21901->21902 21903 7ff6297d381a 21901->21903 21902->21903 21903->21821 21905 7ff6297d9e36 21904->21905 21958 7ff6297f8578 21905->21958 21909 7ff6297ea5c3 21908->21909 21910 7ff6297ea5e0 SetLastError 21908->21910 21909->21910 21911 7ff6297eaaad SetLastError 21909->21911 21915 7ff6297ea5f2 21909->21915 21912 7ff6297dd242 21910->21912 21911->21912 21912->21866 21944 7ff6297eaaf0 21912->21944 21913 7ff6297ea665 GetNativeSystemInfo 21913->21911 21914 7ff6297ea69c VirtualAlloc 21913->21914 21916 7ff6297ea6cd VirtualAlloc 21914->21916 21921 7ff6297ea6f0 21914->21921 21915->21911 21915->21913 21917 7ff6297ea7c7 SetLastError 21916->21917 21916->21921 21917->21912 21918 7ff6297ea762 GetProcessHeap HeapAlloc 21919 7ff6297ea86c 21918->21919 21920 7ff6297ea788 VirtualFree 21918->21920 21923 7ff6297ea8cf SetLastError 21919->21923 21924 7ff6297ea8e7 VirtualAlloc 21919->21924 21920->21917 21922 7ff6297ea79e __std_exception_destroy 21920->21922 21921->21918 21926 7ff6297ea829 VirtualFree 21921->21926 21927 7ff6297ea726 VirtualAlloc 21921->21927 21922->21917 21925 7ff6297ea7a0 VirtualFree 21922->21925 21938 7ff6297ea8da BuildCatchObjectHelperInternal 21923->21938 21924->21938 21925->21922 21926->21917 21930 7ff6297ea83f __std_exception_destroy 21926->21930 21931 7ff6297ea753 21927->21931 21932 7ff6297ea800 VirtualFree 21927->21932 21928 7ff6297eac60 3 API calls 21928->21938 21934 7ff6297ea840 VirtualFree 21930->21934 21936 7ff6297ea867 21930->21936 21931->21918 21931->21921 21933 7ff6297ea81f __std_exception_destroy 21932->21933 21933->21932 21935 7ff6297ea827 21933->21935 21934->21930 21935->21917 21936->21917 21938->21924 21938->21928 21940 7ff6297eaa01 21938->21940 21972 7ff6297ea000 21938->21972 21977 7ff6297ea3d0 21938->21977 21986 7ff6297ea140 21938->21986 21941 7ff6297eaa6e SetLastError 21940->21941 21943 7ff6297eaa81 21940->21943 21942 7ff6297eac60 3 API calls 21941->21942 21942->21943 21943->21911 21945 7ff6297eab57 21944->21945 21950 7ff6297eab2d 21944->21950 21946 7ff6297eac3a SetLastError 21945->21946 21947 7ff6297dd256 21945->21947 21946->21947 21947->21837 21947->21874 21948 7ff6297eabed 21995 7ff6297fa290 47 API calls 2 library calls 21948->21995 21950->21945 21950->21948 21994 7ff6297f9e80 47 API calls 3 library calls 21950->21994 21953 7ff6297dd328 21952->21953 21956 7ff6297eac69 __std_exception_destroy 21952->21956 21953->21871 21954 7ff6297eacf4 VirtualFree 21957 7ff6297ead03 __std_exception_destroy 21954->21957 21955 7ff6297ead45 GetProcessHeap HeapFree 21955->21953 21956->21954 21956->21957 21957->21955 21959 7ff6297f85b1 21958->21959 21962 7ff6297f85f4 21959->21962 21968 7ff6297f3e30 51 API calls 3 library calls 21959->21968 21963 7ff6297f8633 21962->21963 21969 7ff6297f3c6c 47 API calls 2 library calls 21962->21969 21964 7ff6297f8659 21963->21964 21970 7ff6297f394c 47 API calls 2 library calls 21963->21970 21966 7ff6297d9e58 CreateProcessA 21964->21966 21971 7ff6297f394c 47 API calls 2 library calls 21964->21971 21966->21846 21966->21847 21968->21962 21969->21963 21970->21964 21971->21966 21973 7ff6297ea118 21972->21973 21976 7ff6297ea041 memcpy_s BuildCatchObjectHelperInternal 21972->21976 21973->21938 21974 7ff6297ea0b0 VirtualAlloc 21974->21973 21974->21976 21975 7ff6297ea10d SetLastError 21975->21973 21976->21973 21976->21974 21976->21975 21978 7ff6297ea3f7 IsBadReadPtr 21977->21978 21979 7ff6297ea4f1 21977->21979 21978->21979 21983 7ff6297ea41c 21978->21983 21979->21938 21981 7ff6297ea50d SetLastError 21981->21979 21982 7ff6297ea4d7 IsBadReadPtr 21982->21979 21982->21983 21983->21979 21983->21981 21983->21982 21984 7ff6297ea4f3 SetLastError 21983->21984 21984->21979 21993 7ff6297ea183 21986->21993 21987 7ff6297ea328 21988 7ff6297ea351 21987->21988 21989 7ff6297ea372 VirtualProtect 21987->21989 21990 7ff6297ea339 21987->21990 21988->21938 21989->21988 21990->21988 21991 7ff6297ea33e VirtualFree 21990->21991 21991->21988 21992 7ff6297ea281 VirtualProtect 21992->21988 21992->21993 21993->21987 21993->21992 21994->21948 21995->21945 21997 7ff6297ddbfb 21996->21997 21998 7ff6297de2c3 21996->21998 21999 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 21997->21999 22000 7ff6297ddc19 21997->22000 21998->21886 21999->22000 22000->21998 22059 7ff6297df410 22000->22059 22002 7ff6297ddc41 22002->21998 22003 7ff6297d3e30 10 API calls 22002->22003 22003->21998 22005 7ff6297ede98 std::_Facet_Register 49 API calls 22004->22005 22006 7ff6297dde49 memcpy_s BuildCatchObjectHelperInternal 22005->22006 22007 7ff6297ede98 std::_Facet_Register 49 API calls 22006->22007 22008 7ff6297dde9d 22007->22008 22009 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 22008->22009 22010 7ff6297ddeed 22009->22010 22011 7ff6297ddefe 22010->22011 22264 7ff6297da4c0 49 API calls BuildCatchObjectHelperInternal 22010->22264 22013 7ff6297f8940 52 API calls 22011->22013 22014 7ff6297def16 CloseHandle 22013->22014 22016 7ff6297deffa 22014->22016 22016->21886 22018 7ff6297ede98 std::_Facet_Register 49 API calls 22017->22018 22020 7ff6297deeda BuildCatchObjectHelperInternal 22018->22020 22019 7ff6297deffa 22019->21886 22020->22019 22021 7ff6297f8940 52 API calls 22020->22021 22022 7ff6297def16 CloseHandle 22021->22022 22022->22019 22025 7ff6297ddc59 22024->22025 22026 7ff6297ddd3d 22024->22026 22027 7ff6297ede98 std::_Facet_Register 49 API calls 22025->22027 22026->21886 22028 7ff6297ddc63 memcpy_s BuildCatchObjectHelperInternal 22027->22028 22029 7ff6297ddc91 wsprintfW 22028->22029 22030 7ff6297ddca6 22028->22030 22029->22030 22031 7ff6297dddf3 22030->22031 22035 7ff6297ddcf6 BuildCatchObjectHelperInternal 22030->22035 22032 7ff6297f87a0 std::_Locinfo::_Locinfo_ctor 47 API calls 22031->22032 22033 7ff6297dde08 22032->22033 22034 7ff6297f8940 52 API calls 22033->22034 22036 7ff6297dde24 CloseHandle 22034->22036 22035->22026 22038 7ff6297d3e30 10 API calls 22035->22038 22037 7ff6297dde3a 22036->22037 22037->22026 22038->22026 22040 7ff6297de2a2 22039->22040 22041 7ff6297de2c3 22040->22041 22042 7ff6297d3e30 10 API calls 22040->22042 22041->21886 22042->22041 22044 7ff6297dd9df 22043->22044 22045 7ff6297dda2a CloseHandle 22043->22045 22046 7ff6297dda44 22044->22046 22047 7ff6297dda0b 22044->22047 22045->22046 22048 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22046->22048 22047->22045 22049 7ff6297dda49 22048->22049 22050 7ff6297ddaf7 22049->22050 22051 7ff6297ede98 std::_Facet_Register 49 API calls 22049->22051 22052 7ff6297ddb41 RegOpenKeyExW 22050->22052 22053 7ff6297ddbb0 22050->22053 22055 7ff6297dda83 memcpy_s 22051->22055 22052->22053 22054 7ff6297ddb7c RegQueryValueExW 22052->22054 22053->21886 22054->22053 22056 7ff6297dda97 GetLastInputInfo GetTickCount wsprintfW 22055->22056 22265 7ff6297d8040 22056->22265 22058->21886 22060 7ff6297ede98 std::_Facet_Register 49 API calls 22059->22060 22061 7ff6297df437 memcpy_s 22060->22061 22062 7ff6297df44b GetLastInputInfo GetTickCount wsprintfW GetForegroundWindow 22061->22062 22063 7ff6297df4b4 CreateToolhelp32Snapshot 22062->22063 22064 7ff6297df4a1 GetWindowTextW 22062->22064 22065 7ff6297df4d8 memcpy_s 22063->22065 22080 7ff6297df555 CreateToolhelp32Snapshot 22063->22080 22064->22063 22069 7ff6297df4e9 Process32FirstW 22065->22069 22067 7ff6297df577 memcpy_s 22073 7ff6297df58b Process32FirstW 22067->22073 22068 7ff6297df5f8 CreateToolhelp32Snapshot 22071 7ff6297df61a memcpy_s 22068->22071 22072 7ff6297df6a8 RegOpenKeyExW 22068->22072 22076 7ff6297df501 22069->22076 22069->22080 22077 7ff6297df62e Process32FirstW 22071->22077 22078 7ff6297df913 RegOpenKeyExW 22072->22078 22079 7ff6297df6fa RegQueryValueExW 22072->22079 22073->22068 22088 7ff6297df5a9 22073->22088 22075 7ff6297df544 Process32NextW 22075->22076 22075->22080 22076->22075 22076->22080 22077->22072 22094 7ff6297df64c 22077->22094 22081 7ff6297df9f2 RegOpenKeyExW 22078->22081 22082 7ff6297df951 RegQueryValueExW 22078->22082 22083 7ff6297df908 RegCloseKey 22079->22083 22092 7ff6297df734 memcpy_s 22079->22092 22080->22067 22080->22068 22084 7ff6297dfad1 7 API calls 22081->22084 22085 7ff6297dfa30 RegQueryValueExW 22081->22085 22086 7ff6297df9e7 RegCloseKey 22082->22086 22097 7ff6297df986 memcpy_s 22082->22097 22083->22078 22090 7ff6297dfb91 FindClose 22084->22090 22091 7ff6297dfb89 22084->22091 22089 7ff6297dfac6 RegCloseKey 22085->22089 22099 7ff6297dfa65 memcpy_s 22085->22099 22086->22081 22087 7ff6297df5e4 Process32NextW 22087->22068 22087->22088 22088->22068 22088->22087 22089->22084 22113 7ff6297dfd10 GetVersion 22090->22113 22091->22090 22096 7ff6297df75e RegQueryValueExW 22092->22096 22093 7ff6297df694 Process32NextW 22093->22072 22093->22094 22094->22072 22094->22093 22096->22083 22098 7ff6297df791 22096->22098 22100 7ff6297df9b0 RegQueryValueExW 22097->22100 22135 7ff6297e1390 49 API calls 4 library calls 22098->22135 22103 7ff6297dfa8f RegQueryValueExW 22099->22103 22100->22086 22101 7ff6297df9df 22100->22101 22101->22086 22103->22089 22104 7ff6297dfabe 22103->22104 22104->22089 22105 7ff6297dfbd1 BuildCatchObjectHelperInternal 22110 7ff6297dfcbe 22105->22110 22112 7ff6297d3e30 10 API calls 22105->22112 22106 7ff6297df900 22106->22083 22107 7ff6297dfcfe 22108 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22107->22108 22109 7ff6297dfd03 22108->22109 22110->22002 22111 7ff6297df79d 22111->22083 22111->22106 22111->22107 22112->22110 22114 7ff6297e0145 22113->22114 22115 7ff6297dfd40 22113->22115 22114->22105 22115->22114 22116 7ff6297dfd4c 7 API calls 22115->22116 22117 7ff6297dfe0e GetSystemMetrics 22116->22117 22118 7ff6297dfdfa 22116->22118 22120 7ff6297dfe2e GetSystemMetrics 22117->22120 22121 7ff6297dfe78 GetSystemMetrics 22117->22121 22119 7ff6297dfe97 8 API calls 22118->22119 22122 7ff6297dffe2 memcpy_s 22119->22122 22120->22119 22121->22119 22123 7ff6297dfff7 GetDIBits 22122->22123 22124 7ff6297e002f memcpy_s BuildCatchObjectHelperInternal 22123->22124 22125 7ff6297ede98 std::_Facet_Register 49 API calls 22124->22125 22126 7ff6297e00a2 22125->22126 22136 7ff6297e02a0 GlobalAlloc GlobalLock 22126->22136 22129 7ff6297e01b1 BuildCatchObjectHelperInternal 22131 7ff6297e01f2 DeleteObject DeleteObject ReleaseDC 22129->22131 22130 7ff6297e00e1 DeleteObject DeleteObject ReleaseDC 22133 7ff6297e010b 22130->22133 22131->22133 22132 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22134 7ff6297e0295 22132->22134 22133->22114 22133->22132 22135->22111 22184 7ff62980d110 22136->22184 22138 7ff6297e02f8 GlobalUnlock CreateStreamOnHGlobal 22139 7ff6297e031f 22138->22139 22140 7ff6297e0671 GlobalFree 22138->22140 22186 7ff6297d61e0 22139->22186 22141 7ff6297e00d1 22140->22141 22141->22129 22141->22130 22145 7ff6297e037c 22146 7ff6297e0384 GdipCreateBitmapFromStream 22145->22146 22183 7ff6297e05e7 22145->22183 22147 7ff6297e03b0 GdipDisposeImage 22146->22147 22148 7ff6297e03bb 22146->22148 22147->22183 22204 7ff6297dc340 GdipGetImagePixelFormat 22148->22204 22150 7ff6297e062a 22153 7ff6297d61e0 58 API calls 22150->22153 22151 7ff6297e0606 DeleteObject 22151->22150 22152 7ff6297e03c8 GdipDisposeImage 22154 7ff6297e03dc CreateStreamOnHGlobal 22152->22154 22152->22183 22155 7ff6297e062f EnterCriticalSection 22153->22155 22156 7ff6297e03f9 22154->22156 22154->22183 22157 7ff6297e0642 EnterCriticalSection 22155->22157 22158 7ff6297e0667 LeaveCriticalSection 22155->22158 22238 7ff6297dc7b0 22156->22238 22160 7ff6297e0654 GdiplusShutdown 22157->22160 22161 7ff6297e065a LeaveCriticalSection 22157->22161 22158->22140 22160->22161 22161->22158 22162 7ff6297e0406 GetHGlobalFromStream GlobalLock 22163 7ff6297e04bf GlobalSize 22162->22163 22164 7ff6297e042e GlobalFree 22162->22164 22168 7ff6297e04d2 BuildCatchObjectHelperInternal 22163->22168 22166 7ff6297e044f DeleteObject 22164->22166 22167 7ff6297e0471 22164->22167 22166->22167 22169 7ff6297d61e0 58 API calls 22167->22169 22252 7ff6297d9e70 49 API calls 4 library calls 22168->22252 22171 7ff6297e0476 EnterCriticalSection 22169->22171 22172 7ff6297e04ae LeaveCriticalSection 22171->22172 22173 7ff6297e0489 EnterCriticalSection 22171->22173 22172->22141 22174 7ff6297e04a1 LeaveCriticalSection 22173->22174 22175 7ff6297e049b GdiplusShutdown 22173->22175 22174->22172 22175->22174 22176 7ff6297e0594 22180 7ff6297e05d3 GlobalUnlock 22176->22180 22181 7ff6297e05af DeleteObject 22176->22181 22177 7ff6297e0501 22177->22176 22178 7ff6297e0698 22177->22178 22179 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22178->22179 22182 7ff6297e069d 22179->22182 22180->22183 22181->22180 22183->22150 22183->22151 22185 7ff62980d100 22184->22185 22185->22138 22185->22185 22187 7ff6297d6200 22186->22187 22188 7ff6297d626b EnterCriticalSection LeaveCriticalSection 22186->22188 22253 7ff6297edbac AcquireSRWLockExclusive SleepConditionVariableSRW ReleaseSRWLockExclusive 22187->22253 22197 7ff6297dc9b0 22188->22197 22198 7ff6297d61e0 58 API calls 22197->22198 22199 7ff6297dc9bb 22198->22199 22200 7ff6297dc9c4 22199->22200 22201 7ff6297dc9cc EnterCriticalSection 22199->22201 22200->22145 22202 7ff6297dca23 LeaveCriticalSection 22201->22202 22203 7ff6297dc9e9 GdiplusStartup 22201->22203 22202->22145 22203->22202 22206 7ff6297dc385 GdipGetImageHeight 22204->22206 22207 7ff6297dc402 22206->22207 22208 7ff6297dc40f GdipGetImageWidth 22206->22208 22207->22208 22209 7ff6297dc424 22208->22209 22254 7ff6297dc160 22209->22254 22211 7ff6297dc445 22212 7ff6297dc461 GdipGetImagePaletteSize 22211->22212 22213 7ff6297dc5fc 22211->22213 22219 7ff6297dc449 __std_exception_destroy 22211->22219 22223 7ff6297dc47a std::_Locinfo::_Locinfo_ctor 22212->22223 22214 7ff6297dc6e2 GdipCreateBitmapFromScan0 GdipGetImageGraphicsContext GdipDrawImageI GdipDeleteGraphics GdipDisposeImage 22213->22214 22215 7ff6297dc622 GdipBitmapLockBits 22213->22215 22214->22219 22218 7ff6297dc66a BuildCatchObjectHelperInternal 22215->22218 22215->22219 22216 7ff6297dc6c4 GdipBitmapUnlockBits 22216->22219 22217 7ff6297dc78d memcpy_s 22261 7ff6297f8afc 11 API calls _get_daylight 22217->22261 22218->22216 22218->22217 22219->22152 22221 7ff6297dc4e7 GdipGetImagePalette 22228 7ff6297dc4fb 22221->22228 22222 7ff6297dc799 22262 7ff6297f3d38 47 API calls _invalid_parameter_noinfo 22222->22262 22223->22219 22223->22221 22225 7ff6297dc7a4 22263 7ff6297d10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 22225->22263 22228->22219 22228->22228 22229 7ff6297dc5aa SetDIBColorTable 22228->22229 22259 7ff6297d6280 56 API calls 22228->22259 22229->22213 22230 7ff6297dc5c4 SelectObject 22229->22230 22260 7ff6297d6280 56 API calls 22230->22260 22233 7ff6297dc564 22235 7ff6297dc58e SelectObject 22233->22235 22236 7ff6297dc586 CreateCompatibleDC 22233->22236 22234 7ff6297dc5db 22234->22213 22237 7ff6297dc5f3 DeleteDC 22234->22237 22235->22229 22236->22235 22237->22213 22239 7ff6297dc9b0 61 API calls 22238->22239 22240 7ff6297dc7d4 22239->22240 22241 7ff6297dc992 22240->22241 22242 7ff6297dc7dc GdipGetImageEncodersSize 22240->22242 22241->22162 22242->22241 22243 7ff6297dc7f2 std::_Locinfo::_Locinfo_ctor 22242->22243 22244 7ff6297dc86b GdipGetImageEncoders 22243->22244 22245 7ff6297dc861 __std_exception_destroy 22243->22245 22244->22245 22246 7ff6297dc87f 22244->22246 22245->22162 22246->22245 22247 7ff6297dc923 GdipCreateBitmapFromHBITMAP 22246->22247 22248 7ff6297dc8f1 GdipCreateBitmapFromScan0 22246->22248 22249 7ff6297dc933 GdipSaveImageToStream 22247->22249 22248->22249 22250 7ff6297dc95e GdipDisposeImage 22249->22250 22251 7ff6297dc951 GdipDisposeImage 22249->22251 22250->22245 22251->22245 22252->22177 22255 7ff6297dc19b memcpy_s 22254->22255 22256 7ff6297dc202 CreateDIBSection 22255->22256 22258 7ff6297dc249 __std_exception_destroy 22255->22258 22257 7ff6297dc227 GetObjectW 22256->22257 22256->22258 22257->22258 22258->22211 22259->22233 22260->22234 22261->22222 22262->22225 22264->22011 22266 7ff6297d80e4 memcpy_s 22265->22266 22268 7ff6297d8076 memcpy_s 22265->22268 22267 7ff6297ec2e0 77 API calls 22266->22267 22270 7ff6297d8105 22267->22270 22302 7ff6297ec2e0 22268->22302 22270->22270 22271 7ff6297d81bb 22270->22271 22272 7ff6297d82b7 22270->22272 22273 7ff6297d80b8 BuildCatchObjectHelperInternal 22270->22273 22301 7ff6297d818f 22270->22301 22316 7ff6297d9c80 49 API calls 4 library calls 22271->22316 22319 7ff6297d9c80 49 API calls 4 library calls 22272->22319 22273->22050 22276 7ff6297d81d6 22317 7ff6297d9e70 49 API calls 4 library calls 22276->22317 22277 7ff6297d82d6 22320 7ff6297d9e70 49 API calls 4 library calls 22277->22320 22278 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22279 7ff6297d8675 22278->22279 22280 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22279->22280 22283 7ff6297d867b 22280->22283 22284 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22283->22284 22285 7ff6297d8681 22284->22285 22288 7ff6297f3d58 _invalid_parameter_noinfo_noreturn 47 API calls 22285->22288 22286 7ff6297d8206 22318 7ff6297d9bc0 47 API calls _invalid_parameter_noinfo_noreturn 22286->22318 22287 7ff6297d8303 22321 7ff6297d9bc0 47 API calls _invalid_parameter_noinfo_noreturn 22287->22321 22291 7ff6297d8687 22288->22291 22292 7ff6297d84f4 OutputDebugStringA 22293 7ff6297d8518 MultiByteToWideChar 22292->22293 22297 7ff6297d8591 memcpy_s BuildCatchObjectHelperInternal 22292->22297 22294 7ff6297eded4 22293->22294 22295 7ff6297d855f MultiByteToWideChar 22294->22295 22295->22297 22296 7ff6297d84dc 22296->22292 22323 7ff6297d9bc0 47 API calls _invalid_parameter_noinfo_noreturn 22297->22323 22298 7ff6297d8273 std::_Locinfo::_Locinfo_ctor BuildCatchObjectHelperInternal 22298->22279 22298->22283 22298->22292 22298->22296 22322 7ff6297da010 49 API calls 4 library calls 22298->22322 22301->22273 22301->22278 22301->22285 22303 7ff6297ec300 wsprintfW CreateFileW 22302->22303 22304 7ff6297ec34d DeviceIoControl 22303->22304 22305 7ff6297ec509 22303->22305 22306 7ff6297ec500 CloseHandle 22304->22306 22311 7ff6297ec398 __std_exception_destroy 22304->22311 22305->22273 22306->22305 22307 7ff6297ec3c2 DeviceIoControl 22308 7ff6297ec4f3 __std_exception_destroy 22307->22308 22307->22311 22308->22306 22309 7ff6297ec41c DeviceIoControl 22309->22306 22309->22311 22310 7ff6297ec480 DeviceIoControl 22310->22308 22310->22311 22311->22306 22311->22307 22311->22309 22311->22310 22312 7ff6297ec520 WideCharToMultiByte WideCharToMultiByte 22311->22312 22324 7ff6297ec1b0 22311->22324 22312->22311 22315 7ff6297ec4ef 22315->22305 22316->22276 22317->22286 22318->22298 22319->22277 22320->22287 22321->22298 22322->22298 22323->22301 22325 7ff6297ec1d1 22324->22325 22326 7ff6297ec2c9 CloseHandle 22325->22326 22327 7ff6297ec22f CreateFileA 22325->22327 22326->22303 22326->22315 22327->22326 22328 7ff6297ec268 __std_exception_destroy 22327->22328 22329 7ff6297ec270 DeviceIoControl 22328->22329 22329->22326 22330 7ff6297ec2ab 22329->22330 22333 7ff6297ebdd0 22330->22333 22334 7ff6297ec190 CloseHandle 22333->22334 22352 7ff6297ebdfd memcpy_s 22333->22352 22335 7ff6297ebe40 DeviceIoControl 22337 7ff6297ec166 __std_exception_destroy 22335->22337 22335->22352 22336 7ff6297ebe8c DeviceIoControl 22336->22352 22337->22334 22338 7ff6297ebf8e DeviceIoControl 22338->22352 22339 7ff6297ebf08 GlobalAlloc 22340 7ff6297ebf20 DeviceIoControl 22339->22340 22339->22352 22342 7ff6297ebf7b GlobalFree 22340->22342 22340->22352 22341 7ff6297ebfee GlobalAlloc 22343 7ff6297ec003 DeviceIoControl 22341->22343 22341->22352 22342->22352 22344 7ff6297ec041 22343->22344 22345 7ff6297ec06c GlobalFree 22343->22345 22353 7ff6297ec520 WideCharToMultiByte 22344->22353 22345->22352 22346 7ff6297ec5c0 WideCharToMultiByte WideCharToMultiByte GetSystemDefaultLangID DeviceIoControl lstrcpyA 22346->22352 22348 7ff6297ec04a GlobalFree 22349 7ff6297ec05b 22348->22349 22348->22352 22351 7ff6297ec1b0 58 API calls 22349->22351 22349->22352 22351->22349 22352->22335 22352->22336 22352->22337 22352->22338 22352->22339 22352->22341 22352->22342 22352->22346 22357 7ff6297ebd70 51 API calls 22352->22357 22354 7ff6297ec561 22353->22354 22355 7ff6297ec59a __std_exception_destroy 22353->22355 22354->22355 22356 7ff6297ec570 WideCharToMultiByte 22354->22356 22355->22348 22356->22355 22357->22352 22359 7ff6297febe8 _get_daylight 11 API calls 22358->22359 22362 7ff6297f8889 22359->22362 22360 7ff6297f88d0 ExitThread 22361 7ff6297f88a5 22364 7ff6297f88b3 CloseHandle 22361->22364 22365 7ff6297f88b9 22361->22365 22362->22360 22362->22361 22367 7ff6298010fc 5 API calls std::_Locinfo::_Locinfo_ctor 22362->22367 22364->22365 22365->22360 22366 7ff6297f88c7 FreeLibraryAndExitThread 22365->22366 22366->22360 22367->22361 22397 7ff6297def25 RegOpenKeyExW RegDeleteValueW RegSetValueExW RegCloseKey 22470 7ff6297de01f 71 API calls memcpy_s 22472 7ff6297d9220 GetModuleFileNameW GetCommandLineW GetStartupInfoW CreateProcessW ExitProcess 22473 7ff6297dc020 GdipCloneImage GdipAlloc 22474 7ff62980ea30 WSACleanup 22475 7ff6297de217 TerminateThread CloseHandle 22399 7ff629805d34 56 API calls 3 library calls 22400 7ff6297db331 17 API calls 22402 7ff6297d1130 HeapAlloc 22403 7ff6297e1b30 50 API calls 22405 7ff629805040 60 API calls 4 library calls 22406 7ff6297d5640 40 API calls 22407 7ff6297d1040 GetTickCount 22480 7ff6297d1140 HeapFree 22481 7ff6297e1340 HeapFree HeapDestroy HeapCreate HeapDestroy __std_exception_destroy 22484 7ff6297d9740 83 API calls 22485 7ff6297ee13c GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 22408 7ff62980ea50 DeleteDC DeleteDC DeleteDC DeleteDC 22488 7ff629801338 FreeLibrary 22491 7ff62980714c 54 API calls 5 library calls 22493 7ff629800748 12 API calls 22494 7ff62980a544 67 API calls 22412 7ff6297de248 7 API calls 22496 7ff6297d1160 HeapReAlloc 22497 7ff6297df160 52 API calls 5 library calls 22498 7ff6297fab5c 7 API calls 22417 7ff6297d1058 GetLastError IsDebuggerPresent OutputDebugStringW shared_ptr 22419 7ff6297d1470 VirtualFree 22420 7ff6297d4470 164 API calls std::_Locinfo::_Locinfo_ctor 22501 7ff6297de36a OpenEventLogW ClearEventLogW CloseEventLog 22502 7ff6297fbb69 63 API calls 22503 7ff629800368 17 API calls 2 library calls 22422 7ff62980cc64 CloseHandle 22423 7ff6297d1a80 LeaveCriticalSection 22424 7ff6297dbe80 12 API calls _Wcrtomb 22425 7ff6297dc080 64 API calls 22507 7ff6297ef77c 60 API calls _CallSETranslator 22427 7ff6297d1078 InitializeCriticalSectionEx shared_ptr 22509 7ff6297dbd90 13 API calls 22431 7ff629800488 80 API calls Concurrency::details::SchedulerProxy::DeleteThis 22511 7ff6297defa3 RegOpenKeyExW RegDeleteValueW RegCloseKey 22512 7ff6297edfa4 48 API calls 2 library calls 22513 7ff629807ba0 57 API calls 4 library calls 22433 7ff6297d54a0 70 API calls 22514 7ff6297d11a0 HeapSize 22434 7ff6297e0ca0 15 API calls BuildCatchObjectHelperInternal 22436 7ff62980549c GetProcessHeap 22437 7ff62980eab0 EnterCriticalSection GdiplusShutdown LeaveCriticalSection 22438 7ff6297de697 79 API calls 4 library calls 22517 7ff6297ec7b4 DeleteCriticalSection __std_exception_destroy 22440 7ff6297ed0b0 7 API calls __std_exception_destroy 22518 7ff6297d11b0 HeapDestroy 22521 7ff6297f25aa 57 API calls 2 library calls 22522 7ff62980eba4 DecodePointer

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 0 7ff6297d62f0-7ff6297d6344 call 7ff6297ee4e0 call 7ff6297ede98 call 7ff62980d7b0 7 7ff6297d635e-7ff6297d63ac call 7ff62980d7b0 gethostname gethostbyname 0->7 8 7ff6297d6346-7ff6297d6359 call 7ff6297f87a0 0->8 12 7ff6297d63b2-7ff6297d63fc inet_ntoa call 7ff6297f8f58 * 2 7->12 13 7ff6297d644f-7ff6297d6538 MultiByteToWideChar * 2 GetLastInputInfo GetTickCount wsprintfW MultiByteToWideChar * 2 LoadLibraryW 7->13 8->7 12->13 29 7ff6297d63fe 12->29 15 7ff6297d653e-7ff6297d6551 GetProcAddress 13->15 16 7ff6297d665c-7ff6297d6697 GetSystemInfo wsprintfW 13->16 19 7ff6297d6653-7ff6297d6656 FreeLibrary 15->19 20 7ff6297d6557-7ff6297d65e5 call 7ff6297d3670 call 7ff6297eded4 call 7ff6297d91a0 15->20 17 7ff6297d66a0-7ff6297d66bf GetDriveTypeW 16->17 21 7ff6297d66c1-7ff6297d66f5 GetDiskFreeSpaceExW 17->21 22 7ff6297d66f8-7ff6297d66fd 17->22 19->16 45 7ff6297d65ed-7ff6297d6620 RegOpenKeyExW RegQueryValueExW 20->45 46 7ff6297d65e7 20->46 21->22 22->17 25 7ff6297d66ff-7ff6297d67a2 GlobalMemoryStatusEx call 7ff6297d3670 * 2 call 7ff6297d8e00 GetForegroundWindow 22->25 47 7ff6297d67a4-7ff6297d67b4 GetWindowTextW 25->47 48 7ff6297d67ba-7ff6297d67fd lstrlenW call 7ff6297d8cd0 25->48 32 7ff6297d6400-7ff6297d644d inet_ntoa call 7ff6297f8f58 * 2 29->32 32->13 49 7ff6297d6622-7ff6297d6624 45->49 50 7ff6297d6640-7ff6297d664e RegCloseKey call 7ff6297ede64 45->50 46->45 47->48 56 7ff6297d6823-7ff6297d6862 call 7ff6297f87a0 lstrlenW call 7ff6297d8cd0 48->56 57 7ff6297d67ff-7ff6297d681d GetLocalTime wsprintfW 48->57 49->50 52 7ff6297d6626-7ff6297d663b call 7ff6297f9248 49->52 50->19 52->50 62 7ff6297d6864-7ff6297d6873 call 7ff6297f87a0 56->62 63 7ff6297d6878-7ff6297d68ab GetModuleHandleW GetProcAddress 56->63 57->56 62->63 65 7ff6297d68b1 GetSystemInfo 63->65 66 7ff6297d68ad-7ff6297d68af GetNativeSystemInfo 63->66 67 7ff6297d68b7-7ff6297d68c3 65->67 66->67 68 7ff6297d68c5-7ff6297d68cf 67->68 69 7ff6297d68d1 67->69 68->69 70 7ff6297d68d6-7ff6297d6916 wsprintfW call 7ff6297d8ad0 GetCurrentProcessId 68->70 69->70 73 7ff6297d6a5e-7ff6297d6a8f CoInitializeEx CoCreateInstance 70->73 74 7ff6297d691c-7ff6297d6937 OpenProcess 70->74 75 7ff6297d6a95-7ff6297d6aaa 73->75 76 7ff6297d6b8f 73->76 77 7ff6297d693d-7ff6297d6955 K32GetProcessImageFileNameW 74->77 78 7ff6297d6a57 74->78 82 7ff6297d6ab0-7ff6297d6ab2 75->82 81 7ff6297d6b96-7ff6297d6bef call 7ff6297f87a0 call 7ff62980d7b0 RegOpenKeyExW 76->81 79 7ff6297d6a4e-7ff6297d6a51 CloseHandle 77->79 80 7ff6297d695b-7ff6297d696f GetLogicalDriveStringsW 77->80 78->73 79->78 83 7ff6297d6975-7ff6297d697e 80->83 84 7ff6297d6a3e-7ff6297d6a48 lstrcpyW 80->84 96 7ff6297d6d52-7ff6297d6d62 lstrlenW 81->96 97 7ff6297d6bf5-7ff6297d6c4f RegQueryInfoKeyW 81->97 82->76 86 7ff6297d6ab8-7ff6297d6ae5 82->86 83->84 87 7ff6297d6984-7ff6297d698b 83->87 84->79 106 7ff6297d6b7e-7ff6297d6b8d CoUninitialize 86->106 107 7ff6297d6aeb 86->107 89 7ff6297d6990-7ff6297d69b0 lstrcmpiW 87->89 92 7ff6297d69b2-7ff6297d69c4 lstrcmpiW 89->92 93 7ff6297d6a2e-7ff6297d6a38 89->93 92->93 95 7ff6297d69c6-7ff6297d69fe QueryDosDeviceW 92->95 93->84 93->89 95->79 101 7ff6297d6a00-7ff6297d6a28 lstrlenW call 7ff6297f90ac 95->101 98 7ff6297d6d82-7ff6297d6e7d call 7ff6297d79e0 call 7ff6297f9248 GetTickCount call 7ff6297f8b9c call 7ff6297f8f10 wsprintfW GetLocaleInfoW GetSystemDirectoryW GetCurrentHwProfileW 96->98 99 7ff6297d6d64-7ff6297d6d7d call 7ff6297f9248 96->99 97->98 102 7ff6297d6c55-7ff6297d6c67 97->102 137 7ff6297d6e7f-7ff6297d6e8b 98->137 138 7ff6297d6eb6 98->138 99->98 101->93 115 7ff6297d6e8d-7ff6297d6eb1 lstrcpyW lstrcatW 101->115 102->96 103 7ff6297d6c6d-7ff6297d6c70 102->103 103->96 109 7ff6297d6c76-7ff6297d6c8f call 7ff62980d7b0 103->109 106->76 106->81 111 7ff6297d6af0-7ff6297d6b13 107->111 119 7ff6297d6c95 109->119 120 7ff6297d6d47-7ff6297d6d4c RegCloseKey 109->120 122 7ff6297d6b15-7ff6297d6b34 111->122 123 7ff6297d6b4d-7ff6297d6b78 111->123 115->79 124 7ff6297d6ca0-7ff6297d6cf5 call 7ff62980d7b0 RegEnumKeyExW lstrlenW 119->124 120->96 132 7ff6297d6b42-7ff6297d6b47 122->132 133 7ff6297d6b36-7ff6297d6b3c SysFreeString 122->133 123->106 123->111 135 7ff6297d6cf7-7ff6297d6d07 lstrlenW 124->135 136 7ff6297d6d39-7ff6297d6d41 124->136 132->123 133->132 135->136 139 7ff6297d6d09-7ff6297d6d34 call 7ff6297f8b24 * 2 135->139 136->120 136->124 140 7ff6297d6ebb-7ff6297d6f0d call 7ff6297d7250 lstrlenW call 7ff6297d8cd0 137->140 138->140 139->136 148 7ff6297d6f13-7ff6297d6f96 GetLocalTime wsprintfW RegOpenKeyExW RegDeleteValueW RegCloseKey RegCreateKeyW 140->148 149 7ff6297d6fe7-7ff6297d6ffb CreateToolhelp32Snapshot 140->149 150 7ff6297d6fda-7ff6297d6fe1 RegCloseKey 148->150 151 7ff6297d6f98-7ff6297d6fcb lstrlenW RegSetValueExW 148->151 152 7ff6297d7001-7ff6297d7031 call 7ff62980d7b0 Process32FirstW 149->152 153 7ff6297d7088 149->153 150->149 151->150 155 7ff6297d6fcd-7ff6297d6fd4 RegCloseKey 151->155 152->153 161 7ff6297d7033-7ff6297d703a 152->161 154 7ff6297d708a-7ff6297d70a5 CreateToolhelp32Snapshot 153->154 157 7ff6297d70ab-7ff6297d70db call 7ff62980d7b0 Process32FirstW 154->157 158 7ff6297d7138 154->158 155->150 157->158 167 7ff6297d70dd-7ff6297d70e8 157->167 162 7ff6297d713a-7ff6297d7155 CreateToolhelp32Snapshot 158->162 164 7ff6297d7040-7ff6297d704f 161->164 165 7ff6297d71ff-7ff6297d7219 call 7ff6297d3e30 162->165 166 7ff6297d715b-7ff6297d718b call 7ff62980d7b0 Process32FirstW 162->166 168 7ff6297d7050-7ff6297d705a 164->168 172 7ff6297d721c-7ff6297d7240 call 7ff6297ede64 165->172 166->165 175 7ff6297d718d-7ff6297d7198 166->175 171 7ff6297d70f0-7ff6297d70fe 167->171 173 7ff6297d7074-7ff6297d7086 Process32NextW 168->173 174 7ff6297d705c-7ff6297d7064 168->174 176 7ff6297d7100-7ff6297d710a 171->176 173->153 173->164 178 7ff6297d706a-7ff6297d7072 174->178 179 7ff6297d71e6-7ff6297d71eb 174->179 180 7ff6297d71a0-7ff6297d71ae 175->180 181 7ff6297d7124-7ff6297d7136 Process32NextW 176->181 182 7ff6297d710c-7ff6297d7114 176->182 178->168 178->173 179->154 184 7ff6297d71b0-7ff6297d71ba 180->184 181->158 181->171 185 7ff6297d71f0-7ff6297d71f5 182->185 186 7ff6297d711a-7ff6297d7122 182->186 187 7ff6297d71d0-7ff6297d71e2 Process32NextW 184->187 188 7ff6297d71bc-7ff6297d71c4 184->188 185->162 186->176 186->181 187->180 191 7ff6297d71e4 187->191 189 7ff6297d71fa 188->189 190 7ff6297d71c6-7ff6297d71ce 188->190 189->165 190->184 190->187 191->165
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Process32lstrlen$CloseCreateInfo$Systemwsprintf$ByteCharFirstHandleMultiNextOpenSnapshotTimeToolhelp32Wide$AddressFreeProcProcessQueryValue$Concurrency::cancel_current_taskCountCurrentDriveFileInstanceLibraryLocalModuleNativeTickWindow_invalid_parameter_noinfoinet_ntoalstrcmpi$DeleteDeviceDirectoryDiskEnumForegroundGlobalImageInitializeInputLastLoadLocaleLogicalMemoryNameProfileSpaceStatusStringStringsTextTypeUninitializegethostbynamegethostnamelstrcpy
              • String ID: %d min$%d.%d$%d.%d.%d$%sFree%d Gb $9b5db265-7770-4834-9125-526b4323e01f$A:\$AppEvents$B:\$FriendlyName$GetNativeSystemInfo$HDD:%d$INSTALLTIME$Network$ProductName$RtlGetNtVersionNumbers$SOFTWARE\Microsoft\Windows NT\CurrentVersion$Software$Software\Tencent\Plugin\VAS$Telegram.exe$VenGROUP$VenNetwork$VenREMARK$WeChat.exe$WxWork.exe$X64 %s$kernel32.dll$ntdll.dll$x64$x86
              • API String ID: 4136965836-1406015123
              • Opcode ID: 2ddc40a1924fd65b20fbacfc896f38d1c8af44059fc11dcb60be5f4691cfa860
              • Instruction ID: 2009d0bf13d7514b13368a146c02d490ba620e50fe765a152c349a6372b07a8a
              • Opcode Fuzzy Hash: 2ddc40a1924fd65b20fbacfc896f38d1c8af44059fc11dcb60be5f4691cfa860
              • Instruction Fuzzy Hash: 66927232A09A8286EF20DF25DC446E93360FBC5B98F848532DA5E877A4EF3CD645D711

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 193 7ff6297eb500-7ff6297eb541 call 7ff6297f9c1c SleepEx 196 7ff6297eb573-7ff6297eb57a 193->196 197 7ff6297eb543-7ff6297eb56d call 7ff6297ede98 call 7ff6297f8940 CloseHandle 193->197 199 7ff6297eb580-7ff6297eb59d GetCurrentProcess OpenProcessToken 196->199 200 7ff6297eb64f-7ff6297eb759 GetLocalTime wsprintfW SetUnhandledExceptionFilter call 7ff6297f8940 CloseHandle call 7ff6297ede98 call 7ff6297d36e0 call 7ff6297ead80 AllocateAndInitializeSid 196->200 197->196 201 7ff6297eb5f4-7ff6297eb617 GetModuleHandleA GetProcAddress 199->201 202 7ff6297eb59f-7ff6297eb5ee LookupPrivilegeValueW AdjustTokenPrivileges CloseHandle 199->202 215 7ff6297eb75b-7ff6297eb773 CheckTokenMembership 200->215 216 7ff6297eb789-7ff6297eb790 200->216 201->200 205 7ff6297eb619-7ff6297eb64a GetCurrentProcessId OpenProcess 201->205 202->201 205->200 219 7ff6297eb775 215->219 220 7ff6297eb77c-7ff6297eb783 FreeSid 215->220 217 7ff6297eb792-7ff6297eb807 RegOpenKeyExW RegDeleteValueW RegSetValueExW RegCloseKey 216->217 218 7ff6297eb80d-7ff6297eb81b 216->218 217->218 221 7ff6297eb820-7ff6297eb833 218->221 219->220 220->216 222 7ff6297eb835-7ff6297eb85f call 7ff6297f87a0 * 2 221->222 223 7ff6297eb861-7ff6297eb885 call 7ff6297f87a0 * 2 221->223 232 7ff6297eb88b-7ff6297eb8b4 222->232 223->232 233 7ff6297eb8f9-7ff6297eb903 232->233 234 7ff6297eb8b6-7ff6297eb8f2 call 7ff6297f87a0 * 2 232->234 236 7ff6297eb905 233->236 237 7ff6297eb90a-7ff6297eb955 call 7ff6297f9c1c SleepEx call 7ff6297f9c1c call 7ff6297d3820 233->237 234->233 236->237 237->221 246 7ff6297eb95b-7ff6297eba18 call 7ff6297f9c1c CreateEventA call 7ff6297f87a0 call 7ff6297d62f0 237->246 253 7ff6297eba1d-7ff6297eba20 246->253 254 7ff6297eba22-7ff6297eba2e 253->254 255 7ff6297eba30 253->255 260 7ff6297eba7e-7ff6297eba8d 254->260 256 7ff6297eba33-7ff6297eba3a 255->256 258 7ff6297eba65-7ff6297eba6c 256->258 259 7ff6297eba3c-7ff6297eba4c Sleep 256->259 262 7ff6297eba72-7ff6297eba7d Sleep 258->262 259->256 261 7ff6297eba4e-7ff6297eba55 259->261 263 7ff6297ebad5-7ff6297ebae4 CloseHandle 260->263 264 7ff6297eba8f-7ff6297ebaa7 260->264 261->258 265 7ff6297eba57-7ff6297eba63 261->265 262->260 263->221 266 7ff6297ebabe-7ff6297ebace call 7ff6297ede64 264->266 267 7ff6297ebaa9-7ff6297ebabc 264->267 265->262 266->263 267->266 269 7ff6297ebae9-7ff6297ebb04 call 7ff6297f3d58 IsDebuggerPresent 267->269 274 7ff6297ebb11-7ff6297ebb34 LoadLibraryW 269->274 275 7ff6297ebb06-7ff6297ebb10 269->275 276 7ff6297ebb40-7ff6297ebb5e GetProcAddress 274->276 277 7ff6297ebb36-7ff6297ebb3b 274->277 279 7ff6297ebb73-7ff6297ebc25 call 7ff62980d7b0 GetLocalTime wsprintfW CreateFileW 276->279 280 7ff6297ebb60-7ff6297ebb6e FreeLibrary 276->280 278 7ff6297ebcae-7ff6297ebcc8 277->278 284 7ff6297ebc35-7ff6297ebc90 GetCurrentThreadId GetCurrentProcessId GetCurrentProcess CloseHandle FreeLibrary 279->284 285 7ff6297ebc27-7ff6297ebc33 FreeLibrary 279->285 281 7ff6297ebca6 280->281 281->278 286 7ff6297ebc96-7ff6297ebc9e 284->286 285->286 286->281
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CloseHandle$ProcessSleep$OpenTokenValue$AddressByteCharCurrentFreeLibraryMultiProcWide_invalid_parameter_noinfoinet_ntoa$AdjustAllocateCheckCreateDebuggerDeleteEventExceptionFilterInitializeLoadLocalLookupMembershipModulePresentPrivilegePrivilegesTimeUnhandled_invalid_parameter_noinfo_noreturngethostbynamegethostnamewsprintf
              • String ID: !analyze -v$%4d.%2d.%2d-%2d:%2d:%2d$%s-%04d%02d%02d-%02d%02d%02d.dmp$10443$10443$4433$DbgHelp.dll$MiniDumpWriteDump$NtDll.dll$NtSetInformationProcess$SOFTWARE$SeDebugPrivilege$VenkernalData_info$huazai789.top$huazai789.top$huazai789.top$huazai789.top$loginconfig
              • API String ID: 905065789-687188468
              • Opcode ID: c019dc0e360b6e64028bcd0e4b6b1f282aa0814bb9dbeae3b87a1a61d9282837
              • Instruction ID: 49b456b1722a512f3351d31c11cb082958380bf12acc6e5f62fc1e779b93da92
              • Opcode Fuzzy Hash: c019dc0e360b6e64028bcd0e4b6b1f282aa0814bb9dbeae3b87a1a61d9282837
              • Instruction Fuzzy Hash: 6E226072A09B8286EF20DF21EC402A977A5FFC5B94F444535DA8D87AA4DF3CE145E702

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 289 7ff6297df410-7ff6297df49f call 7ff6297ede98 call 7ff62980d7b0 GetLastInputInfo GetTickCount wsprintfW GetForegroundWindow 294 7ff6297df4b4-7ff6297df4d6 CreateToolhelp32Snapshot 289->294 295 7ff6297df4a1-7ff6297df4ae GetWindowTextW 289->295 296 7ff6297df555 294->296 297 7ff6297df4d8-7ff6297df4ff call 7ff62980d7b0 Process32FirstW 294->297 295->294 298 7ff6297df557-7ff6297df571 CreateToolhelp32Snapshot 296->298 297->296 303 7ff6297df501-7ff6297df508 297->303 300 7ff6297df577-7ff6297df5a7 call 7ff62980d7b0 Process32FirstW 298->300 301 7ff6297df5f8 298->301 300->301 312 7ff6297df5a9 300->312 304 7ff6297df5fa-7ff6297df614 CreateToolhelp32Snapshot 301->304 306 7ff6297df510-7ff6297df517 303->306 307 7ff6297df61a-7ff6297df64a call 7ff62980d7b0 Process32FirstW 304->307 308 7ff6297df6a8 304->308 310 7ff6297df520-7ff6297df52a 306->310 307->308 322 7ff6297df64c-7ff6297df657 307->322 313 7ff6297df6aa-7ff6297df6f4 RegOpenKeyExW 308->313 314 7ff6297df544-7ff6297df553 Process32NextW 310->314 315 7ff6297df52c-7ff6297df534 310->315 317 7ff6297df5b0-7ff6297df5ba 312->317 318 7ff6297df913-7ff6297df94b RegOpenKeyExW 313->318 319 7ff6297df6fa-7ff6297df72e RegQueryValueExW 313->319 314->296 314->306 320 7ff6297df7f2-7ff6297df7f4 315->320 321 7ff6297df53a-7ff6297df542 315->321 325 7ff6297df5c0-7ff6297df5ca 317->325 323 7ff6297df9f2-7ff6297dfa2a RegOpenKeyExW 318->323 324 7ff6297df951-7ff6297df984 RegQueryValueExW 318->324 326 7ff6297df734-7ff6297df78b call 7ff6297eded4 call 7ff62980d7b0 RegQueryValueExW 319->326 327 7ff6297df908-7ff6297df90d RegCloseKey 319->327 320->298 321->310 321->314 331 7ff6297df660-7ff6297df66a 322->331 329 7ff6297dfad1-7ff6297dfb87 SHGetFolderPathW lstrcatW CreateFileW lstrlenW WriteFile CloseHandle FindFirstFileW 323->329 330 7ff6297dfa30-7ff6297dfa63 RegQueryValueExW 323->330 332 7ff6297df9e7-7ff6297df9ec RegCloseKey 324->332 333 7ff6297df986-7ff6297df9dd call 7ff6297eded4 call 7ff62980d7b0 RegQueryValueExW 324->333 334 7ff6297df5e4-7ff6297df5f6 Process32NextW 325->334 335 7ff6297df5cc-7ff6297df5d4 325->335 326->327 359 7ff6297df791-7ff6297df7b9 call 7ff6297e1390 326->359 327->318 340 7ff6297dfb91-7ff6297dfbdc FindClose call 7ff6297dfd10 329->340 341 7ff6297dfb89 329->341 337 7ff6297dfa65-7ff6297dfabc call 7ff6297eded4 call 7ff62980d7b0 RegQueryValueExW 330->337 338 7ff6297dfac6-7ff6297dfacb RegCloseKey 330->338 339 7ff6297df670-7ff6297df67a 331->339 332->323 333->332 362 7ff6297df9df 333->362 334->301 334->317 343 7ff6297df5da-7ff6297df5e2 335->343 344 7ff6297df7f9-7ff6297df7fb 335->344 337->338 369 7ff6297dfabe 337->369 338->329 347 7ff6297df694-7ff6297df6a6 Process32NextW 339->347 348 7ff6297df67c-7ff6297df684 339->348 357 7ff6297dfbde-7ff6297dfbe2 340->357 358 7ff6297dfbf8-7ff6297dfc20 call 7ff6297eded4 340->358 341->340 343->325 343->334 344->304 347->308 347->331 353 7ff6297df800-7ff6297df802 348->353 354 7ff6297df68a-7ff6297df692 348->354 353->313 354->339 354->347 357->358 363 7ff6297dfbe4-7ff6297dfbf1 357->363 370 7ff6297dfc23-7ff6297dfc7c 358->370 371 7ff6297df845-7ff6297df855 359->371 372 7ff6297df7bf-7ff6297df7ca 359->372 362->332 363->358 369->338 370->370 375 7ff6297dfc7e-7ff6297dfcac call 7ff62980d110 370->375 373 7ff6297df8cd-7ff6297df8d1 371->373 374 7ff6297df857-7ff6297df85e 371->374 376 7ff6297df7d0-7ff6297df7d9 372->376 373->327 377 7ff6297df8d3-7ff6297df8e5 373->377 378 7ff6297df862-7ff6297df86b 374->378 389 7ff6297dfcbe-7ff6297dfcc1 375->389 390 7ff6297dfcae-7ff6297dfcbb call 7ff6297d3e30 375->390 376->371 380 7ff6297df7db 376->380 381 7ff6297df900-7ff6297df903 call 7ff6297ede64 377->381 382 7ff6297df8e7-7ff6297df8fa 377->382 378->373 383 7ff6297df86d 378->383 385 7ff6297df7e0-7ff6297df7e4 380->385 381->327 382->381 386 7ff6297dfcfe-7ff6297dfd03 call 7ff6297f3d58 382->386 388 7ff6297df870-7ff6297df874 383->388 391 7ff6297df807-7ff6297df80a 385->391 392 7ff6297df7e6-7ff6297df7ee 385->392 395 7ff6297df88b-7ff6297df88e 388->395 396 7ff6297df876-7ff6297df87e 388->396 398 7ff6297dfcc3-7ff6297dfcc6 call 7ff6297ede64 389->398 399 7ff6297dfccb-7ff6297dfcf4 call 7ff6297ede64 389->399 390->389 391->371 393 7ff6297df80c-7ff6297df81c 391->393 392->385 397 7ff6297df7f0 392->397 401 7ff6297df820-7ff6297df826 393->401 395->373 404 7ff6297df890-7ff6297df89d 395->404 396->388 403 7ff6297df880 396->403 397->371 398->399 407 7ff6297df882-7ff6297df886 401->407 408 7ff6297df828-7ff6297df834 401->408 403->373 409 7ff6297df8a0-7ff6297df8a6 404->409 407->376 408->401 412 7ff6297df836-7ff6297df83f 408->412 410 7ff6297dfcf5-7ff6297dfcf9 409->410 411 7ff6297df8ac-7ff6297df8b8 409->411 410->378 411->409 413 7ff6297df8ba-7ff6297df8c3 411->413 412->371 414 7ff6297df8c5 412->414 413->373 413->414 414->373
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Process32QueryValue$Close$CreateFirst$FileNextOpenSnapshotToolhelp32$Concurrency::cancel_current_taskFindWindow$CountFolderForegroundHandleInfoInputLastPathTextTickWrite_invalid_parameter_noinfo_noreturnlstrcatlstrlenwsprintf
              • String ID: %d min$C:\ProgramData\Mylnk$C:\Users$OpenAi_Service$SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders$SOFTWARE\Microsoft\Windows\CurrentVersion\Run$Startup$Telegram.exe$WXWork.exe$WeChat.exe$\kernelquick.sys
              • API String ID: 3029130142-1423135667
              • Opcode ID: cd40ed56a906d75ba6bdc4be580731d37d28795f89819925eba70c9b472de1ca
              • Instruction ID: b557bf54490ddab7372b563ac34deccc8ba07bf4527244de3cbbdf96bafcb493
              • Opcode Fuzzy Hash: cd40ed56a906d75ba6bdc4be580731d37d28795f89819925eba70c9b472de1ca
              • Instruction Fuzzy Hash: 8132B122A19A8285EF60CF25EC046BD77A0FBC9B84F848136DA5D87794EF3CE644D711
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: lstrlen$QueryValue$Open
              • String ID: 10443$4433$Console$Vendata$huazai789.top$huazai789.top$huazai789.top$o1:$o2:$o3:$p1:$p2:$p3:$t1:$t2:$t3:
              • API String ID: 1772312705-3685074344
              • Opcode ID: c599fbb0e57935ebe8c3f9b158b0f14cad8e83e9b9ac755a95a7fb9a9d72626c
              • Instruction ID: e6358204bb49a96cbf657aab49d530723a75ee55a9be2e3da47b98313b6c7ab7
              • Opcode Fuzzy Hash: c599fbb0e57935ebe8c3f9b158b0f14cad8e83e9b9ac755a95a7fb9a9d72626c
              • Instruction Fuzzy Hash: 4922F261F1966B82FF249F16EC506B967A1EFD5B84F844035C58EC2A91EF3CF145A302

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 567 7ff6297dfd10-7ff6297dfd3a GetVersion 568 7ff6297e0284-7ff6297e028f 567->568 569 7ff6297dfd40 567->569 570 7ff6297dfd42-7ff6297dfd46 569->570 571 7ff6297dfd4c-7ff6297dfdf8 GetDesktopWindow GetDC CreateCompatibleDC GetDC GetDeviceCaps * 2 ReleaseDC 569->571 570->568 570->571 572 7ff6297dfe0e-7ff6297dfe2c GetSystemMetrics 571->572 573 7ff6297dfdfa-7ff6297dfe09 571->573 575 7ff6297dfe2e-7ff6297dfe76 GetSystemMetrics 572->575 576 7ff6297dfe78-7ff6297dfe93 GetSystemMetrics 572->576 574 7ff6297dfe97-7ff6297e00db GetSystemMetrics * 2 CreateCompatibleBitmap SelectObject SetStretchBltMode GetSystemMetrics * 2 StretchBlt call 7ff6297eded4 call 7ff62980d7b0 GetDIBits call 7ff6297eded4 call 7ff62980d7b0 call 7ff62980d110 call 7ff6297ede98 call 7ff6297e02a0 573->574 591 7ff6297e01b1-7ff6297e01e1 call 7ff6297eded4 574->591 592 7ff6297e00e1-7ff6297e011b DeleteObject * 2 ReleaseDC call 7ff6297ede64 * 2 574->592 575->574 576->574 597 7ff6297e01e3 591->597 598 7ff6297e01e6-7ff6297e0221 call 7ff62980d110 DeleteObject * 2 ReleaseDC call 7ff6297ede64 * 2 591->598 603 7ff6297e014d-7ff6297e01b0 call 7ff6297ede64 592->603 604 7ff6297e011d-7ff6297e012a 592->604 597->598 616 7ff6297e0226-7ff6297e022e 598->616 607 7ff6297e012c-7ff6297e013f 604->607 608 7ff6297e0148 call 7ff6297ede64 604->608 609 7ff6297e0145 607->609 610 7ff6297e0290-7ff6297e0295 call 7ff6297f3d58 607->610 608->603 609->608 618 7ff6297e0230-7ff6297e023d 616->618 619 7ff6297e025c-7ff6297e027c call 7ff6297ede64 616->619 620 7ff6297e023f-7ff6297e0252 618->620 621 7ff6297e0257 call 7ff6297ede64 618->621 619->568 620->610 623 7ff6297e0254 620->623 621->619 623->621
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: MetricsSystem$Object$CapsCompatibleCreateDeleteDeviceReleaseStretch$BitmapBitsDesktopModeSelectVersionWindow_invalid_parameter_noinfo_noreturn
              • String ID: $($6$gfff$gfff
              • API String ID: 3905184151-2922166585
              • Opcode ID: 23c8a55448e17b2e192b0ad263d360ed319ab87aa3f017f2fb229a62f0da65d9
              • Instruction ID: e6f50fab4e4491ac76698744b28236f50c0f0088e649fdd5a1641726d1338e16
              • Opcode Fuzzy Hash: 23c8a55448e17b2e192b0ad263d360ed319ab87aa3f017f2fb229a62f0da65d9
              • Instruction Fuzzy Hash: 67E1A372A1878186EB259F25E80436AB3A1FFD9BC4F048235EA8E97B55DF3CD4849701

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 626 7ff6297d7250-7ff6297d72a6 627 7ff6297d72b0-7ff6297d72b9 626->627 627->627 628 7ff6297d72bb-7ff6297d72c4 627->628 629 7ff6297d72e2-7ff6297d72e7 call 7ff6297da300 628->629 630 7ff6297d72c6-7ff6297d72e0 call 7ff62980d110 628->630 634 7ff6297d72ec 629->634 630->634 635 7ff6297d72f3-7ff6297d72fb 634->635 635->635 636 7ff6297d72fd-7ff6297d7310 635->636 637 7ff6297d7312-7ff6297d7343 call 7ff62980d110 636->637 638 7ff6297d7345-7ff6297d7355 call 7ff6297da300 636->638 642 7ff6297d735a 637->642 638->642 643 7ff6297d7361-7ff6297d736a 642->643 643->643 644 7ff6297d736c-7ff6297d737f 643->644 645 7ff6297d73b4-7ff6297d73c4 call 7ff6297da300 644->645 646 7ff6297d7381-7ff6297d73b2 call 7ff62980d110 644->646 650 7ff6297d73c9-7ff6297d73cd 645->650 646->650 651 7ff6297d73d4-7ff6297d73dd 650->651 651->651 652 7ff6297d73df-7ff6297d73f2 651->652 653 7ff6297d73f4-7ff6297d7425 call 7ff62980d110 652->653 654 7ff6297d7427-7ff6297d7434 call 7ff6297da300 652->654 658 7ff6297d7439-7ff6297d744d 653->658 654->658 659 7ff6297d7485-7ff6297d749f call 7ff6297da300 658->659 660 7ff6297d744f-7ff6297d7483 call 7ff62980d110 658->660 664 7ff6297d74a4-7ff6297d74af 659->664 660->664 665 7ff6297d74b0-7ff6297d74b9 664->665 665->665 666 7ff6297d74bb-7ff6297d74ce 665->666 667 7ff6297d7503-7ff6297d7510 call 7ff6297da300 666->667 668 7ff6297d74d0-7ff6297d7501 call 7ff62980d110 666->668 672 7ff6297d7515-7ff6297d7519 667->672 668->672 673 7ff6297d7520-7ff6297d7529 672->673 673->673 674 7ff6297d752b-7ff6297d753e 673->674 675 7ff6297d7573-7ff6297d7580 call 7ff6297da300 674->675 676 7ff6297d7540-7ff6297d7571 call 7ff62980d110 674->676 680 7ff6297d7585-7ff6297d7634 call 7ff6297e9170 call 7ff6297e9b00 MultiByteToWideChar * 2 675->680 676->680 685 7ff6297d7663-7ff6297d767d 680->685 686 7ff6297d7636-7ff6297d7647 680->686 689 7ff6297d76b2-7ff6297d76d2 685->689 690 7ff6297d767f-7ff6297d7696 685->690 687 7ff6297d765e call 7ff6297ede64 686->687 688 7ff6297d7649-7ff6297d765c 686->688 687->685 688->687 691 7ff6297d76d9-7ff6297d7717 call 7ff6297f3d58 CreateMutexExW GetLastError 688->691 693 7ff6297d76ad call 7ff6297ede64 690->693 694 7ff6297d7698-7ff6297d76ab 690->694 701 7ff6297d7749-7ff6297d7750 691->701 702 7ff6297d7719 691->702 693->689 694->693 697 7ff6297d76d3-7ff6297d76d8 call 7ff6297f3d58 694->697 697->691 704 7ff6297d77f0-7ff6297d78a2 GetModuleHandleW GetConsoleWindow SHGetFolderPathW lstrcatW CreateMutexW WaitForSingleObject CreateFileW GetFileSize CloseHandle 701->704 705 7ff6297d7756 701->705 703 7ff6297d7720-7ff6297d7747 Sleep CreateMutexW GetLastError 702->703 703->701 703->703 706 7ff6297d78a4-7ff6297d78a7 DeleteFileW 704->706 707 7ff6297d78ad-7ff6297d78dd ReleaseMutex DirectInput8Create 704->707 708 7ff6297d7760-7ff6297d77c0 lstrlenW call 7ff6297d8cd0 705->708 706->707 709 7ff6297d78e3-7ff6297d7903 707->709 710 7ff6297d7980-7ff6297d799e 707->710 714 7ff6297d77c2-7ff6297d77d6 lstrcmpW 708->714 715 7ff6297d77d8-7ff6297d77ea SleepEx 708->715 709->710 716 7ff6297d7905-7ff6297d791b 709->716 714->704 714->715 715->704 715->708 716->710 718 7ff6297d791d-7ff6297d7935 716->718 718->710 720 7ff6297d7937-7ff6297d796d 718->720 720->710 722 7ff6297d796f-7ff6297d797e 720->722 722->710 724 7ff6297d799f-7ff6297d79d1 GetTickCount GetKeyState call 7ff6297dadb0 722->724
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ByteCharMultiWide$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
              • String ID: <$X64$\DisplaySessionContainers.log$key$open
              • API String ID: 143101810-941791203
              • Opcode ID: f52566929edf70c3aaf07bb65ffeca76ea03ad49a5c62821bfeb29e09d75be49
              • Instruction ID: 97389b04d3eddb92ac588bca15dc559eb76c662dac530a73a9a3ea3989548360
              • Opcode Fuzzy Hash: f52566929edf70c3aaf07bb65ffeca76ea03ad49a5c62821bfeb29e09d75be49
              • Instruction Fuzzy Hash: 75228172A19A8296EF10DF25E8042AE73A1FBC4BD4F544631EA9E83B98DF3CD144D741

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 939 7ff6297d79e0-7ff6297d7a2c call 7ff62980d7b0 call 7ff6297efc98 944 7ff6297d7a32-7ff6297d7a46 939->944 945 7ff6297d7afc-7ff6297d7b27 CoCreateInstance 939->945 946 7ff6297d7a50-7ff6297d7a78 call 7ff62980d7b0 CreateToolhelp32Snapshot 944->946 947 7ff6297d7d21-7ff6297d7d2c lstrlenW 945->947 948 7ff6297d7b2d-7ff6297d7b79 945->948 958 7ff6297d7a7a-7ff6297d7a90 Process32FirstW 946->958 959 7ff6297d7ad6-7ff6297d7af6 call 7ff6297efc98 946->959 950 7ff6297d7d2e-7ff6297d7d3e lstrcatW 947->950 951 7ff6297d7d3f-7ff6297d7d46 947->951 956 7ff6297d7d0f-7ff6297d7d19 948->956 957 7ff6297d7b7f-7ff6297d7b9b 948->957 950->951 954 7ff6297d7d4e-7ff6297d7d64 951->954 955 7ff6297d7d48 951->955 955->954 956->947 960 7ff6297d7d1b 956->960 957->956 967 7ff6297d7ba1-7ff6297d7c5d call 7ff62980d7b0 wsprintfW RegOpenKeyExW 957->967 961 7ff6297d7a92-7ff6297d7a9c 958->961 962 7ff6297d7acd-7ff6297d7ad0 CloseHandle 958->962 959->945 959->946 960->947 965 7ff6297d7aa0-7ff6297d7aaa 961->965 962->959 968 7ff6297d7ab4-7ff6297d7ab9 965->968 969 7ff6297d7aac-7ff6297d7ab2 965->969 975 7ff6297d7c63-7ff6297d7cbe call 7ff62980d7b0 RegQueryValueExW 967->975 976 7ff6297d7ced-7ff6297d7cff 967->976 971 7ff6297d7d65-7ff6297d7d6f CloseHandle 968->971 972 7ff6297d7abf-7ff6297d7acb Process32NextW 968->972 969->965 969->968 971->959 974 7ff6297d7d75-7ff6297d7d93 lstrcatW * 2 971->974 972->961 972->962 974->959 980 7ff6297d7ce0-7ff6297d7ce7 RegCloseKey 975->980 981 7ff6297d7cc0-7ff6297d7cda lstrcatW * 2 975->981 979 7ff6297d7d07-7ff6297d7d09 976->979 979->956 979->967 980->976 981->980
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: lstrcat$Close$CreateHandleProcess32$FirstInstanceNextOpenQuerySnapshotToolhelp32Valuelstrlenwsprintf
              • String ID: CLSID\{%.8X-%.4X-%.4X-%.2X%.2X-%.2X%.2X%.2X%.2X%.2X%.2X}$Windows Defender IOfficeAntiVirus implementation
              • API String ID: 582347850-1583895642
              • Opcode ID: 134265c9e40a9f760aa4fceb9a534aa5a21de15c77527937ae6ae4b8d1d4e22b
              • Instruction ID: 0d69fcf0f06746cb43c9b0c04f40ffb277f94585dce5e0ec5b54ca566fcec142
              • Opcode Fuzzy Hash: 134265c9e40a9f760aa4fceb9a534aa5a21de15c77527937ae6ae4b8d1d4e22b
              • Instruction Fuzzy Hash: 2AA19472A08A828AEB20CF35EC406AA77A1FBC5B88F544535DE4D87B68DF3CD645D701

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 998 7ff6297dcd40-7ff6297dcd72 999 7ff6297dd233-7ff6297dd248 call 7ff6297ea5a0 998->999 1000 7ff6297dcd78-7ff6297dcd8e 998->1000 1008 7ff6297dd3e5-7ff6297dd403 999->1008 1009 7ff6297dd24e-7ff6297dd25c call 7ff6297eaaf0 999->1009 1002 7ff6297dcd94-7ff6297dcda9 1000->1002 1003 7ff6297dce2a-7ff6297dce41 1000->1003 1007 7ff6297dcdb0-7ff6297dcdb7 1002->1007 1005 7ff6297dce93 1003->1005 1006 7ff6297dce43-7ff6297dce4d 1003->1006 1012 7ff6297dce96-7ff6297dcf76 call 7ff62980d7b0 * 2 GetSystemDirectoryA call 7ff6297d9e10 CreateProcessA 1005->1012 1010 7ff6297dce50-7ff6297dce5a 1006->1010 1011 7ff6297dcdc0-7ff6297dcdc8 1007->1011 1029 7ff6297dd262-7ff6297dd2e4 call 7ff6297f87a0 * 2 call 7ff6297ede98 call 7ff62980d7b0 call 7ff6297d3670 1009->1029 1030 7ff6297dd386-7ff6297dd3bf call 7ff6297ede98 call 7ff62980d7b0 call 7ff6297f87a0 1009->1030 1014 7ff6297dce60-7ff6297dce6d 1010->1014 1015 7ff6297dce0e-7ff6297dce12 1011->1015 1016 7ff6297dcdca-7ff6297dcdd1 1011->1016 1054 7ff6297dd1ae-7ff6297dd1ff call 7ff6297ede98 call 7ff62980d7b0 call 7ff6297d3670 1012->1054 1055 7ff6297dcf7c-7ff6297dcfa3 VirtualAllocEx 1012->1055 1021 7ff6297dce6f-7ff6297dce79 1014->1021 1022 7ff6297dce7b-7ff6297dce7f 1014->1022 1018 7ff6297dd088-7ff6297dd08c 1015->1018 1019 7ff6297dce18-7ff6297dce24 1015->1019 1023 7ff6297dcdd3-7ff6297dcdda 1016->1023 1024 7ff6297dce0b 1016->1024 1027 7ff6297dd092-7ff6297dd0cf call 7ff6297ede98 call 7ff62980d7b0 call 7ff6297f87a0 1018->1027 1028 7ff6297dce26 1018->1028 1019->1007 1019->1028 1021->1014 1021->1022 1031 7ff6297dce85-7ff6297dce8d 1022->1031 1032 7ff6297dd0d4-7ff6297dd0db 1022->1032 1033 7ff6297dce05-7ff6297dce09 1023->1033 1034 7ff6297dcddc-7ff6297dcde4 1023->1034 1024->1015 1075 7ff6297dd3c3 1027->1075 1028->1003 1092 7ff6297dd2e6-7ff6297dd2f6 call 7ff6297d3e30 1029->1092 1093 7ff6297dd2f9-7ff6297dd323 call 7ff6297ede64 call 7ff6297eac60 1029->1093 1030->1075 1031->1010 1039 7ff6297dce8f 1031->1039 1032->1012 1040 7ff6297dd0e1-7ff6297dd13c call 7ff6297ede98 call 7ff62980d7b0 call 7ff6297f9248 1032->1040 1033->1015 1041 7ff6297dcdff-7ff6297dce03 1034->1041 1042 7ff6297dcde6-7ff6297dcdfb 1034->1042 1039->1005 1077 7ff6297dd140-7ff6297dd191 1040->1077 1041->1015 1042->1011 1048 7ff6297dcdfd 1042->1048 1048->1015 1094 7ff6297dd214-7ff6297dd22e call 7ff6297ede64 1054->1094 1095 7ff6297dd201-7ff6297dd20e 1054->1095 1055->1054 1061 7ff6297dcfa9-7ff6297dcfc4 WriteProcessMemory 1055->1061 1061->1054 1068 7ff6297dcfca-7ff6297dcfe8 GetThreadContext 1061->1068 1068->1054 1074 7ff6297dcfee-7ff6297dd009 SetThreadContext 1068->1074 1074->1054 1079 7ff6297dd00f-7ff6297dd06b ResumeThread call 7ff6297ede98 call 7ff62980d7b0 call 7ff6297d3670 1074->1079 1080 7ff6297dd3c5-7ff6297dd3d2 1075->1080 1081 7ff6297dd3d8 1075->1081 1077->1077 1083 7ff6297dd193-7ff6297dd1a9 1077->1083 1105 7ff6297dd080-7ff6297dd083 1079->1105 1106 7ff6297dd06d-7ff6297dd07d call 7ff6297d3e30 1079->1106 1080->1081 1086 7ff6297dd3db-7ff6297dd3e0 call 7ff6297ede64 1081->1086 1083->1012 1086->1008 1092->1093 1108 7ff6297dd328-7ff6297dd379 call 7ff6297ede98 call 7ff62980d7b0 call 7ff6297d3670 1093->1108 1094->1008 1095->1094 1105->1086 1106->1105 1108->1030
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Thread$ContextProcess$AllocCreateDirectoryMemoryResumeSystemVirtualWrite
              • String ID: %s %s$%s%s$9b5db265-7770-4834-9125-526b4323e01f$@$Windows\System32\svchost.exe$h$nlyloadinmyself$plugmark
              • API String ID: 4033188109-885983150
              • Opcode ID: b9226c03d3f32129d931d83eef70cf8a6a1e94e3ac3e5827d49aa26e2b45b146
              • Instruction ID: 5320edebddfa111e6207cca51053e9491c1c3facd945a7e5785b05eab70b65fa
              • Opcode Fuzzy Hash: b9226c03d3f32129d931d83eef70cf8a6a1e94e3ac3e5827d49aa26e2b45b146
              • Instruction Fuzzy Hash: 3912A162B18A8282EB20CF25D8442BD77A1FBD9B84F488136DB4D87B95DF3CE185D351

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1148 7ff6297ea5a0-7ff6297ea5c1 1149 7ff6297ea5c3-7ff6297ea5cb 1148->1149 1150 7ff6297ea5e0-7ff6297ea5ed SetLastError 1148->1150 1151 7ff6297ea5d1-7ff6297ea5de 1149->1151 1152 7ff6297eaaad-7ff6297eaaba SetLastError 1149->1152 1153 7ff6297ea7e4-7ff6297ea7f8 1150->1153 1151->1150 1154 7ff6297ea5f2-7ff6297ea600 1151->1154 1152->1153 1154->1152 1155 7ff6297ea606-7ff6297ea610 1154->1155 1155->1152 1156 7ff6297ea616-7ff6297ea61c 1155->1156 1156->1152 1157 7ff6297ea622-7ff6297ea636 1156->1157 1158 7ff6297ea665-7ff6297ea696 GetNativeSystemInfo 1157->1158 1159 7ff6297ea638-7ff6297ea63e 1157->1159 1158->1152 1161 7ff6297ea69c-7ff6297ea6cb VirtualAlloc 1158->1161 1160 7ff6297ea640-7ff6297ea647 1159->1160 1162 7ff6297ea64f 1160->1162 1163 7ff6297ea649-7ff6297ea64d 1160->1163 1164 7ff6297ea6f0-7ff6297ea70a 1161->1164 1165 7ff6297ea6cd-7ff6297ea6ea VirtualAlloc 1161->1165 1169 7ff6297ea651-7ff6297ea663 1162->1169 1163->1169 1167 7ff6297ea762-7ff6297ea782 GetProcessHeap HeapAlloc 1164->1167 1168 7ff6297ea70c 1164->1168 1165->1164 1166 7ff6297ea7c7-7ff6297ea7dc SetLastError 1165->1166 1166->1153 1171 7ff6297ea86c-7ff6297ea8cd 1167->1171 1172 7ff6297ea788-7ff6297ea79c VirtualFree 1167->1172 1170 7ff6297ea710-7ff6297ea720 call 7ff6297f3dd0 1168->1170 1169->1158 1169->1160 1182 7ff6297ea829-7ff6297ea83d VirtualFree 1170->1182 1183 7ff6297ea726-7ff6297ea74d VirtualAlloc 1170->1183 1175 7ff6297ea8cf-7ff6297ea8d4 SetLastError 1171->1175 1176 7ff6297ea8e7-7ff6297ea934 VirtualAlloc call 7ff62980d110 call 7ff6297ea000 1171->1176 1172->1166 1174 7ff6297ea79e 1172->1174 1179 7ff6297ea7a0-7ff6297ea7c5 VirtualFree call 7ff6297f3938 1174->1179 1180 7ff6297ea8da-7ff6297ea8e2 call 7ff6297eac60 1175->1180 1176->1180 1196 7ff6297ea936-7ff6297ea941 1176->1196 1179->1166 1180->1176 1182->1166 1187 7ff6297ea83f 1182->1187 1188 7ff6297ea753-7ff6297ea760 1183->1188 1189 7ff6297ea800-7ff6297ea825 VirtualFree call 7ff6297f3938 1183->1189 1194 7ff6297ea840-7ff6297ea865 VirtualFree call 7ff6297f3938 1187->1194 1188->1167 1188->1170 1198 7ff6297ea827 1189->1198 1205 7ff6297ea867 1194->1205 1199 7ff6297ea9d9 1196->1199 1200 7ff6297ea947-7ff6297ea94d 1196->1200 1198->1166 1202 7ff6297ea9de-7ff6297ea9eb call 7ff6297ea3d0 1199->1202 1203 7ff6297ea94f-7ff6297ea951 1200->1203 1204 7ff6297ea956-7ff6297ea969 1200->1204 1202->1180 1210 7ff6297ea9f1-7ff6297ea9f4 call 7ff6297ea140 1202->1210 1203->1202 1204->1199 1207 7ff6297ea96b 1204->1207 1205->1166 1209 7ff6297ea970-7ff6297ea98b 1207->1209 1211 7ff6297ea9cc-7ff6297ea9d7 1209->1211 1212 7ff6297ea98d 1209->1212 1215 7ff6297ea9f9-7ff6297ea9fb 1210->1215 1211->1199 1211->1209 1214 7ff6297ea990-7ff6297ea9a1 1212->1214 1216 7ff6297ea9a3-7ff6297ea9a6 1214->1216 1217 7ff6297ea9ae 1214->1217 1215->1180 1218 7ff6297eaa01-7ff6297eaa0c 1215->1218 1219 7ff6297ea9b2-7ff6297ea9ca 1216->1219 1220 7ff6297ea9a8-7ff6297ea9ac 1216->1220 1217->1219 1221 7ff6297eaa0e-7ff6297eaa1a 1218->1221 1222 7ff6297eaa4a-7ff6297eaa52 1218->1222 1219->1211 1219->1214 1220->1219 1221->1222 1225 7ff6297eaa1c-7ff6297eaa22 1221->1225 1223 7ff6297eaa54-7ff6297eaa5b 1222->1223 1224 7ff6297eaaa1-7ff6297eaaa5 1222->1224 1226 7ff6297eaa95-7ff6297eaa99 1223->1226 1227 7ff6297eaa5d-7ff6297eaa6c 1223->1227 1224->1152 1225->1222 1228 7ff6297eaa24-7ff6297eaa28 1225->1228 1226->1224 1231 7ff6297eaa6e-7ff6297eaa81 SetLastError call 7ff6297eac60 1227->1231 1232 7ff6297eaa86-7ff6297eaa8d 1227->1232 1229 7ff6297eaa30-7ff6297eaa48 1228->1229 1229->1222 1231->1232 1232->1226
              APIs
              • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA5E5
              • GetNativeSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA66A
              • VirtualAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA6BF
              • VirtualAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA6DE
              • VirtualAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA741
              • GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA762
              • HeapAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA776
              • VirtualFree.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA793
              • VirtualFree.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA7AF
              • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA7CC
              • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EAAB2
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Virtual$Alloc$ErrorLast$FreeHeap$InfoNativeProcessSystem
              • String ID:
              • API String ID: 1282860858-0
              • Opcode ID: 2db4db2f5dea0229961aa6511efc0787ebed8919f4287dccc69c8883441e57f8
              • Instruction ID: 74e816ab0669b5dc2206821c97dbce6777b1135ddab34da1056e49c0126a2c58
              • Opcode Fuzzy Hash: 2db4db2f5dea0229961aa6511efc0787ebed8919f4287dccc69c8883441e57f8
              • Instruction Fuzzy Hash: 0CD14031B1964286EF68CF16D8547B973A4EFC9BC4F498435CA8D87790EE3CE541A306
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ControlDevice$ByteCharCloseCreateFileHandleMultiWide$wsprintf
              • String ID: \\.\HCD%d
              • API String ID: 2324936672-2696249065
              • Opcode ID: b16b9414ff4f5bba01ca19ea586cfc01d35dadd3bdcc9ae74a2dc0319bdc3a1e
              • Instruction ID: dc9df655f15d230499b4b421d1bff7fbc276b9a3dfa859198fa56b9df881dd96
              • Opcode Fuzzy Hash: b16b9414ff4f5bba01ca19ea586cfc01d35dadd3bdcc9ae74a2dc0319bdc3a1e
              • Instruction Fuzzy Hash: 74519E32608B8186EF609F11B8407AAB6A4FBC57D8F184135EA9E87B95EF3CD015DB01
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Thread$Window$CloseConsoleCreateCurrentExceptionFilterHandleInputMessageObjectPostShowSingleSleepStateUnhandledWait
              • String ID:
              • API String ID: 2277684705-0
              • Opcode ID: 6f2be5bc360ff60992bf957455bd65437668e6ddaf6ac78ef69b290b53bfb88b
              • Instruction ID: 69b4dc8ac8b1c16934775780852df300b1df50e7fa6526cba2464d4be1e610ed
              • Opcode Fuzzy Hash: 6f2be5bc360ff60992bf957455bd65437668e6ddaf6ac78ef69b290b53bfb88b
              • Instruction Fuzzy Hash: 6B012C35E1AE8282EB149F71EC5457933A1FFC8751F498934C80EC3670DF3CA049A202
              APIs
              • _get_daylight.LIBCMT ref: 00007FF629801DED
                • Part of subcall function 00007FF629801464: _invalid_parameter_noinfo.LIBCMT ref: 00007FF629801478
                • Part of subcall function 00007FF6297FE6BC: RtlFreeHeap.NTDLL(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6D2
                • Part of subcall function 00007FF6297FE6BC: GetLastError.KERNEL32(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6DC
                • Part of subcall function 00007FF6297F3D88: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF6297F3D37,?,?,?,?,?,00007FF6297F3C22), ref: 00007FF6297F3D91
                • Part of subcall function 00007FF6297F3D88: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF6297F3D37,?,?,?,?,?,00007FF6297F3C22), ref: 00007FF6297F3DB6
                • Part of subcall function 00007FF629809F14: _invalid_parameter_noinfo.LIBCMT ref: 00007FF629809E5F
              • _get_daylight.LIBCMT ref: 00007FF629801DDC
                • Part of subcall function 00007FF6298014C4: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6298014D8
              • _get_daylight.LIBCMT ref: 00007FF629802052
              • _get_daylight.LIBCMT ref: 00007FF629802063
              • _get_daylight.LIBCMT ref: 00007FF629802074
              • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF6298022B4), ref: 00007FF62980209B
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
              • String ID: Eastern Standard Time$Eastern Summer Time
              • API String ID: 4070488512-239921721
              • Opcode ID: e4d215210ab8a5127c723f465f4324ebd8545cea5875ff9c0ed7522d57f15f04
              • Instruction ID: 164d4f138c2cfd211a800ee46dc6b5324585f2318602d37e6732fcbbd1f05567
              • Opcode Fuzzy Hash: e4d215210ab8a5127c723f465f4324ebd8545cea5875ff9c0ed7522d57f15f04
              • Instruction Fuzzy Hash: C6D1BF26E0964286EF20EF25DC902B96661FFC47A4F484835EE0DC7A96DF3CE441E742
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ControlDevice_invalid_parameter_noinfo_noreturn$CreateFilewsprintf
              • String ID:
              • API String ID: 3155671162-0
              • Opcode ID: 2d5e32564994beb84768749377adeec3dde269dff25c4089fb8d85357c90455d
              • Instruction ID: a8e4c5ab6213ba2ebb5945397518387d98518c114359d610181f83aa5d2629a6
              • Opcode Fuzzy Hash: 2d5e32564994beb84768749377adeec3dde269dff25c4089fb8d85357c90455d
              • Instruction Fuzzy Hash: 3002AF22F08B8189EF00DF61E8102ED63A1AB85BE8F044635EE5D97BD9DF3CE445A341
              APIs
              • _get_daylight.LIBCMT ref: 00007FF629802052
                • Part of subcall function 00007FF6298014C4: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6298014D8
              • _get_daylight.LIBCMT ref: 00007FF629802063
                • Part of subcall function 00007FF629801464: _invalid_parameter_noinfo.LIBCMT ref: 00007FF629801478
              • _get_daylight.LIBCMT ref: 00007FF629802074
                • Part of subcall function 00007FF629801494: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6298014A8
                • Part of subcall function 00007FF6297FE6BC: RtlFreeHeap.NTDLL(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6D2
                • Part of subcall function 00007FF6297FE6BC: GetLastError.KERNEL32(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6DC
              • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF6298022B4), ref: 00007FF62980209B
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
              • String ID: Eastern Standard Time$Eastern Summer Time
              • API String ID: 3458911817-239921721
              • Opcode ID: d39622db5b0ee5333b178c37cbbab90ca343d8bae9bfc90199294d5daa5d9118
              • Instruction ID: c17caaa019dc1031a5565540c24bbc4f381a5bac2d4c07f5daa77aae19b37bdb
              • Opcode Fuzzy Hash: d39622db5b0ee5333b178c37cbbab90ca343d8bae9bfc90199294d5daa5d9118
              • Instruction Fuzzy Hash: A0517F32E1968286EF20DF21DC815B97761BFC8794F484936EA4DC3A96DF3CE441A742
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _get_daylight$_isindst$_invalid_parameter_noinfo
              • String ID:
              • API String ID: 1405656091-0
              • Opcode ID: bc1b3b9caf7716422d15d8d8075c51535e8cc771750b1ef0c981aa63b125a24c
              • Instruction ID: 900934f287734a8d413da50959e998b05a10f67654ab3dd3deedaf30fdbe6acf
              • Opcode Fuzzy Hash: bc1b3b9caf7716422d15d8d8075c51535e8cc771750b1ef0c981aa63b125a24c
              • Instruction Fuzzy Hash: F491B3B2B053468BEF588F25CD412B82291EB94BC8F549039DE0E9BB89EF3CE5419741
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Virtual$AllocFreeTimerecvselecttime
              • String ID:
              • API String ID: 1996171534-0
              • Opcode ID: 6a2d55f36b77c358a951ba4548c2a2acb045dcba24c00c69cff2d5afcb20d37b
              • Instruction ID: 10e1d8315aef429a731f0d6acc3dc6068aab6c1ec23b85165cc2a50d883df11c
              • Opcode Fuzzy Hash: 6a2d55f36b77c358a951ba4548c2a2acb045dcba24c00c69cff2d5afcb20d37b
              • Instruction Fuzzy Hash: CC715D72A18A8581EB209F29D8046BD3360FBD5BC8F549235DF8D83795EF38E584D711
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Virtual$AllocFree
              • String ID:
              • API String ID: 2087232378-0
              • Opcode ID: 7adfbc43d79927e24f2f975998fe396b12a3d4926a19e200812a52629311d3ed
              • Instruction ID: 4cec014c12844507d2444b812732b2cf4f820860baf66e27a0e488f177673c52
              • Opcode Fuzzy Hash: 7adfbc43d79927e24f2f975998fe396b12a3d4926a19e200812a52629311d3ed
              • Instruction Fuzzy Hash: 7641C332B09A458AEB0DCE2AE850669A765FB88FC4B084539EE4EC7744EF3CD841D750

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 727 7ff6297d8900-7ff6297d8938 GetCurrentProcessId OpenProcess 728 7ff6297d893a-7ff6297d895c OpenProcessToken 727->728 729 7ff6297d8967-7ff6297d896c 727->729 730 7ff6297d895e-7ff6297d8961 CloseHandle 728->730 731 7ff6297d8971-7ff6297d8a12 call 7ff6297d8690 call 7ff62980d110 CloseHandle * 2 728->731 732 7ff6297d8a9a-7ff6297d8ab4 729->732 730->729 737 7ff6297d8a14-7ff6297d8a2b 731->737 738 7ff6297d8a4f-7ff6297d8a63 731->738 739 7ff6297d8a42-7ff6297d8a47 call 7ff6297ede64 737->739 740 7ff6297d8a2d-7ff6297d8a40 737->740 741 7ff6297d8a65-7ff6297d8a7c 738->741 742 7ff6297d8a98 738->742 739->738 740->739 743 7ff6297d8abb-7ff6297d8b39 call 7ff6297f3d58 call 7ff6297eded4 GetCurrentProcessId wsprintfW call 7ff6297d8900 call 7ff62980d7b0 GetVersionExW 740->743 745 7ff6297d8a93 call 7ff6297ede64 741->745 746 7ff6297d8a7e-7ff6297d8a91 741->746 742->732 761 7ff6297d8c92 743->761 762 7ff6297d8b3f-7ff6297d8b44 743->762 745->742 746->745 749 7ff6297d8ab5-7ff6297d8aba call 7ff6297f3d58 746->749 749->743 764 7ff6297d8c99-7ff6297d8ca3 wsprintfW 761->764 762->761 763 7ff6297d8b4a-7ff6297d8b4f 762->763 763->761 766 7ff6297d8b55-7ff6297d8b7b GetCurrentProcess OpenProcessToken 763->766 765 7ff6297d8ca9-7ff6297d8cc0 call 7ff6297ede64 764->765 766->761 768 7ff6297d8b81-7ff6297d8bb0 GetTokenInformation 766->768 770 7ff6297d8c3c-7ff6297d8c4c CloseHandle 768->770 771 7ff6297d8bb6-7ff6297d8bbf GetLastError 768->771 770->761 773 7ff6297d8c4e-7ff6297d8c54 770->773 771->770 772 7ff6297d8bc1-7ff6297d8be1 LocalAlloc 771->772 774 7ff6297d8be3-7ff6297d8c10 GetTokenInformation 772->774 775 7ff6297d8c34 772->775 776 7ff6297d8c56-7ff6297d8c5c 773->776 777 7ff6297d8c89-7ff6297d8c90 773->777 778 7ff6297d8c12-7ff6297d8c29 GetSidSubAuthorityCount GetSidSubAuthority 774->778 779 7ff6297d8c2b-7ff6297d8c2e LocalFree 774->779 775->770 780 7ff6297d8c5e-7ff6297d8c64 776->780 781 7ff6297d8c80-7ff6297d8c87 776->781 777->764 778->779 779->775 782 7ff6297d8c77-7ff6297d8c7e 780->782 783 7ff6297d8c66-7ff6297d8c6c 780->783 781->764 782->764 783->765 784 7ff6297d8c6e-7ff6297d8c75 783->784 784->764
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Process$CloseHandleToken$CurrentOpen$AuthorityInformationLocal_invalid_parameter_noinfo_noreturnwsprintf$AllocCountErrorFreeLastVersion
              • String ID: -N/$NO/$None/%s$VenNetwork
              • API String ID: 3589523989-819860926
              • Opcode ID: 450628a110485d3eb8edb58debbdbfde318f95bac93751fab00fe031b43d7a27
              • Instruction ID: c419760e597b5630b1add909bb1aadd158b3a4232c21a1bbc8c035577959562b
              • Opcode Fuzzy Hash: 450628a110485d3eb8edb58debbdbfde318f95bac93751fab00fe031b43d7a27
              • Instruction Fuzzy Hash: CCA16C62A0DB8282EF609F25E8443BA6360FFC5B90F448635DA9D83B98DF3CD545D702

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 785 7ff6297e02a0-7ff6297e0319 GlobalAlloc GlobalLock call 7ff62980d110 GlobalUnlock CreateStreamOnHGlobal 788 7ff6297e031f-7ff6297e037e call 7ff6297d61e0 EnterCriticalSection LeaveCriticalSection call 7ff6297dc9b0 785->788 789 7ff6297e0671-7ff6297e067a GlobalFree 785->789 795 7ff6297e0384-7ff6297e03ae GdipCreateBitmapFromStream 788->795 796 7ff6297e05ee-7ff6297e0604 788->796 790 7ff6297e067d-7ff6297e0697 789->790 797 7ff6297e03b0-7ff6297e03b6 GdipDisposeImage 795->797 798 7ff6297e03bb-7ff6297e03d6 call 7ff6297dc340 GdipDisposeImage 795->798 801 7ff6297e062a-7ff6297e0640 call 7ff6297d61e0 EnterCriticalSection 796->801 802 7ff6297e0606-7ff6297e0624 DeleteObject 796->802 797->796 798->796 805 7ff6297e03dc-7ff6297e03f3 CreateStreamOnHGlobal 798->805 808 7ff6297e0642-7ff6297e0652 EnterCriticalSection 801->808 809 7ff6297e0667-7ff6297e066b LeaveCriticalSection 801->809 802->801 805->796 807 7ff6297e03f9-7ff6297e0401 call 7ff6297dc7b0 805->807 813 7ff6297e0406-7ff6297e0428 GetHGlobalFromStream GlobalLock 807->813 811 7ff6297e0654 GdiplusShutdown 808->811 812 7ff6297e065a-7ff6297e0661 LeaveCriticalSection 808->812 809->789 811->812 812->809 814 7ff6297e04bf-7ff6297e0508 GlobalSize call 7ff6297eded4 call 7ff62980d110 call 7ff6297d9e70 813->814 815 7ff6297e042e-7ff6297e044d GlobalFree 813->815 831 7ff6297e055e 814->831 832 7ff6297e050a-7ff6297e0512 814->832 820 7ff6297e044f-7ff6297e046b DeleteObject 815->820 821 7ff6297e0471-7ff6297e0487 call 7ff6297d61e0 EnterCriticalSection 815->821 820->821 826 7ff6297e04ae-7ff6297e04ba LeaveCriticalSection 821->826 827 7ff6297e0489-7ff6297e0499 EnterCriticalSection 821->827 826->790 829 7ff6297e04a1-7ff6297e04a8 LeaveCriticalSection 827->829 830 7ff6297e049b GdiplusShutdown 827->830 829->826 830->829 833 7ff6297e0562-7ff6297e0566 831->833 834 7ff6297e0544-7ff6297e055c 832->834 835 7ff6297e0514-7ff6297e0521 832->835 836 7ff6297e0599-7ff6297e05ad call 7ff6297ede64 833->836 837 7ff6297e0568-7ff6297e0579 833->837 834->833 838 7ff6297e0523-7ff6297e0536 835->838 839 7ff6297e053f call 7ff6297ede64 835->839 849 7ff6297e05d3-7ff6297e05e7 GlobalUnlock 836->849 850 7ff6297e05af-7ff6297e05cd DeleteObject 836->850 841 7ff6297e0594 call 7ff6297ede64 837->841 842 7ff6297e057b-7ff6297e058e 837->842 844 7ff6297e053c 838->844 845 7ff6297e0698-7ff6297e069f call 7ff6297f3d58 838->845 839->834 841->836 842->841 842->845 844->839 849->796 850->849
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$Global$EnterLeave$Stream$CreateGdip$DeleteDisposeFreeFromGdiplusImageLockObjectShutdown$AllocBitmapErrorInitializeLastUnlock_invalid_parameter_noinfo_noreturn
              • String ID:
              • API String ID: 953580087-0
              • Opcode ID: bd51bed798d7755ae1ba6cc52b0510cce8857c70ba01d429c7def06d381aeeb7
              • Instruction ID: 5bf70ff574659c38c5a803d8e17ac0154dcc7d758154149090c4944708c345d8
              • Opcode Fuzzy Hash: bd51bed798d7755ae1ba6cc52b0510cce8857c70ba01d429c7def06d381aeeb7
              • Instruction Fuzzy Hash: E3C13A36B09B428AEB00DF65E8042AD2371FB84B98F048535DE5E97A99DF3CE459E341

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 853 7ff6297dc340-7ff6297dc383 GdipGetImagePixelFormat 854 7ff6297dc385 853->854 855 7ff6297dc387-7ff6297dc3a4 853->855 854->855 856 7ff6297dc3a6-7ff6297dc3b3 855->856 857 7ff6297dc3b9-7ff6297dc3c4 855->857 856->857 858 7ff6297dc3db-7ff6297dc400 GdipGetImageHeight 857->858 859 7ff6297dc3c6-7ff6297dc3d4 857->859 860 7ff6297dc402-7ff6297dc40c 858->860 861 7ff6297dc40f-7ff6297dc422 GdipGetImageWidth 858->861 859->858 860->861 862 7ff6297dc424 861->862 863 7ff6297dc426-7ff6297dc447 call 7ff6297dc160 861->863 862->863 866 7ff6297dc453-7ff6297dc45b 863->866 867 7ff6297dc449-7ff6297dc44e 863->867 869 7ff6297dc461-7ff6297dc478 GdipGetImagePaletteSize 866->869 870 7ff6297dc60d-7ff6297dc61c 866->870 868 7ff6297dc773-7ff6297dc78c 867->868 871 7ff6297dc47a 869->871 872 7ff6297dc47c-7ff6297dc487 869->872 873 7ff6297dc6e2-7ff6297dc74d GdipCreateBitmapFromScan0 GdipGetImageGraphicsContext GdipDrawImageI GdipDeleteGraphics GdipDisposeImage 870->873 874 7ff6297dc622-7ff6297dc64e GdipBitmapLockBits 870->874 871->872 875 7ff6297dc4ba-7ff6297dc4c6 call 7ff6297f3dd0 872->875 876 7ff6297dc489-7ff6297dc492 call 7ff6297db2e0 872->876 877 7ff6297dc753-7ff6297dc756 873->877 878 7ff6297dc650-7ff6297dc65a 874->878 879 7ff6297dc66a-7ff6297dc686 874->879 892 7ff6297dc4cd-7ff6297dc4d4 875->892 893 7ff6297dc4c8-7ff6297dc4cb 875->893 876->875 896 7ff6297dc494-7ff6297dc49b 876->896 883 7ff6297dc770 877->883 884 7ff6297dc758 877->884 878->877 880 7ff6297dc6c4-7ff6297dc6db GdipBitmapUnlockBits 879->880 881 7ff6297dc688-7ff6297dc68b 879->881 880->877 889 7ff6297dc6dd-7ff6297dc6e0 880->889 887 7ff6297dc6ad-7ff6297dc6c2 881->887 888 7ff6297dc68d-7ff6297dc690 881->888 883->868 891 7ff6297dc760-7ff6297dc76e call 7ff6297f3938 884->891 887->880 887->881 894 7ff6297dc794-7ff6297dc7af call 7ff6297f8afc call 7ff6297f3d38 call 7ff6297d10f0 888->894 895 7ff6297dc696-7ff6297dc69f 888->895 889->877 891->883 898 7ff6297dc4d7-7ff6297dc4da 892->898 893->898 900 7ff6297dc6a5-7ff6297dc6a8 call 7ff62980d110 895->900 901 7ff6297dc78d-7ff6297dc78f call 7ff62980d7b0 895->901 902 7ff6297dc49d 896->902 903 7ff6297dc4a7-7ff6297dc4b8 call 7ff6297ee4e0 896->903 906 7ff6297dc4dc-7ff6297dc4e2 898->906 907 7ff6297dc4e7-7ff6297dc4f9 GdipGetImagePalette 898->907 900->887 901->894 902->903 903->898 906->877 911 7ff6297dc4ff-7ff6297dc50a 907->911 912 7ff6297dc4fb 907->912 916 7ff6297dc65f-7ff6297dc665 911->916 917 7ff6297dc510-7ff6297dc515 911->917 912->911 916->877 919 7ff6297dc555-7ff6297dc55d 917->919 920 7ff6297dc517 917->920 923 7ff6297dc55f-7ff6297dc56a call 7ff6297d6280 919->923 924 7ff6297dc5aa-7ff6297dc5c2 SetDIBColorTable 919->924 922 7ff6297dc520-7ff6297dc553 920->922 922->919 922->922 931 7ff6297dc570-7ff6297dc57d 923->931 925 7ff6297dc5c4-7ff6297dc5de SelectObject call 7ff6297d6280 924->925 926 7ff6297dc607 924->926 934 7ff6297dc5e0-7ff6297dc5ea 925->934 926->870 932 7ff6297dc57f-7ff6297dc584 931->932 933 7ff6297dc58e-7ff6297dc5a6 SelectObject 931->933 932->931 935 7ff6297dc586-7ff6297dc588 CreateCompatibleDC 932->935 933->924 936 7ff6297dc5fc-7ff6297dc603 934->936 937 7ff6297dc5ec-7ff6297dc5f1 934->937 935->933 936->926 937->934 938 7ff6297dc5f3-7ff6297dc5f6 DeleteDC 937->938 938->936
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Gdip$Image$Bitmap$BitsCreateDeleteGraphicsObjectPaletteSelect$ColorCompatibleContextDisposeDrawFormatFromHeightLockPixelScan0SizeTableUnlockWidth_invalid_parameter_noinfo
              • String ID: &
              • API String ID: 4034434136-3042966939
              • Opcode ID: dd11024c4d0ee26c12cb960423acbe48478663fb147fae3e010d538c7f7c31a7
              • Instruction ID: 273ef5da407a75a6094d79f82f99ae4d166b372158dff8c4f0f06a34bc61cd6b
              • Opcode Fuzzy Hash: dd11024c4d0ee26c12cb960423acbe48478663fb147fae3e010d538c7f7c31a7
              • Instruction Fuzzy Hash: D9D1CC72A05A828AEB608F21D9446BC37A4FB84BD8F098435DF1E97B84DF3CE904D751

              Control-flow Graph

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: setsockopt$ByteCharMultiWidelstrlen$EventIoctlResetTimeconnectgethostbynamehtonssockettime
              • String ID: 0u
              • API String ID: 3082052849-3203441087
              • Opcode ID: e6a13d699f6763c7654f24c20153140ddf5521bbc938d0bcbfbca2fb93ded773
              • Instruction ID: 9a9564c4dbad45cf3266a518d48e973739a0d9a78e44ca9c658081014ef9d66a
              • Opcode Fuzzy Hash: e6a13d699f6763c7654f24c20153140ddf5521bbc938d0bcbfbca2fb93ded773
              • Instruction Fuzzy Hash: A2713D72609B8186EB20CF21F84076AB7A5FB84B94F044239EA9E47B58DF3DD149DB05
              APIs
                • Part of subcall function 0000000180002AE0: RegOpenKeyExW.ADVAPI32 ref: 00000001800027CE
                • Part of subcall function 00000001800033C0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00000001800034F6
                • Part of subcall function 00000001800033C0: Concurrency::cancel_current_task.LIBCPMT ref: 00000001800034FC
              • RegOpenKeyExW.ADVAPI32 ref: 0000000180002B74
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Open$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
              • String ID: CleanTempTrash$Failed to open source registry key. Error: $OpenAi_Service$SOFTWARE\AiServer$Software\AiServer$Software\Microsoft\Windows\CurrentVersion\Run$Startup item added successfully!$getinfo_mark
              • API String ID: 1623771123-487670668
              • Opcode ID: 31687ab3facf5392310ce355a23f745cdf45f1b013910d7f5573e4811e5d18d7
              • Instruction ID: 3aee7fd0f9c7fee61078e072a23cf8b7440c246dedc74f5af328adb52fafc02c
              • Opcode Fuzzy Hash: 31687ab3facf5392310ce355a23f745cdf45f1b013910d7f5573e4811e5d18d7
              • Instruction Fuzzy Hash: 9451B472614A8895FBA2DB28E4847DE7361F7897D4F509202FA9D43AE9DF78C648C700

              Control-flow Graph

              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Process$Token$CurrentOpen$AuthorityCloseHandleInformationLocalwsprintf$AllocCountErrorFreeLastVersion
              • String ID: VenNetwork
              • API String ID: 4155081256-3057682757
              • Opcode ID: 1692176833e3a9b7a26e51401c227b190f30f5d7bbf91e349ba2e469b46507f9
              • Instruction ID: bd437d130500fbeec262de9800465d4e0524ce7081f8d34249f576e85ca2138f
              • Opcode Fuzzy Hash: 1692176833e3a9b7a26e51401c227b190f30f5d7bbf91e349ba2e469b46507f9
              • Instruction Fuzzy Hash: 07411B31A0A682C1EF619F61EC447FA2360EFC5B81F488535DA8E82794DF3CD449E712

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1236 7ff6297ebdd0-7ff6297ebdf7 1237 7ff6297ec190-7ff6297ec1a1 CloseHandle 1236->1237 1238 7ff6297ebdfd-7ff6297ebe17 1236->1238 1239 7ff6297ebe20-7ff6297ebe3a call 7ff6297f3dd0 1238->1239 1242 7ff6297ec170-7ff6297ec188 1239->1242 1243 7ff6297ebe40-7ff6297ebe7c DeviceIoControl 1239->1243 1242->1237 1244 7ff6297ebe82-7ff6297ebe86 1243->1244 1245 7ff6297ec168-7ff6297ec16b call 7ff6297f3938 1243->1245 1246 7ff6297ebe8c-7ff6297ebeeb DeviceIoControl 1244->1246 1247 7ff6297ec15a-7ff6297ec160 1244->1247 1245->1242 1249 7ff6297ebf84-7ff6297ebf88 1246->1249 1250 7ff6297ebef1-7ff6297ebef8 1246->1250 1247->1239 1251 7ff6297ec166 1247->1251 1253 7ff6297ec075-7ff6297ec0cd call 7ff62980d7b0 call 7ff6297ec5c0 * 2 1249->1253 1254 7ff6297ebf8e-7ff6297ebfd5 DeviceIoControl 1249->1254 1250->1249 1252 7ff6297ebefe-7ff6297ebf06 1250->1252 1251->1242 1252->1249 1255 7ff6297ebf08-7ff6297ebf1e GlobalAlloc 1252->1255 1271 7ff6297ec0d2-7ff6297ec0f9 call 7ff6297ebd70 1253->1271 1254->1253 1257 7ff6297ebfdb-7ff6297ebfe8 1254->1257 1255->1249 1258 7ff6297ebf20-7ff6297ebf64 DeviceIoControl 1255->1258 1257->1253 1260 7ff6297ebfee-7ff6297ec001 GlobalAlloc 1257->1260 1261 7ff6297ebf7b-7ff6297ebf7e GlobalFree 1258->1261 1262 7ff6297ebf66-7ff6297ebf6c 1258->1262 1260->1253 1264 7ff6297ec003-7ff6297ec03f DeviceIoControl 1260->1264 1261->1249 1262->1261 1265 7ff6297ebf6e-7ff6297ebf79 1262->1265 1267 7ff6297ec041-7ff6297ec059 call 7ff6297ec520 GlobalFree 1264->1267 1268 7ff6297ec06c-7ff6297ec06f GlobalFree 1264->1268 1265->1249 1265->1261 1267->1253 1273 7ff6297ec05b-7ff6297ec06a call 7ff6297ec1b0 1267->1273 1268->1253 1278 7ff6297ec100-7ff6297ec107 1271->1278 1273->1253 1278->1278 1279 7ff6297ec109-7ff6297ec10d 1278->1279 1280 7ff6297ec114-7ff6297ec11c 1279->1280 1280->1280 1281 7ff6297ec11e-7ff6297ec128 1280->1281 1281->1242 1282 7ff6297ec12a-7ff6297ec12d 1281->1282 1283 7ff6297ec130-7ff6297ec138 1282->1283 1283->1283 1284 7ff6297ec13a-7ff6297ec13e 1283->1284 1285 7ff6297ec140-7ff6297ec14e 1284->1285 1285->1285 1286 7ff6297ec150-7ff6297ec155 1285->1286 1286->1247
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ControlDeviceGlobal$Free$Alloc
              • String ID: - External Hub$%s-%s|
              • API String ID: 3253977144-729331614
              • Opcode ID: 6ebde190928095b1eae62e95338309e58df42c3839912d6c9fa9ddc0bde6fb78
              • Instruction ID: 6accf1e0f1fbe5a6c731d1e2f0840196f1363627f68666d356ee603c171c9897
              • Opcode Fuzzy Hash: 6ebde190928095b1eae62e95338309e58df42c3839912d6c9fa9ddc0bde6fb78
              • Instruction Fuzzy Hash: 29B1AD72A08B8185EB20CF11E8403EAB7A0FBC5794F584139DB8997BA4DF3CD544C701

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1287 7ff6297d8690-7ff6297d86bf 1288 7ff6297d86c4-7ff6297d86d3 1287->1288 1289 7ff6297d86c1 1287->1289 1290 7ff6297d86d5 1288->1290 1291 7ff6297d86d8-7ff6297d86ed 1288->1291 1289->1288 1290->1291 1292 7ff6297d86f3-7ff6297d8713 GetTokenInformation 1291->1292 1293 7ff6297d88d8 1291->1293 1294 7ff6297d8715-7ff6297d871e GetLastError 1292->1294 1295 7ff6297d874e-7ff6297d8776 GetTokenInformation 1292->1295 1296 7ff6297d88da-7ff6297d88f1 1293->1296 1294->1293 1297 7ff6297d8724-7ff6297d8748 GetProcessHeap HeapAlloc 1294->1297 1298 7ff6297d88bf-7ff6297d88c2 1295->1298 1299 7ff6297d877c-7ff6297d87be LookupAccountSidW 1295->1299 1297->1293 1297->1295 1298->1293 1300 7ff6297d88c4-7ff6297d88d2 GetProcessHeap HeapFree 1298->1300 1301 7ff6297d87ef-7ff6297d87fe 1299->1301 1302 7ff6297d87c0-7ff6297d87cb GetLastError 1299->1302 1300->1293 1305 7ff6297d8800-7ff6297d8807 1301->1305 1303 7ff6297d87cd-7ff6297d87e3 call 7ff6297f87a0 1302->1303 1304 7ff6297d87e8-7ff6297d87ea 1302->1304 1303->1298 1304->1296 1305->1305 1307 7ff6297d8809-7ff6297d8818 1305->1307 1308 7ff6297d8844-7ff6297d884c call 7ff6297da1a0 1307->1308 1309 7ff6297d881a-7ff6297d8821 1307->1309 1315 7ff6297d8851-7ff6297d8859 1308->1315 1311 7ff6297d8823 1309->1311 1312 7ff6297d8826-7ff6297d8842 call 7ff62980d110 1309->1312 1311->1312 1312->1315 1317 7ff6297d8860-7ff6297d8867 1315->1317 1317->1317 1318 7ff6297d8869-7ff6297d8870 1317->1318 1319 7ff6297d8872-7ff6297d8879 1318->1319 1320 7ff6297d889f-7ff6297d88ad call 7ff6297da1a0 1318->1320 1322 7ff6297d887e-7ff6297d889d call 7ff62980d110 1319->1322 1323 7ff6297d887b 1319->1323 1324 7ff6297d88b2-7ff6297d88ba 1320->1324 1322->1324 1323->1322 1324->1298
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Heap$ErrorInformationLastProcessToken$AccountAllocFreeLookup
              • String ID: NONE_MAPPED
              • API String ID: 162735656-2950899194
              • Opcode ID: fc7d76223dfa6cbbf8efa4015a3b0f0cb7eb74909b040ee270e83bc7d35c4934
              • Instruction ID: 0d7aa6959fcc725e49a9c06b1bea6ecd4e36e89ccd4731abd4f5fbf7408ae856
              • Opcode Fuzzy Hash: fc7d76223dfa6cbbf8efa4015a3b0f0cb7eb74909b040ee270e83bc7d35c4934
              • Instruction Fuzzy Hash: 1C519B62A19B8286EF609F02E8402AE63A0FBC5FD4F884936DA5D83794EF3CD544D355
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CountInfoInputLastOpenQueryTickValue_invalid_parameter_noinfo_noreturnwsprintf
              • String ID: %d min$Console$IpDatespecial
              • API String ID: 357503962-2712035571
              • Opcode ID: f28287e08346a151c8f9e7dd536401413db980339d8fbe5e32e9d5c07144a3e5
              • Instruction ID: 5ada80380fda37d1c30f336262545d14df9133c8770d5846de3c0a7e156ecb9b
              • Opcode Fuzzy Hash: f28287e08346a151c8f9e7dd536401413db980339d8fbe5e32e9d5c07144a3e5
              • Instruction Fuzzy Hash: 9A51D032605E8185EF608F28EC443B937A4FB85B99F488131DA5C8BB99EF3DC589D701
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Gdip$Image$BitmapCreateDisposeEncodersFrom$SaveScan0SizeStream
              • String ID: &
              • API String ID: 370471037-3042966939
              • Opcode ID: 4526caf998ada3252c84406b8f766584f007c4df05e28e230d859843c7169577
              • Instruction ID: 9b779ff3738035a9de4adfdb62a561ee63abba392501d1e97a6b8c84db6cf203
              • Opcode Fuzzy Hash: 4526caf998ada3252c84406b8f766584f007c4df05e28e230d859843c7169577
              • Instruction Fuzzy Hash: 3B516F32A08A8286EF119F219C009B863A1FBC5BD8F4C8535DE5D87B94DF3CE946A351
              APIs
              • GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
              • FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
              • FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAB5
              • FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAE2
              • FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAF3
              • FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB04
              • SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value$ErrorLast
              • String ID:
              • API String ID: 2506987500-0
              • Opcode ID: 390d5eb095ce68ec242a92ef1551fbfc0110d75ff9e2c87602c77b0264b82abd
              • Instruction ID: 114d00ecf7c75050e4ae425305f2d178ed19eab8250da7b976feb1bb7b91222b
              • Opcode Fuzzy Hash: 390d5eb095ce68ec242a92ef1551fbfc0110d75ff9e2c87602c77b0264b82abd
              • Instruction Fuzzy Hash: 81214C20F0E64242FE546F259D465396242AFC47F8F184B35DC7E96AC6EE2CB801B603
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: InfoSystem$AddressHandleModuleNativeProc
              • String ID: GetNativeSystemInfo$kernel32.dll
              • API String ID: 3433367815-192647395
              • Opcode ID: 882c301155eb64aee104ed8b19a7cf0e71553aaaeea973eafe02328fb5bce8a2
              • Instruction ID: 382805faddc7aba3c8056985a327359d3e6595b9f7cc423e5315fab82d60cf8e
              • Opcode Fuzzy Hash: 882c301155eb64aee104ed8b19a7cf0e71553aaaeea973eafe02328fb5bce8a2
              • Instruction Fuzzy Hash: 1CF0F615E2AA8283EF61AF10EC002752350FFD8700FC49735E98E82658EF2CE2959611
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Close$OpenQueryValuelstrcmp
              • String ID:
              • API String ID: 4288439342-0
              • Opcode ID: 898e3f92dd09ced9f59f1214a1bb77de0c366a7caab65dc6ea004482ae0e6425
              • Instruction ID: 70db7948d4d659aaeb6455f33d49e848d97f6799b1bfba277f003e4051012189
              • Opcode Fuzzy Hash: 898e3f92dd09ced9f59f1214a1bb77de0c366a7caab65dc6ea004482ae0e6425
              • Instruction Fuzzy Hash: FE318431618B8182EB608F25EC886AA73A4FFD9B90F548631DA5D837E8DF3DD444D741
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo_noreturn$CreateFactory
              • String ID: %s%s %d %d $%s%s %d*%d
              • API String ID: 2331002265-1924168580
              • Opcode ID: 905f7797e8ca330743f3d0d1c8fe144fccdbbcf9989baf0f74f56d9a75f292ec
              • Instruction ID: 42e7c24a1eaf7fa50364fa88b0e65d66e87b1960d0f195d9a10ceec4c879e0f8
              • Opcode Fuzzy Hash: 905f7797e8ca330743f3d0d1c8fe144fccdbbcf9989baf0f74f56d9a75f292ec
              • Instruction Fuzzy Hash: C3A16C32B08B8589EB10CF65D8442EE7761FB89BD8F544622EE9D97B98DF38D481C701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CloseCreateErrorFreeHandleLastLibraryThread_invalid_parameter_noinfo
              • String ID:
              • API String ID: 2067211477-0
              • Opcode ID: bf8243345e757f2f55ee74e3b164a4444cec9f217b6620c703edaf3e446c73ac
              • Instruction ID: bfcd740702408affd95fb42346d53c0b816f7524fd5243d727f1f62c076a2bc2
              • Opcode Fuzzy Hash: bf8243345e757f2f55ee74e3b164a4444cec9f217b6620c703edaf3e446c73ac
              • Instruction Fuzzy Hash: A7218035A09B8285EF14DF66AC011B9A3A0FFC8BD4F184535DE5E93755DF3CE400A602
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ControlCreateDeviceFile
              • String ID: L$\\.\
              • API String ID: 107608037-1891537229
              • Opcode ID: 0cbf31d1c7ae4fdc9b9f59bce1c389b46034841fd4249985a256846f0105b842
              • Instruction ID: 494c79c9d2c2840e99091d931249b5cc63549821e463ccce0beffdbfc600b40b
              • Opcode Fuzzy Hash: 0cbf31d1c7ae4fdc9b9f59bce1c389b46034841fd4249985a256846f0105b842
              • Instruction Fuzzy Hash: 8431B672A0C68581EB018F51B8503B97B90EBD5BE4F084235EBE947BC5DF7CD5059B01
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CurrentThreadsend
              • String ID:
              • API String ID: 302076607-0
              • Opcode ID: 8fc84bb4e0a68a1d65a8e1ac48c208ce2ab72bf0ff2939eb6e9be73f1c549aff
              • Instruction ID: 7f7789a86e4a0568312fe0c2f9aba13d51e4cc12de4dfcc3a53fbf620aec1fb1
              • Opcode Fuzzy Hash: 8fc84bb4e0a68a1d65a8e1ac48c208ce2ab72bf0ff2939eb6e9be73f1c549aff
              • Instruction Fuzzy Hash: 5C518C22A08B8687EB248F25E94436AB7B0FB84BC8F049035DB5987B55EF7CE4529351
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CancelEventclosesocketsetsockopt
              • String ID:
              • API String ID: 852421847-0
              • Opcode ID: 2fb1975f05564cd4b635324778d61c2216334fb941b2a99bb5b0bfd9df8af0fc
              • Instruction ID: 7b4bae3cbe9a674dea8d5fbb81e0bc0cadb86f2c72eed4e2896a0ab4bc147ebe
              • Opcode Fuzzy Hash: 2fb1975f05564cd4b635324778d61c2216334fb941b2a99bb5b0bfd9df8af0fc
              • Instruction Fuzzy Hash: E8F06D32605A8183DB108F25E85432AB330FBC4BA4F544735CBAD476A4CF3DD0658702
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CloseHandlewsprintf
              • String ID: %s_bin
              • API String ID: 3088109604-2665034546
              • Opcode ID: 1cc5837084052d4333c8776d802eed0366a0c4f2efb28125bb70cfdcc1c100eb
              • Instruction ID: 5617388d3e261318d9268445558d80e55a5f7c94cb32370ec1cd5ba93b964b40
              • Opcode Fuzzy Hash: 1cc5837084052d4333c8776d802eed0366a0c4f2efb28125bb70cfdcc1c100eb
              • Instruction Fuzzy Hash: 9F51A962B09AA685EF60DF21C814BA92360EFC5B84F4A8036DA5D87781EF3CD801D312
              APIs
              • VirtualProtect.KERNEL32(?,?,00000000,?,00007FF6297EA9F9,?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA2C4
              • VirtualFree.KERNELBASE(?,?,00000000,?,00007FF6297EA9F9,?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA34E
              • VirtualProtect.KERNEL32(?,?,00000000,?,00007FF6297EA9F9,?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EA3B5
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Virtual$Protect$Free
              • String ID:
              • API String ID: 3866829018-0
              • Opcode ID: 790f28dfba3ce3385ed62d36621e11434fbf0ea754f1c5bfbbc011f1c81681f5
              • Instruction ID: 71bae36a680b682bc5fe7be5ac3dddab7c5268726a8172563ff0b07e559e5958
              • Opcode Fuzzy Hash: 790f28dfba3ce3385ed62d36621e11434fbf0ea754f1c5bfbbc011f1c81681f5
              • Instruction Fuzzy Hash: 8261CEB2B1865186EF28CF5AA840AB967A1FB98BC4F445031DF8E97B44DF3CE850D701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ByteCharMultiWide$ControlDefaultDeviceLangSystemlstrcpy
              • String ID:
              • API String ID: 3058672631-0
              • Opcode ID: 261198a72c51156676862921f16f9480d45e931e86c7b1aea88ce01165389770
              • Instruction ID: 9be63de009065d9cb1391d7f06aa5b4a320941ffa02c60295eb9313a05e9ce48
              • Opcode Fuzzy Hash: 261198a72c51156676862921f16f9480d45e931e86c7b1aea88ce01165389770
              • Instruction Fuzzy Hash: F331C035A0CB8285EF21CF11A8443AAA3A5EBD9BD0F584135FA9DC7B89DF3DD4409B01
              APIs
              • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,0000000180017F3B), ref: 0000000180023829
              • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,0000000180017F3B), ref: 000000018002389B
                • Part of subcall function 0000000180019170: HeapAlloc.KERNEL32(?,?,?,0000000180021D89,?,?,00000000,000000018002397F,?,?,?,0000000180018293,?,?,?,0000000180018189), ref: 00000001800191AE
              • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,0000000180017F3B), ref: 00000001800238FA
                • Part of subcall function 0000000180019134: HeapFree.KERNEL32(?,?,0000000180018293,000000018002602A,?,?,?,00000001800263A7,?,?,00000000,0000000180023D7D,?,?,?,0000000180023CAF), ref: 000000018001914A
                • Part of subcall function 0000000180019134: GetLastError.KERNEL32(?,?,0000000180018293,000000018002602A,?,?,?,00000001800263A7,?,?,00000000,0000000180023D7D,?,?,?,0000000180023CAF), ref: 0000000180019154
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: EnvironmentFreeStrings$Heap$AllocErrorLast
              • String ID:
              • API String ID: 3331406755-0
              • Opcode ID: b2f60d656982d0100eabe4758fe4a58dba44e13eded4e913d1951d74df5580bb
              • Instruction ID: da456c4d4685c92bdc55fa069fa15b697c477944deadc6af73ddf7f7c9b1de89
              • Opcode Fuzzy Hash: b2f60d656982d0100eabe4758fe4a58dba44e13eded4e913d1951d74df5580bb
              • Instruction Fuzzy Hash: 3A31E531604B5981EBA79F2668413DEB7A4F74CFD0F488229FA5A47BC5DF34C6498300
              APIs
                • Part of subcall function 00007FF6297D61E0: InitializeCriticalSectionEx.KERNEL32 ref: 00007FF6297D6231
                • Part of subcall function 00007FF6297D61E0: GetLastError.KERNEL32 ref: 00007FF6297D623B
              • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF6297DC7D4), ref: 00007FF6297DC9DA
              • GdiplusStartup.GDIPLUS ref: 00007FF6297DCA0F
              • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF6297DC7D4), ref: 00007FF6297DCA27
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$EnterErrorGdiplusInitializeLastLeaveStartup
              • String ID:
              • API String ID: 2723390537-0
              • Opcode ID: 65629aaaa719a2e99d15e3f5434e13b9281ffa3b8c64cff51ac5a9778f412de6
              • Instruction ID: 6a939418fbdeca4ea937247bc3aaf68db6d8715a4a56fe38b83ea59f0f0fb458
              • Opcode Fuzzy Hash: 65629aaaa719a2e99d15e3f5434e13b9281ffa3b8c64cff51ac5a9778f412de6
              • Instruction Fuzzy Hash: 08019E32A09B81C7EB408F15E80036AB3E1F7C5B81F481025EA8E83758CF3CD095DB50
              APIs
                • Part of subcall function 00007FF6297FEBE8: GetLastError.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEBF7
                • Part of subcall function 00007FF6297FEBE8: SetLastError.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEC97
              • CloseHandle.KERNEL32(?,?,?,00007FF6297F8A25,?,?,?,?,00007FF6297F8869), ref: 00007FF6297F88B3
              • FreeLibraryAndExitThread.KERNEL32(?,?,?,00007FF6297F8A25,?,?,?,?,00007FF6297F8869), ref: 00007FF6297F88C9
              • ExitThread.KERNEL32 ref: 00007FF6297F88D2
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorExitLastThread$CloseFreeHandleLibrary
              • String ID:
              • API String ID: 1991824761-0
              • Opcode ID: 9d899525cbf94069d0aecb2dad8b7ed7b52f5d6c34f84ba4291cfdf2ce1d2a7a
              • Instruction ID: 729c1399758a5911999040f313576f442f497b6851f67a044778219dca7f8451
              • Opcode Fuzzy Hash: 9d899525cbf94069d0aecb2dad8b7ed7b52f5d6c34f84ba4291cfdf2ce1d2a7a
              • Instruction Fuzzy Hash: 63F06222A19A8691FF145F208C442BD3264AFC0BB8F2C4735DA3D822E4EF3CD845D346
              APIs
              • VirtualFree.KERNELBASE(?,?,00000000,00007FF6297EA8E2,?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EAD00
              • GetProcessHeap.KERNEL32(?,?,00000000,00007FF6297EA8E2,?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EAD45
              • HeapFree.KERNEL32(?,?,00000000,00007FF6297EA8E2,?,?,?,?,?,?,?,?,?,00007FF6297DD242), ref: 00007FF6297EAD53
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: FreeHeap$ProcessVirtual
              • String ID:
              • API String ID: 190046822-0
              • Opcode ID: c7db7b0691119067bd3ad48bc2d9db251511b48ffc2b1eb7c2b1f3e989671234
              • Instruction ID: db08792c01f73604e645fb162825973a15ac69c4a9d59c1c896254ceca41ee04
              • Opcode Fuzzy Hash: c7db7b0691119067bd3ad48bc2d9db251511b48ffc2b1eb7c2b1f3e989671234
              • Instruction Fuzzy Hash: 07315A36B09A4197EB58DF16E9402A96360FB89BC4F488031DF8D93B54CF3DE8A2D701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: SleepTimetime
              • String ID:
              • API String ID: 346578373-0
              • Opcode ID: 2becff6657bc7d5012ec94526cf32972d5272bc21be79492e35a94961d449a59
              • Instruction ID: a11317faa6071ae481c4f52618fd6a1ef3ae155457889509cb5095d7c40bddab
              • Opcode Fuzzy Hash: 2becff6657bc7d5012ec94526cf32972d5272bc21be79492e35a94961d449a59
              • Instruction Fuzzy Hash: 67018C22B1864287EB648F25E98833C26A0FB89B88F445634C75E877D4CF7CD4E5CB12
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorExitLastThread
              • String ID:
              • API String ID: 1611280651-0
              • Opcode ID: 29301a702b889868f08e3e365d098e4f00faa70b4f08071482801bca7c2ace5b
              • Instruction ID: cb5396bb1ecfc759804f614cbef3658d9b306f0408946f9aab80bcc1a6fc7071
              • Opcode Fuzzy Hash: 29301a702b889868f08e3e365d098e4f00faa70b4f08071482801bca7c2ace5b
              • Instruction Fuzzy Hash: F2F09021F1A64286FF14AF708C461BD1260EFD4B98F185834DD0EE32A2DE2CA8419302
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Concurrency::cancel_current_task
              • String ID:
              • API String ID: 118556049-0
              • Opcode ID: a47e5a6ac0625703f2fd5b566550f71a2f7208a7861a0071670bc6a0f9e7358f
              • Instruction ID: 558b52b9266f1843545ff783cf45a85ae933e94a8a7960efa57a14e98f361c4c
              • Opcode Fuzzy Hash: a47e5a6ac0625703f2fd5b566550f71a2f7208a7861a0071670bc6a0f9e7358f
              • Instruction Fuzzy Hash: D3E0B610E1A14745FD297DA61D1A0F800400FE9BF0E2D1B30E9BE842C2AD1CB891B152
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: CreateObjectSingleThreadWait
              • String ID:
              • API String ID: 1891408510-0
              • Opcode ID: 2e196884986127d3ceab2098e342ff93db7a03bb379680bcd1a5a2c8e1daba12
              • Instruction ID: 601e645bba3044fe888c1c35edc14d5e84fcc3ccd5dc67ab8abe609fb7722b73
              • Opcode Fuzzy Hash: 2e196884986127d3ceab2098e342ff93db7a03bb379680bcd1a5a2c8e1daba12
              • Instruction Fuzzy Hash: 5DE01231A40E8886E7E2CB60E8803C57395B39C3A5F61C226E95D827A4DF7C86DE8704
              APIs
              • RtlFreeHeap.NTDLL(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6D2
              • GetLastError.KERNEL32(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6DC
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorFreeHeapLast
              • String ID:
              • API String ID: 485612231-0
              • Opcode ID: a27750d6ae148c980c7c980f65ba2d3e2e52c6c92a9735542c6e0cceef461146
              • Instruction ID: 82296207a74ff78aa45467df9836eacd1ca68aef2636c076a068e5663808f95d
              • Opcode Fuzzy Hash: a27750d6ae148c980c7c980f65ba2d3e2e52c6c92a9735542c6e0cceef461146
              • Instruction Fuzzy Hash: A5E0C210F1AA4782FF186FF26C461782250EFC4788F488834DC1EE3292EE3C68406706
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AllocErrorLastVirtual
              • String ID:
              • API String ID: 497505419-0
              • Opcode ID: 397192a9a5480a2a43f02e5bb4f2c2ae5134a85a5bb06a3bf5a3146684001a4d
              • Instruction ID: b7144ed485e72726273ff16309495eda9b9c5756260ab565cc97fef0d4ea8d8f
              • Opcode Fuzzy Hash: 397192a9a5480a2a43f02e5bb4f2c2ae5134a85a5bb06a3bf5a3146684001a4d
              • Instruction Fuzzy Hash: 17315E32B05A8586DB24CF16E944AADB7A0FB84BC8F048425DF8D87758DE38D441D711
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Virtual$AllocFree
              • String ID:
              • API String ID: 2087232378-0
              • Opcode ID: 616965ea612f33b462fe03c73724eb49c1abe59c321f00a6c33259c6d796c58f
              • Instruction ID: 711941d1a95e7fa4c492efa502b6ed5147d23c17bbc9efabe9cb9cba9e7842c5
              • Opcode Fuzzy Hash: 616965ea612f33b462fe03c73724eb49c1abe59c321f00a6c33259c6d796c58f
              • Instruction Fuzzy Hash: 83217931B18A4186DB64CF2AF84012AB7A1FBC8BC0B148535EB9ED3B54EF3CE4819744
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Virtual$AllocFree
              • String ID:
              • API String ID: 2087232378-0
              • Opcode ID: 0d2589c5e0cc1a94e4b3bf8f4f54a9d1287f00ffced7c8db5b8a82110618710c
              • Instruction ID: e10ff107408fa1a64cfa1121b56b2dc3138a99e23c43d9d5d8181909f13070a9
              • Opcode Fuzzy Hash: 0d2589c5e0cc1a94e4b3bf8f4f54a9d1287f00ffced7c8db5b8a82110618710c
              • Instruction Fuzzy Hash: 2E11E631B29A4182DB098F36A840129A3A5FFD8BC0B188535EA4ED3758EF3CD891DB40
              APIs
                • Part of subcall function 00007FF6297EDC60: __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF6297EDC74
              • __scrt_release_startup_lock.LIBCMT ref: 00007FF6297EE057
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: __scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
              • String ID:
              • API String ID: 2217363868-0
              • Opcode ID: cbc0649b0607904615e0344cdc653858b0dfbbed05089a03dbfd93f3e9e99ab1
              • Instruction ID: c7538881e104367bf9d5664acc1349d90f81bebf403827d1a4f15f2acb56d901
              • Opcode Fuzzy Hash: cbc0649b0607904615e0344cdc653858b0dfbbed05089a03dbfd93f3e9e99ab1
              • Instruction Fuzzy Hash: 64314821E0D24781FE10AF20DC113F92291AFC57C8F984839EA8DDB6D7DE6DA845A603
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Startup
              • String ID:
              • API String ID: 724789610-0
              • Opcode ID: 27a40b9f3cf52b959e37d45274ab80e386b8a2eb9336faf4e796e06ae50c97e7
              • Instruction ID: 85abfcb04a0e7ec63147c048f0c93f3c5ce77a4ca756d325ad7beb3746599bfd
              • Opcode Fuzzy Hash: 27a40b9f3cf52b959e37d45274ab80e386b8a2eb9336faf4e796e06ae50c97e7
              • Instruction Fuzzy Hash: 6FE0DF36B0A585CAEB109F20D8490B43364FB98300F448131E58D83754CE2CD105CF02
              APIs
                • Part of subcall function 00007FF6297EDE98: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6297EDEC8
                • Part of subcall function 00007FF6297EDE98: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6297EDECE
                • Part of subcall function 00007FF6297F87A0: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6297F87C6
              • CloseHandle.KERNEL32 ref: 00007FF6297DEF19
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Concurrency::cancel_current_task$CloseHandle_invalid_parameter_noinfo
              • String ID:
              • API String ID: 1286571413-0
              • Opcode ID: 795a488eb799d89edc104639d8927af7c833b25f0a8359dc5aa5e50726ea34de
              • Instruction ID: 0c09ecb5db1b50839a81061bfeafcfa5ab029dab661e3080cb6cfc978218e6c5
              • Opcode Fuzzy Hash: 795a488eb799d89edc104639d8927af7c833b25f0a8359dc5aa5e50726ea34de
              • Instruction Fuzzy Hash: 2831C972A09B8181EB68DF14EC542EA7765FFC8B84F45403AEA0D8B791CF38E551C312
              APIs
              • HeapAlloc.KERNEL32(?,?,00000000,00007FF6297FEC4A,?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000), ref: 00007FF6298007DD
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AllocHeap
              • String ID:
              • API String ID: 4292702814-0
              • Opcode ID: 5abeb196846a99efc048d9272fb7f243a149b6d2c5d53d359644ea1774af9d54
              • Instruction ID: b7e7fe76cb2e106d53747c2ddcf1f75b2ddce51c8c6a9fdf41da2fd137a87f02
              • Opcode Fuzzy Hash: 5abeb196846a99efc048d9272fb7f243a149b6d2c5d53d359644ea1774af9d54
              • Instruction Fuzzy Hash: 1AF04914B0B64690FF585F669D212B812819FC9B80F0C4834CD0FC62C2ED2DA481E613
              APIs
              • HeapAlloc.KERNEL32(?,?,00000000,000000018001AC2E,?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000), ref: 0000000180019111
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: AllocHeap
              • String ID:
              • API String ID: 4292702814-0
              • Opcode ID: b5ea840a628f107a9da8338485d59c42d040e35b06e100e8d6cbc895d25b2cc2
              • Instruction ID: 2d049a45cd5562e9303f9dec3307b21b18cc0b01f45dbb24d3d7cdf7b57fb27d
              • Opcode Fuzzy Hash: b5ea840a628f107a9da8338485d59c42d040e35b06e100e8d6cbc895d25b2cc2
              • Instruction Fuzzy Hash: 5CF01D74306E0E65FFD757E698563D552955B8CBC0F0CC4316E0A866D6EE1CC6C98320
              APIs
              • HeapAlloc.KERNEL32(?,?,?,00007FF62980252D,?,?,00000000,00007FF6297FA3FB,?,?,?,00007FF6297FC5D3,?,?,?,00007FF6297FC4C9), ref: 00007FF6297FEE0E
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AllocHeap
              • String ID:
              • API String ID: 4292702814-0
              • Opcode ID: c5d91307553507d7a0b65c4578cb45837d9ca66b83f15ba5a6112bdae37f71ee
              • Instruction ID: 502cb2c02b37c9638db69580e4441c185f4e369ebf01c77ec18f25970220f41b
              • Opcode Fuzzy Hash: c5d91307553507d7a0b65c4578cb45837d9ca66b83f15ba5a6112bdae37f71ee
              • Instruction Fuzzy Hash: 69F08C11F0924381FE685F626C4127821809FC4BF8F0C4A34DD2FE72C2DE2CA4907117
              APIs
              • HeapAlloc.KERNEL32(?,?,?,0000000180021D89,?,?,00000000,000000018002397F,?,?,?,0000000180018293,?,?,?,0000000180018189), ref: 00000001800191AE
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: AllocHeap
              • String ID:
              • API String ID: 4292702814-0
              • Opcode ID: b709143ca084da33be42754c1e493520f3745cf4fca273073b856f6a6cafe918
              • Instruction ID: 8b076323ac14c9c74f5c2ceb88a10fe258386b5e316ed7e1eda9353324329690
              • Opcode Fuzzy Hash: b709143ca084da33be42754c1e493520f3745cf4fca273073b856f6a6cafe918
              • Instruction Fuzzy Hash: BEF01C70346E0E65FFE76AE258953E512916B8CBE0F08C6207D27867C6EE28C6898310
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CloseHandle_invalid_parameter_noinfo
              • String ID:
              • API String ID: 1071934762-0
              • Opcode ID: 8f6790a5dd6a9596c7ab298d0e7d2b94e71c72f405498175d4b516057f61ba12
              • Instruction ID: 081a42d906e1f98acc2f62c435d7621739ab7c9d30f26a10c55f319c9527cbe3
              • Opcode Fuzzy Hash: 8f6790a5dd6a9596c7ab298d0e7d2b94e71c72f405498175d4b516057f61ba12
              • Instruction Fuzzy Hash: 2AF08222E0D95141FF259F16AC013A95221AFC8BE4F08443AED4EA7B96DE3CE0975725
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Process$Virtual$AddressLibraryLoadProcProtect$AllocCreateCurrentMemoryOpenThreadTokenWrite$AdjustDirectoryFileLookupModuleNamePrivilegePrivilegesRemoteResumeSleepSystemValue
              • String ID: %s%s$@$ExitProcess$Kernel32.dll$OpenProcess$SeDebugPrivilege$WaitForSingleObject$WinExec$Windows\System32\svchost.exe$h
              • API String ID: 3040193174-4212407401
              • Opcode ID: 0c2d203bb3590072b2790da5483ee898493f9f682a060de060c9115ce93124ea
              • Instruction ID: 9e277898d85528f475cd6237a1f40e6e6be3919ea1a55b2cf95946e7ea53ea1d
              • Opcode Fuzzy Hash: 0c2d203bb3590072b2790da5483ee898493f9f682a060de060c9115ce93124ea
              • Instruction Fuzzy Hash: FFA15D32B19B8285EB218F21EC147E923A4FBC9B98F484535DA4D97B68DF3CD249D701
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: lstrlen$wsprintf$ClipboardFileGlobal$CloseCountTickWindow$CreateDataForegroundHandleLocalLockMutexObjectOpenPointerReleaseSingleSizeSleepStateTextTimeUnlockWaitWrite
              • String ID: [$[$%s%s$%s%s$%s%s$[esc]
              • API String ID: 3669393114-972647286
              • Opcode ID: e6ab48ff98ca9ddfa9a13a1758a8a9b1ffd3d9cd46131382e05cf3f4eced504b
              • Instruction ID: a7adf4e7b460d01facda70827200ab54773fe540d65808ce25a6cd2d67d3c538
              • Opcode Fuzzy Hash: e6ab48ff98ca9ddfa9a13a1758a8a9b1ffd3d9cd46131382e05cf3f4eced504b
              • Instruction Fuzzy Hash: A8D16C22E0964286EF149F55EC442BA33A0FFC5780F484936D94EC2BA5DF3CE548E752
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: lstrlen$CreateEventLocalTimewsprintf
              • String ID: %4d.%2d.%2d-%2d:%2d:%2d$o1:$p1:$t1:
              • API String ID: 2157945651-1225219777
              • Opcode ID: fbc654699d2bcbc3c6c2a15488f06ec7da76675f7aed3d372cc1884bb28a3bff
              • Instruction ID: 771016760adc85e49fd45fa9721de950f9cf2b6fb133fa328309b87547b3fc58
              • Opcode Fuzzy Hash: fbc654699d2bcbc3c6c2a15488f06ec7da76675f7aed3d372cc1884bb28a3bff
              • Instruction Fuzzy Hash: 6AF1DD62A1869286EF209F25EC403BD23A0FFC6BD4F404235DA4E97B95DF7CA581D712
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AddressProc$Library$FileFree$CloseCreateHandleLoadSleepWrite
              • String ID: InternetCloseHandle$InternetOpenUrlW$InternetOpenW$InternetReadFile$MSIE 6.0$wininet.dll
              • API String ID: 2977986460-1099148085
              • Opcode ID: b869be42eea26ef83cf2f127258845e1be2102d2018284c86f6782853b1c64bb
              • Instruction ID: ae16e1fd509da3b87a2588df7fbe89a80205fc9a6a622316fe8b0d9883a2a0e2
              • Opcode Fuzzy Hash: b869be42eea26ef83cf2f127258845e1be2102d2018284c86f6782853b1c64bb
              • Instruction Fuzzy Hash: FF41902660A64286EF609F11ED107BA67A0BFC9BD0F884534DD9E47758EF3CD145DB01
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Lockitstd::_$Clipboard$GlobalLockit::_$Lockit::~_$Close_invalid_parameter_noinfo_noreturn$DataLockOpenUnlock$AllocEmptySetgloballocaleSleeplstrlenstd::locale::_
              • String ID:
              • API String ID: 1851032462-0
              • Opcode ID: 17d443d31020443c81c04e4431b72ce10fdf37fb1d3b70aafa3349b7f0a0e1e5
              • Instruction ID: abdc9c1c87c44bd06c8b2bf906a6a592a7fe4fb813f1630011b1c9a23928b4fe
              • Opcode Fuzzy Hash: 17d443d31020443c81c04e4431b72ce10fdf37fb1d3b70aafa3349b7f0a0e1e5
              • Instruction Fuzzy Hash: 94D19E62B09B8282EF149F65E8052BD63A1FFC4BD4F148635EA9D87B99DE3CE440D701
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ProcessToken$AdjustCloseCurrentErrorHandleLastLookupOpenPrivilegePrivilegesValue$ExitWindows
              • String ID: SeShutdownPrivilege
              • API String ID: 1423298842-3733053543
              • Opcode ID: 207f020c3be7a49f4dae7fd528dd377aaad196edefdcd6a65a6542525f0315a2
              • Instruction ID: 43f3b206a46ea1ca97fd261366bee86f61dfe7bf0dfdeaab2f80840b6e9ee435
              • Opcode Fuzzy Hash: 207f020c3be7a49f4dae7fd528dd377aaad196edefdcd6a65a6542525f0315a2
              • Instruction Fuzzy Hash: AE314F76A09E8281EB208F25EC143AE6360FFC4B56F448435DA4ED3664CF3DD18AD711
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ProcessToken$AdjustCloseCurrentErrorHandleLastLookupOpenPrivilegePrivilegesValue$ExitWindows
              • String ID: SeShutdownPrivilege
              • API String ID: 1423298842-3733053543
              • Opcode ID: eb7aa2d56a82b613c27039d286a92213749df77ba304c44aa2638bc2cb38e150
              • Instruction ID: 5c460799dda6eefa19a52a1ca8c0349174485c22a1435c5949ab0b51eb287293
              • Opcode Fuzzy Hash: eb7aa2d56a82b613c27039d286a92213749df77ba304c44aa2638bc2cb38e150
              • Instruction Fuzzy Hash: FE313076A09E8281EB208F25EC143AE6360FFC4B56F448435DA4ED3668DF3DD19AD711
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ProcessToken$AdjustCloseCurrentErrorHandleLastLookupOpenPrivilegePrivilegesValue$ExitWindows
              • String ID: SeShutdownPrivilege
              • API String ID: 1423298842-3733053543
              • Opcode ID: 2905a319caa5e6a93b8be62912fe952188e187deaf7a97c308075b004fe8cd81
              • Instruction ID: af4aa99bdd03dfc0803bbf0af20588a868a8ac9ce12124c6371091959a3b3d25
              • Opcode Fuzzy Hash: 2905a319caa5e6a93b8be62912fe952188e187deaf7a97c308075b004fe8cd81
              • Instruction Fuzzy Hash: 23313076A09E8281EB208F25EC143AA6360FFC4B56F448435DA4ED3668CF3DD18AD701
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
              • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
              • API String ID: 808467561-2761157908
              • Opcode ID: 622423286a591ad007cfa081ef015de5a4a39bf13039204cb660433145fa8b31
              • Instruction ID: 38cbe17930cf9d3979cedf0cb00dabf186a84a6694ece8b26376da6f717b343d
              • Opcode Fuzzy Hash: 622423286a591ad007cfa081ef015de5a4a39bf13039204cb660433145fa8b31
              • Instruction Fuzzy Hash: EAB2E472F1A2828BEB648E64D8407FD37A1FB94388F485935DA0D97A84DF3DE940DB41
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
              • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
              • API String ID: 808467561-2761157908
              • Opcode ID: b048f9b4f73a4be62ca3b9bf14666876d0c5ef1426e987c813675f3b55613251
              • Instruction ID: 57dd0fdac93f6d9dc7dbc0e89f4f3b56aeeb59b00423ec569deab424ad5bf23b
              • Opcode Fuzzy Hash: b048f9b4f73a4be62ca3b9bf14666876d0c5ef1426e987c813675f3b55613251
              • Instruction Fuzzy Hash: F2B2C173B142988BE7A7CF68D4407ED77A1F3587C8F509125EA0A5BA88DB74DB48CB40
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Create$Event$CountCriticalInitializeSectionSpin$Heap$ProcessTimetime
              • String ID: <$<
              • API String ID: 2446585644-213342407
              • Opcode ID: b57f68b10ee80213c52702a7f8fdc3c9127efbb73382aa70b8132b9072a1b558
              • Instruction ID: 54d62515fc68fb8bd20d50b8a0d5fe722b1a0a3471b78475f62405e61a64ed91
              • Opcode Fuzzy Hash: b57f68b10ee80213c52702a7f8fdc3c9127efbb73382aa70b8132b9072a1b558
              • Instruction Fuzzy Hash: F6B16C72605B818AEB44DF75E8843A933A9FB84B48F58453CCF4C4B799DF38A064D729
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Close$OpenQueryValuelstrcpy
              • String ID: %08X
              • API String ID: 2032971926-3773563069
              • Opcode ID: 5daa38b5fec1510e7cc40f4dc4df9c16a8fb62c5527b438061e7080e78411b39
              • Instruction ID: 28229900660663be6c2384513e9d7dcbf002ad6feb5784c68212006d87c823b4
              • Opcode Fuzzy Hash: 5daa38b5fec1510e7cc40f4dc4df9c16a8fb62c5527b438061e7080e78411b39
              • Instruction Fuzzy Hash: 8D51076260CA8195EB708F25E8442AAB3A0FBC5794F844235DBDD83AA8EF3CD545DB05
              APIs
                • Part of subcall function 00007FF6297FEA70: GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
                • Part of subcall function 00007FF6297FEA70: FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
                • Part of subcall function 00007FF6297FEA70: SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
              • TranslateName.LIBCMT ref: 00007FF629807746
              • TranslateName.LIBCMT ref: 00007FF629807781
              • GetACP.KERNEL32(?,?,?,00000000,00000092,00007FF6297FD4D8), ref: 00007FF6298077C8
              • IsValidCodePage.KERNEL32(?,?,?,00000000,00000092,00007FF6297FD4D8), ref: 00007FF629807800
              • GetLocaleInfoW.KERNEL32 ref: 00007FF6298079BD
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLastNameTranslate$CodeInfoLocalePageValidValue
              • String ID: utf8
              • API String ID: 3069159798-905460609
              • Opcode ID: 37be7df193da29510b7907e0100bbba6fd90f4b6abfc1b920c48fd0307dd32be
              • Instruction ID: c8c0f26fb9d17c778134018660b8ab1b7dcadd4531024a1b7dd9be52a54bcfc2
              • Opcode Fuzzy Hash: 37be7df193da29510b7907e0100bbba6fd90f4b6abfc1b920c48fd0307dd32be
              • Instruction Fuzzy Hash: 7C918B32A0A74285EF249F21DC016B922A4EFC4B80F488935DA5D97796EF3CE951E742
              APIs
                • Part of subcall function 000000018001AA54: GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
                • Part of subcall function 000000018001AA54: FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
                • Part of subcall function 000000018001AA54: SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
              • TranslateName.LIBCMT ref: 000000018002700E
              • TranslateName.LIBCMT ref: 0000000180027049
              • GetACP.KERNEL32(?,?,?,00000000,00000092,000000018001B5D8), ref: 0000000180027090
              • IsValidCodePage.KERNEL32(?,?,?,00000000,00000092,000000018001B5D8), ref: 00000001800270C8
              • GetLocaleInfoW.KERNEL32 ref: 0000000180027285
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLastNameTranslate$CodeInfoLocalePageValidValue
              • String ID: utf8
              • API String ID: 3069159798-905460609
              • Opcode ID: 4ffd2c8f3ef1bc4c4732562623f523084972b696f64dccd1426ec82ada748800
              • Instruction ID: a387079458b9de82b9c7a8ee0bdcb34ac007714a2e822cee88a4d9564f636d0e
              • Opcode Fuzzy Hash: 4ffd2c8f3ef1bc4c4732562623f523084972b696f64dccd1426ec82ada748800
              • Instruction Fuzzy Hash: A891773230078886EBA79B61D5413E963A6EB88BC0F54C126EE5C47796EF39CB5DC341
              APIs
                • Part of subcall function 00007FF6297FEA70: GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
                • Part of subcall function 00007FF6297FEA70: FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
                • Part of subcall function 00007FF6297FEA70: SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
                • Part of subcall function 00007FF6297FEA70: FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAB5
              • GetUserDefaultLCID.KERNEL32(00000000,00000092,?,?), ref: 00007FF629808294
                • Part of subcall function 00007FF6297FEA70: FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAE2
                • Part of subcall function 00007FF6297FEA70: FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAF3
                • Part of subcall function 00007FF6297FEA70: FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB04
              • EnumSystemLocalesW.KERNEL32(00000000,00000092,?,?,00000000,?,?,00007FF6297FD4D1), ref: 00007FF62980827B
              • ProcessCodePage.LIBCMT ref: 00007FF6298082BE
              • IsValidCodePage.KERNEL32 ref: 00007FF6298082D0
              • IsValidLocale.KERNEL32 ref: 00007FF6298082E6
              • GetLocaleInfoW.KERNEL32 ref: 00007FF629808342
              • GetLocaleInfoW.KERNEL32 ref: 00007FF62980835E
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
              • String ID:
              • API String ID: 2591520935-0
              • Opcode ID: 93b063b9324fe15be09d4fe66c93335811eaa82d2ace1cc8264bc73b4ee43e9a
              • Instruction ID: 65c14cdb478fae4d5d1aa65df87d5f86f00e719473fb07a957ebdd264cfce199
              • Opcode Fuzzy Hash: 93b063b9324fe15be09d4fe66c93335811eaa82d2ace1cc8264bc73b4ee43e9a
              • Instruction Fuzzy Hash: DB715922B1AB028AFF519F60DC506B923A0BF84B84F484935CA1D93695EF3DE485E352
              APIs
                • Part of subcall function 000000018001AA54: GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
                • Part of subcall function 000000018001AA54: FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
                • Part of subcall function 000000018001AA54: SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
                • Part of subcall function 000000018001AA54: FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA99
              • GetUserDefaultLCID.KERNEL32(?,00000000,00000092,?), ref: 0000000180027B5C
                • Part of subcall function 000000018001AA54: FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AAC6
                • Part of subcall function 000000018001AA54: FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AAD7
                • Part of subcall function 000000018001AA54: FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AAE8
              • EnumSystemLocalesW.KERNEL32(?,00000000,00000092,?,?,00000000,?,000000018001B5D1), ref: 0000000180027B43
              • ProcessCodePage.LIBCMT ref: 0000000180027B86
              • IsValidCodePage.KERNEL32 ref: 0000000180027B98
              • IsValidLocale.KERNEL32 ref: 0000000180027BAE
              • GetLocaleInfoW.KERNEL32 ref: 0000000180027C0A
              • GetLocaleInfoW.KERNEL32 ref: 0000000180027C26
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
              • String ID:
              • API String ID: 2591520935-0
              • Opcode ID: 5c91a6227937ad05a2b05696b8f827191cd932c76757b85b9e837c6fb46ce494
              • Instruction ID: 8e7cf2e13182192303855a75ab31bf7ded5d87f643afd0cea190ef8e38b898c1
              • Opcode Fuzzy Hash: 5c91a6227937ad05a2b05696b8f827191cd932c76757b85b9e837c6fb46ce494
              • Instruction Fuzzy Hash: 3E7188327006088AFB979B61D8507ED23B6BB4CB84F548026AE1D577D6EF78CA4DC311
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
              • String ID:
              • API String ID: 3140674995-0
              • Opcode ID: 18c7dfee12948f11b2b1ef149d65aa3e1b9c7e2d1ea7ed06afb51cbb3a88d299
              • Instruction ID: 81b9118ab963c12c0df3edd79fed144bfd5b1f5ce17fd97e889fee0ed9231a4e
              • Opcode Fuzzy Hash: 18c7dfee12948f11b2b1ef149d65aa3e1b9c7e2d1ea7ed06afb51cbb3a88d299
              • Instruction Fuzzy Hash: 3F313D72609B8186EB609F60EC403EE7364FB84754F48443ADA8E87B95EF3CD648C715
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
              • String ID:
              • API String ID: 3140674995-0
              • Opcode ID: 5f59febad1cd53dd64ccc9711ed8756e5755807797b4d191df3d8d23b24d07d8
              • Instruction ID: c01d8533b26f4ce1c90f8e8b7de78dcd22b8cb5801f89fecd0ee8157cebbaf04
              • Opcode Fuzzy Hash: 5f59febad1cd53dd64ccc9711ed8756e5755807797b4d191df3d8d23b24d07d8
              • Instruction Fuzzy Hash: 78313072205B8896EBA2DF60E8407ED7364F789784F44802AEB4E47B99DF78C65CC710
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Event$ClearCloseOpen
              • String ID: Application$Security$System
              • API String ID: 1391105993-2169399579
              • Opcode ID: 2cf3709b3cb76df16a2a92579992847c2f846cbe0948eda6c13293e34c808135
              • Instruction ID: 56f8bb15b51094aeca1a0f988efc568024b18ac23f09254889ca42e5b5a1c345
              • Opcode Fuzzy Hash: 2cf3709b3cb76df16a2a92579992847c2f846cbe0948eda6c13293e34c808135
              • Instruction Fuzzy Hash: 45F0F436A0EF4181EE168F19FC40266A3A4FFC97A4F084435C95D83764EF3CD0A6A711
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
              • String ID:
              • API String ID: 1239891234-0
              • Opcode ID: e6fb25ffa18b66ffda036dc74a26e2becfae59b68bb230e1827b5a608bc93c87
              • Instruction ID: 0b460acc62d88813e644b25a67d62403293cd5da380e414e851c2194ac741efb
              • Opcode Fuzzy Hash: e6fb25ffa18b66ffda036dc74a26e2becfae59b68bb230e1827b5a608bc93c87
              • Instruction Fuzzy Hash: 28314B32618B8186DF60CF25EC502AE73A4FBC8798F544536EA9D83B99EF3CD5458B01
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
              • String ID:
              • API String ID: 1239891234-0
              • Opcode ID: 33cd27800031f05acb55e5e13d246fb18deae1c6977fcd484fe98010cd05925a
              • Instruction ID: 6d24a55285349e0a32466ab3cede31ef7ad3e5f641f293ad9a4a16c4e4bf81d4
              • Opcode Fuzzy Hash: 33cd27800031f05acb55e5e13d246fb18deae1c6977fcd484fe98010cd05925a
              • Instruction Fuzzy Hash: DB316D32204F8896EBA2CF25E8413DE73A4F78C794F504126FA9D43B99DF38C6598B00
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: FileFindFirst_invalid_parameter_noinfo
              • String ID:
              • API String ID: 2227656907-0
              • Opcode ID: 116a84698524b3bcd43aaaa4f2cca2c7c536e0f4c45a8280c933762a24cf8a5b
              • Instruction ID: eceb2239a555597516b58e629fea01f06fc1030e2b92dfbe7523371a570c83e5
              • Opcode Fuzzy Hash: 116a84698524b3bcd43aaaa4f2cca2c7c536e0f4c45a8280c933762a24cf8a5b
              • Instruction Fuzzy Hash: 12B1E322B5E69281EF609F35AC002B963A0EFD4BE4F484535EE5D97BC5EE3CE4419302
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo_noreturn
              • String ID: %$+
              • API String ID: 3668304517-2626897407
              • Opcode ID: 401c2c817e2d62c7e15ad231be4f1ea01391d3613e5bd2f1ed5587ee333836ca
              • Instruction ID: 0c72ac5516831097d69609888773abc90fa9e593fe57e52def4325b8c611952b
              • Opcode Fuzzy Hash: 401c2c817e2d62c7e15ad231be4f1ea01391d3613e5bd2f1ed5587ee333836ca
              • Instruction Fuzzy Hash: D412F322714AD889FB67CB66D8423ED7765A7597D8F048211FE4917BC5DF38C689C300
              APIs
              Strings
              • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00007FF6297EC78F
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: DebugDebuggerErrorLastOutputPresentString
              • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
              • API String ID: 389471666-631824599
              • Opcode ID: efbf15865cd5c1087f73e292c5c5f3e8b2dd5a504a7ddbe30f15df4fd023cf7f
              • Instruction ID: d60f073e8dbae69b5dd5e71bdd89ed48bb0ad8d4e68a47e722ba877c23af7970
              • Opcode Fuzzy Hash: efbf15865cd5c1087f73e292c5c5f3e8b2dd5a504a7ddbe30f15df4fd023cf7f
              • Instruction Fuzzy Hash: 65114C32A14B82A7FB059F22EE447B932A4FF84745F488535CA4DC2A91EF7CE064D711
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
              • String ID:
              • API String ID: 2933794660-0
              • Opcode ID: 927d23f7388810727b65f4af3e9c2e8883e14348d687a394dfa295301dddcc79
              • Instruction ID: 7967a0d1a800e18c5bfa54f6fda78da02fc195afd4f09031c61e2bb1e7150352
              • Opcode Fuzzy Hash: 927d23f7388810727b65f4af3e9c2e8883e14348d687a394dfa295301dddcc79
              • Instruction Fuzzy Hash: B3113032710F088AEB41CF60E8543E933A4F35D798F444E26EA6D467A4DF78C6998740
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: memcpy_s
              • String ID:
              • API String ID: 1502251526-0
              • Opcode ID: a3a34dc7f104a5757306e0e4006adbba08ef9a00a3e13a0073f806107d450ba3
              • Instruction ID: bb59f6119dc66d405845deec4cda829af1dca9987cde8d92b0ad11c284a4d332
              • Opcode Fuzzy Hash: a3a34dc7f104a5757306e0e4006adbba08ef9a00a3e13a0073f806107d450ba3
              • Instruction Fuzzy Hash: 71C1C272B1868687EB248F15A54466AB791FBC8BC8F448139DF4E97B44DE3DE801DB40
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: memcpy_s
              • String ID:
              • API String ID: 1502251526-0
              • Opcode ID: 8101bab96facb9530bfb020494a0e1e968264cdbe7156957248635d7c5768935
              • Instruction ID: bf614ab6d02e44b5a5fe724c9a5807cb5da0b99d48dbd710ea59ddea60537a81
              • Opcode Fuzzy Hash: 8101bab96facb9530bfb020494a0e1e968264cdbe7156957248635d7c5768935
              • Instruction Fuzzy Hash: 7EC11972B14A8887D766CF15F4447AAB7A1F388BC4F45C129EB4A43794DF39DA09CB40
              APIs
                • Part of subcall function 00007FF6297FEA70: GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
                • Part of subcall function 00007FF6297FEA70: FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
                • Part of subcall function 00007FF6297FEA70: SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
                • Part of subcall function 00007FF6297FEA70: FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAB5
              • GetLocaleInfoW.KERNEL32 ref: 00007FF629807C0C
                • Part of subcall function 00007FF629803D2C: _invalid_parameter_noinfo.LIBCMT ref: 00007FF629803D49
              • GetLocaleInfoW.KERNEL32 ref: 00007FF629807C55
                • Part of subcall function 00007FF629803D2C: _invalid_parameter_noinfo.LIBCMT ref: 00007FF629803DA2
              • GetLocaleInfoW.KERNEL32 ref: 00007FF629807D1D
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: InfoLocale$ErrorLastValue_invalid_parameter_noinfo
              • String ID:
              • API String ID: 1791019856-0
              • Opcode ID: 4cc450313fabdbeb162ddf05968ccc59476cdba522b4e591624cd7ebb73d4fc8
              • Instruction ID: c0479ce25a813ff94aa45e9dfa76d8afa4bb2ac0f29d3a2eb6581448fdcdadcc
              • Opcode Fuzzy Hash: 4cc450313fabdbeb162ddf05968ccc59476cdba522b4e591624cd7ebb73d4fc8
              • Instruction Fuzzy Hash: 88617E72A0A6428AEF748F21ED802B973A1FBC4744F088536CB9ED7695DE3CE551D702
              APIs
                • Part of subcall function 000000018001AA54: GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
                • Part of subcall function 000000018001AA54: FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
                • Part of subcall function 000000018001AA54: SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
                • Part of subcall function 000000018001AA54: FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA99
              • GetLocaleInfoW.KERNEL32 ref: 00000001800274D4
                • Part of subcall function 0000000180022018: _invalid_parameter_noinfo.LIBCMT ref: 0000000180022035
              • GetLocaleInfoW.KERNEL32 ref: 000000018002751D
                • Part of subcall function 0000000180022018: _invalid_parameter_noinfo.LIBCMT ref: 000000018002208E
              • GetLocaleInfoW.KERNEL32 ref: 00000001800275E5
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: InfoLocale$ErrorLastValue_invalid_parameter_noinfo
              • String ID:
              • API String ID: 1791019856-0
              • Opcode ID: e7c8a4d6f19e2a9cb120b9e5f6357821d79c56e7fe48c26ec1b2605e34c34f74
              • Instruction ID: ea540673a1e875a988def7a9043cec9d425756d79e228d6f43f6c29a4f6e8ebd
              • Opcode Fuzzy Hash: e7c8a4d6f19e2a9cb120b9e5f6357821d79c56e7fe48c26ec1b2605e34c34f74
              • Instruction Fuzzy Hash: 2961AF32300A498AEBB78F15E5853E9B3A2F3987C4F44C125EB9D83696DF78C659C740
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: InfoLocale
              • String ID: GetLocaleInfoEx
              • API String ID: 2299586839-2904428671
              • Opcode ID: 053289818baea42516c59c341b95a57cf593464f2c81e046735848086310e6c4
              • Instruction ID: 1bede23ffda47f87c8193841b2363ab940b6fb08d208abca6ebc2050d25b8da0
              • Opcode Fuzzy Hash: 053289818baea42516c59c341b95a57cf593464f2c81e046735848086310e6c4
              • Instruction Fuzzy Hash: 9801A220B09B8286EF008F56BC405AAA760FFC5BD0F5D8836EE5D83B66CE3CD5419381
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: InfoLocale
              • String ID: GetLocaleInfoEx
              • API String ID: 2299586839-2904428671
              • Opcode ID: 18b4ca0eb88ef80670aff3477e6701f020a0a5759cb10721226424d859e7884e
              • Instruction ID: 156160e26a38140b60a2807731a9a6f05caee1a425b4a41eaf59a8b4e33b94ce
              • Opcode Fuzzy Hash: 18b4ca0eb88ef80670aff3477e6701f020a0a5759cb10721226424d859e7884e
              • Instruction Fuzzy Hash: D401D630304B8886E7869B56B4403CAB360FB8CFD0F98C026FE4913B55CE38CA498340
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionRaise_clrfp
              • String ID:
              • API String ID: 15204871-0
              • Opcode ID: d1d57c0b9bdf7be1867346d5e9c7cf9c26021b93baf768b42c1e913034eff148
              • Instruction ID: 389f0b87e379a781abc7bd4354c5e0d719b98df2d96e4e3d8b0bb77097eca73d
              • Opcode Fuzzy Hash: d1d57c0b9bdf7be1867346d5e9c7cf9c26021b93baf768b42c1e913034eff148
              • Instruction Fuzzy Hash: 65B14A77A19B898BEB15CF29C84636C7BA0F784B48F188922DA5D837A4CF3DD451D701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionRaise_clrfp
              • String ID:
              • API String ID: 15204871-0
              • Opcode ID: 64edc78ecfd727663a2eec849e4f94a3e23609f055b790b63dac00a5eec0822b
              • Instruction ID: 157f6c65db41ecfeecb567327d8779fe537be203eb86134e2953601b35ace97b
              • Opcode Fuzzy Hash: 64edc78ecfd727663a2eec849e4f94a3e23609f055b790b63dac00a5eec0822b
              • Instruction Fuzzy Hash: FDB15C77200B888BEB56CF29C84679C3BE1F388B88F15C915EB5983BA4CB39C556C705
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID: $
              • API String ID: 0-227171996
              • Opcode ID: f4d1caadcdf6a988165dfb6027386ea397a00727bebf28c93510380ffb834353
              • Instruction ID: c2b59749609b74643b3a643b46a51e8c62e5180fd6ec7c19111231d983d95688
              • Opcode Fuzzy Hash: f4d1caadcdf6a988165dfb6027386ea397a00727bebf28c93510380ffb834353
              • Instruction Fuzzy Hash: 37E1D232A1864682EF688E29885013D37A0FFC5BCCF245235DE5EA7794DF39E851E742
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID: e+000$gfff
              • API String ID: 0-3030954782
              • Opcode ID: 7a480f9cb63785b231e93cdb4053ba6ead140b4a31814c2e6dd1f53a1ff5a9d1
              • Instruction ID: 0886cf8349eb524f940676018b78d0907b04f7aebd05000deaa52e793cd83053
              • Opcode Fuzzy Hash: 7a480f9cb63785b231e93cdb4053ba6ead140b4a31814c2e6dd1f53a1ff5a9d1
              • Instruction Fuzzy Hash: B8515667B182C586EB248E359D01769BB91E7C4BD8F488231CFAC9BAD5CE3DE0459702
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID: e+000$gfff
              • API String ID: 0-3030954782
              • Opcode ID: 7839747eeb9cec4fd4c8cce22d1961d615cc2eef855c1dfbf2e657f5c8e8a5df
              • Instruction ID: 4b170b0a227cc471e01380ac096fa8c2442fefdb737c4e13e3d6401bd183a735
              • Opcode Fuzzy Hash: 7839747eeb9cec4fd4c8cce22d1961d615cc2eef855c1dfbf2e657f5c8e8a5df
              • Instruction Fuzzy Hash: 5F516B32718AC846E7A68E75D8017D9BB91F349BD4F48C225EBA447BC5CF39C648C700
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Info
              • String ID:
              • API String ID: 1807457897-0
              • Opcode ID: ef971687b4d926983742e7774fd885bf35e4f0216a13785a2dd56e9bb41dc7e4
              • Instruction ID: e29789b478fb275f1e8c6ad0c81750455828c8fc06a725fca25db7cedaf83b5d
              • Opcode Fuzzy Hash: ef971687b4d926983742e7774fd885bf35e4f0216a13785a2dd56e9bb41dc7e4
              • Instruction Fuzzy Hash: CD12B422908BC586EB55CF3899052FD73A4FB98788F059235EF9D83652EF38E185D701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Info
              • String ID:
              • API String ID: 1807457897-0
              • Opcode ID: 0b8bb1b34a0c2f1e30a2356161536a014fb88af5f51ffa66bb3df95501b28b5c
              • Instruction ID: 3c4fc3300faa48db14865e6a4ff872402a45db70766de693992efec69ed5bd17
              • Opcode Fuzzy Hash: 0b8bb1b34a0c2f1e30a2356161536a014fb88af5f51ffa66bb3df95501b28b5c
              • Instruction Fuzzy Hash: AE128D32A09BC886E792CF3898553ED77A4F75D788F45D215EB9883692EF34D289C700
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 8414e77b36878549f5b0e3bccc639848814f899fad4efa7dd0a1f809894a600d
              • Instruction ID: 2eead6120dde2243a313d5d22804b89ef76d264b873d3b572b93ef2b9c021bce
              • Opcode Fuzzy Hash: 8414e77b36878549f5b0e3bccc639848814f899fad4efa7dd0a1f809894a600d
              • Instruction Fuzzy Hash: 6CE16032A05B8186EB20DF61E8502EE67A4FB94788F444A35DF8E93B56DF7CD245D301
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 6afb9a5e56fd1efeb5a79563753703eec6417f171a818c239c85cc8112bc2bbb
              • Instruction ID: e53b30f7492d9f50eeaa436770ac225c724aeacfd510853a63653c83ee606128
              • Opcode Fuzzy Hash: 6afb9a5e56fd1efeb5a79563753703eec6417f171a818c239c85cc8112bc2bbb
              • Instruction Fuzzy Hash: 60E16136601B8886E762DB61E4403EE77A4F3587C8F418626AF8D53B96EF78C359C340
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID: [RO] %ld bytes
              • API String ID: 0-772938740
              • Opcode ID: 2a2e8e66bac2129e6156a5cab3092c46a0c869edfc0550a0c0319ad8eb13d815
              • Instruction ID: 0859a1fcee40f2c7ea1b0b7c8ce338931986d9a52f73fc0dc0415a6b16c38c0e
              • Opcode Fuzzy Hash: 2a2e8e66bac2129e6156a5cab3092c46a0c869edfc0550a0c0319ad8eb13d815
              • Instruction Fuzzy Hash: 1D42A0336093C5CFC728CF28D84026E7BA1F755B88F448129DB8A87B46DB38E955CB61
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 54882ea8b6c9d5ba74674056cf66cbb49d54c44a5f7a74155c37b7cda10e4cc9
              • Instruction ID: 0a66dcab7d219d87d19b15b5397b2ad04345f92aff25d62f10166f4fe4474c82
              • Opcode Fuzzy Hash: 54882ea8b6c9d5ba74674056cf66cbb49d54c44a5f7a74155c37b7cda10e4cc9
              • Instruction Fuzzy Hash: EC510532700B9495FB629BB2A8443DE7BA1F748BD4F148215FE6827B99CF38C645C700
              APIs
                • Part of subcall function 00007FF6297FEA70: GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
                • Part of subcall function 00007FF6297FEA70: FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
                • Part of subcall function 00007FF6297FEA70: SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
                • Part of subcall function 00007FF6297FEA70: FlsSetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEAB5
              • GetLocaleInfoW.KERNEL32 ref: 00007FF629807E50
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLastValue$InfoLocale
              • String ID:
              • API String ID: 673564084-0
              • Opcode ID: 78331e8626ceae13e165f45be8e9c39df8b73f22d2433a778c66892baaa36d47
              • Instruction ID: da2409e1cb12db418634f6c3c5885c71e84eac094b39c59793aee29fd3de5ec3
              • Opcode Fuzzy Hash: 78331e8626ceae13e165f45be8e9c39df8b73f22d2433a778c66892baaa36d47
              • Instruction Fuzzy Hash: E8318432A0A68686EF64DF21DC413BA77A1FBC4B84F488835DA4DC3696DF3CE8519701
              APIs
                • Part of subcall function 000000018001AA54: GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
                • Part of subcall function 000000018001AA54: FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
                • Part of subcall function 000000018001AA54: SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
                • Part of subcall function 000000018001AA54: FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA99
              • GetLocaleInfoW.KERNEL32 ref: 0000000180027718
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLastValue$InfoLocale
              • String ID:
              • API String ID: 673564084-0
              • Opcode ID: b00c17ae192729a6fdeef141fbd06e0b2bf478bea8696f8ea33d978de4225696
              • Instruction ID: 37a65b734f0adcaeba591b2ef7b6103d3c612fc7c8cf2b624e5b95ac28a75953
              • Opcode Fuzzy Hash: b00c17ae192729a6fdeef141fbd06e0b2bf478bea8696f8ea33d978de4225696
              • Instruction Fuzzy Hash: 9631A53270868986FBA6DB22E5453DA73A2F74C7C4F44D125AA5D83386DF38D658CB40
              APIs
                • Part of subcall function 00007FF6297FEA70: GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
                • Part of subcall function 00007FF6297FEA70: FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
                • Part of subcall function 00007FF6297FEA70: SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
              • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF629808227,00000000,00000092,?,?,00000000,?,?,00007FF6297FD4D1), ref: 00007FF629807AD6
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$EnumLocalesSystemValue
              • String ID:
              • API String ID: 3029459697-0
              • Opcode ID: 38d1bb4dd5fc36fce91c109945422f99630cdbbec874ccb9ac4aa4c93a8a8835
              • Instruction ID: 8c52fda7e706dc25de27ff547d1257b97b178eba7d35c65e8512de8930cd7744
              • Opcode Fuzzy Hash: 38d1bb4dd5fc36fce91c109945422f99630cdbbec874ccb9ac4aa4c93a8a8835
              • Instruction Fuzzy Hash: 6A11DF67A196458AEF148F25D880AA87BA1FB80BE0F488535C62A833C0DE2CD6D1D741
              APIs
                • Part of subcall function 000000018001AA54: GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
                • Part of subcall function 000000018001AA54: FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
                • Part of subcall function 000000018001AA54: SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
              • EnumSystemLocalesW.KERNEL32(?,?,?,0000000180027AEF,?,00000000,00000092,?,?,00000000,?,000000018001B5D1), ref: 000000018002739E
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$EnumLocalesSystemValue
              • String ID:
              • API String ID: 3029459697-0
              • Opcode ID: 5bd2186e112f69379f156c343fff4cde9b4be6d361bec19bdc5c3ffbc2975843
              • Instruction ID: 03a58cb6f3d0a554b078fb62157272aa9ff3625539107b1877c6160ae808668a
              • Opcode Fuzzy Hash: 5bd2186e112f69379f156c343fff4cde9b4be6d361bec19bdc5c3ffbc2975843
              • Instruction Fuzzy Hash: 33119073B046488AEB96CF15D0407ED7BA2F354BE0F449115EA59433D2CA74C7D9D740
              APIs
                • Part of subcall function 00007FF6297FEA70: GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
                • Part of subcall function 00007FF6297FEA70: FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
                • Part of subcall function 00007FF6297FEA70: SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
              • GetLocaleInfoW.KERNEL32(?,?,?,00007FF629807D9A), ref: 00007FF629808027
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$InfoLocaleValue
              • String ID:
              • API String ID: 3796814847-0
              • Opcode ID: 1404621e90844f28406baa3f7135073bb99a8dc7fcfb637c4814ec71fcd74dfb
              • Instruction ID: 9da76272cc8ffc679b4cbb267c908a6509fe86be8fae1a2b7a68d7168c0bf59d
              • Opcode Fuzzy Hash: 1404621e90844f28406baa3f7135073bb99a8dc7fcfb637c4814ec71fcd74dfb
              • Instruction Fuzzy Hash: 44112B32F1955282EB648E25A84067A6291EB907A4F184A31D66EC36C4DE3FD8E19701
              APIs
                • Part of subcall function 000000018001AA54: GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
                • Part of subcall function 000000018001AA54: FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
                • Part of subcall function 000000018001AA54: SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
              • GetLocaleInfoW.KERNEL32(?,?,?,0000000180027662), ref: 00000001800278EF
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$InfoLocaleValue
              • String ID:
              • API String ID: 3796814847-0
              • Opcode ID: 14311e75246232a58eca73cc5d50466e2c6423b61549b768a9208db0531edaf9
              • Instruction ID: 1a085d7b33792e676e52833a6860771bdbee7f9c3905fd9649a454f294247adc
              • Opcode Fuzzy Hash: 14311e75246232a58eca73cc5d50466e2c6423b61549b768a9208db0531edaf9
              • Instruction Fuzzy Hash: BA112C3271075A83E7B78725A0507DE6352E7487E4F94C621FA6E476C6DE25CAC98700
              APIs
                • Part of subcall function 00007FF6297FEA70: GetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA7F
                • Part of subcall function 00007FF6297FEA70: FlsGetValue.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEA94
                • Part of subcall function 00007FF6297FEA70: SetLastError.KERNEL32(?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F,?,?,?,00007FF6297F6443), ref: 00007FF6297FEB1F
              • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF6298081E3,00000000,00000092,?,?,00000000,?,?,00007FF6297FD4D1), ref: 00007FF629807B86
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$EnumLocalesSystemValue
              • String ID:
              • API String ID: 3029459697-0
              • Opcode ID: 8774f767528f023f0cd98180308321dc77e83cd5d8c54262d56985676ea63ca7
              • Instruction ID: ba59d4d68a64ea09ecf6a975ade89bd3885d8a4d23748de308610b51fc147259
              • Opcode Fuzzy Hash: 8774f767528f023f0cd98180308321dc77e83cd5d8c54262d56985676ea63ca7
              • Instruction Fuzzy Hash: 0B01F172F0928186EF104F25EC507B972E2EB80BA4F499632C629832C4DF6C9481E702
              APIs
                • Part of subcall function 000000018001AA54: GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
                • Part of subcall function 000000018001AA54: FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
                • Part of subcall function 000000018001AA54: SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
              • EnumSystemLocalesW.KERNEL32(?,?,?,0000000180027AAB,?,00000000,00000092,?,?,00000000,?,000000018001B5D1), ref: 000000018002744E
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$EnumLocalesSystemValue
              • String ID:
              • API String ID: 3029459697-0
              • Opcode ID: ee3d3c82fdada7cbaed223f853a88881109f67b09674cd2b6671f7bd82dbdc24
              • Instruction ID: 46bef5634a71dda6086a3ddf3ac60f52935d4e8bdf7e60bd74096ca2df7c83b5
              • Opcode Fuzzy Hash: ee3d3c82fdada7cbaed223f853a88881109f67b09674cd2b6671f7bd82dbdc24
              • Instruction Fuzzy Hash: DC012872B0428886E7935F15E4407DD7B92E7547E4F84C321E62D472C6CF748A89C700
              APIs
              • EnumSystemLocalesW.KERNEL32(?,?,00000000,00007FF629800CDF,?,?,?,?,?,?,?,?,00000000,00007FF629807088), ref: 00007FF629800887
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: EnumLocalesSystem
              • String ID:
              • API String ID: 2099609381-0
              • Opcode ID: 0da49028f00012ccddbac4aa6a8129618cfbebd136c027dc8325545b3ece71c8
              • Instruction ID: c69c4ee82d00ba2bd0da2d16992ba393000ef038cba90cd3f232968a84606781
              • Opcode Fuzzy Hash: 0da49028f00012ccddbac4aa6a8129618cfbebd136c027dc8325545b3ece71c8
              • Instruction Fuzzy Hash: 5CF01972A08A8182EB04DF59ECA06A923A2EBD9BC0F588035DA5DD7765DE3CD4909741
              APIs
              • EnumSystemLocalesW.KERNEL32(?,?,00000000,000000018001D717,?,?,?,?,?,?,?,?,00000000,0000000180026950), ref: 000000018001D403
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: EnumLocalesSystem
              • String ID:
              • API String ID: 2099609381-0
              • Opcode ID: fe72f1a3ad6c5a3b9e81fcab1cd3359c69f51c0bc6bac52839abf76237238e4d
              • Instruction ID: 0633ae1dc9c06405525ae1c04c282fdac54c281b7edad598843910c61773c16b
              • Opcode Fuzzy Hash: fe72f1a3ad6c5a3b9e81fcab1cd3359c69f51c0bc6bac52839abf76237238e4d
              • Instruction Fuzzy Hash: 24F08C72304B4882E785CB25F9803D93361F39CBC0F18C126FA09833A5DE3CC6988700
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID: gfffffff
              • API String ID: 0-1523873471
              • Opcode ID: 172941b2f1d4039ba21c6dc8853c143536a16ca8654b5df5f12dde2487208479
              • Instruction ID: b682ec45779f4a389715d5f5a4e88d7e33e30aa30513086e5e03be8623ca75fd
              • Opcode Fuzzy Hash: 172941b2f1d4039ba21c6dc8853c143536a16ca8654b5df5f12dde2487208479
              • Instruction Fuzzy Hash: F5A13663B0878686EF21CF2AA8007BD7795AB94BC8F048132DE8D97791DE3DD505D702
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID: gfffffff
              • API String ID: 0-1523873471
              • Opcode ID: 60c2470d55af355183fd3387e29489bb56ac59a459d69000e798784da7b510f3
              • Instruction ID: d2763f70ebed7c490bb57bf5841f2ff8c3d64a5cec0011bf8ef22a43d63104e5
              • Opcode Fuzzy Hash: 60c2470d55af355183fd3387e29489bb56ac59a459d69000e798784da7b510f3
              • Instruction Fuzzy Hash: 00A13772605BC887EB62CF69A050BDE7B91E759BC4F05C122EE8947785DE3DC60AC701
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID: 0-3916222277
              • Opcode ID: c34624d6eead3179ac2cf2b8b6742605d4d7dbd300549322e291b817085e6e61
              • Instruction ID: d33f30400335aafbfd837b7605d7d396eef3993a962c5e860651cf40f96d80ce
              • Opcode Fuzzy Hash: c34624d6eead3179ac2cf2b8b6742605d4d7dbd300549322e291b817085e6e61
              • Instruction Fuzzy Hash: 3FB18072104F8886EBA68F39C0903AD3BA1F34DF88F258115EB4A47399EF35C669C755
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID: 0-3916222277
              • Opcode ID: 6871d27396c91e0bed272bc22aae0ea20e11987830d478801ef476eeb5b70fb8
              • Instruction ID: c0dcb2d7d3fa426d66ce146109f2ff97501ca087ad8bd09f0b8d148b1a942a5c
              • Opcode Fuzzy Hash: 6871d27396c91e0bed272bc22aae0ea20e11987830d478801ef476eeb5b70fb8
              • Instruction Fuzzy Hash: EEB15D72908A9986EB648F39C85423C3BA0F785F8CF284139CE4EA7395CF39D451E756
              APIs
              • GetLastError.KERNEL32 ref: 00007FF6298027E9
                • Part of subcall function 00007FF629800788: HeapAlloc.KERNEL32(?,?,00000000,00007FF6297FEC4A,?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000), ref: 00007FF6298007DD
                • Part of subcall function 00007FF6297FE6BC: RtlFreeHeap.NTDLL(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6D2
                • Part of subcall function 00007FF6297FE6BC: GetLastError.KERNEL32(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6DC
                • Part of subcall function 00007FF629809FAC: _invalid_parameter_noinfo.LIBCMT ref: 00007FF629809FDF
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorHeapLast$AllocFree_invalid_parameter_noinfo
              • String ID:
              • API String ID: 916656526-0
              • Opcode ID: 2731b98c1a1bd789ef0b97b34515e52132692a4da0e75e7f906c4430b486a5a9
              • Instruction ID: 20c278d954eefd4c05942e3f8e706827181d06c5ece51876feeb79ef25f0d040
              • Opcode Fuzzy Hash: 2731b98c1a1bd789ef0b97b34515e52132692a4da0e75e7f906c4430b486a5a9
              • Instruction Fuzzy Hash: 5641B121F0A64341FF605E266C527BAA6807FD5B80F584935EE8DC7B86EE7CE441A703
              APIs
              • GetLastError.KERNEL32 ref: 0000000180021371
                • Part of subcall function 00000001800190BC: HeapAlloc.KERNEL32(?,?,00000000,000000018001AC2E,?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000), ref: 0000000180019111
                • Part of subcall function 0000000180019134: HeapFree.KERNEL32(?,?,0000000180018293,000000018002602A,?,?,?,00000001800263A7,?,?,00000000,0000000180023D7D,?,?,?,0000000180023CAF), ref: 000000018001914A
                • Part of subcall function 0000000180019134: GetLastError.KERNEL32(?,?,0000000180018293,000000018002602A,?,?,?,00000001800263A7,?,?,00000000,0000000180023D7D,?,?,?,0000000180023CAF), ref: 0000000180019154
                • Part of subcall function 000000018002830C: _invalid_parameter_noinfo.LIBCMT ref: 000000018002833F
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorHeapLast$AllocFree_invalid_parameter_noinfo
              • String ID:
              • API String ID: 916656526-0
              • Opcode ID: a7be9f51bd1662d991b1ebb676dc04fbbddf3e532b420ae9f300a947dfa9964a
              • Instruction ID: 7a3a9990485bbaee88e3e506b751e2240306ee86e9a5f67496d39c90b381273c
              • Opcode Fuzzy Hash: a7be9f51bd1662d991b1ebb676dc04fbbddf3e532b420ae9f300a947dfa9964a
              • Instruction Fuzzy Hash: 8041053130164946FBB3AA6668517EAA381BBADBC1F54C126FE5D47BC5EE3CC7098700
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: HeapProcess
              • String ID:
              • API String ID: 54951025-0
              • Opcode ID: a4c0618735cd60c429b975491587cf71a59f3df0e4ebbbb37a7c6a7071235292
              • Instruction ID: 8e7eb5117c70c52c494ca66bc4d86bff7b5410cce119e7e0ff3f78556e90e3d8
              • Opcode Fuzzy Hash: a4c0618735cd60c429b975491587cf71a59f3df0e4ebbbb37a7c6a7071235292
              • Instruction Fuzzy Hash: FFB09230E03E08C6FA8B2B216CC238423A47B8C781F898019900D80320EF6C17AE5704
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f9d3e26cd520c0d7484bca21c75386a0081201fe8f2cf936fcf25e5b7a4aa551
              • Instruction ID: c6ebdc2a5b29c1efe7e59bb26e4e089097155df29f5760917b3677dc45327c2a
              • Opcode Fuzzy Hash: f9d3e26cd520c0d7484bca21c75386a0081201fe8f2cf936fcf25e5b7a4aa551
              • Instruction Fuzzy Hash: 2A22CEB7F3805047D36DCB1DEC52FA97692B7A4308748A02CBA07C3F45EA3DEA458A44
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 2dbab6f601d912f7832fe87e6cb8010b159b99cec89eaaed4f22644e13967388
              • Instruction ID: 58811309cce860158141c56d4597e401ed2b5bb32e76bcc25f94fb0a2fa7da0e
              • Opcode Fuzzy Hash: 2dbab6f601d912f7832fe87e6cb8010b159b99cec89eaaed4f22644e13967388
              • Instruction Fuzzy Hash: C1C1DD73B1869187DB19CE26E9505B9B792FBD4BE0B55C134DB8A47B88DE3CD841CB00
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 4fe8ec01f60584a1ee149ae2a08fff37cdae008ac808ef4f9df4273de0df04db
              • Instruction ID: 4ca544c8c45fb67e3e572b5ee39f801ec61e10b6ca7f28c36964770d7c6d352f
              • Opcode Fuzzy Hash: 4fe8ec01f60584a1ee149ae2a08fff37cdae008ac808ef4f9df4273de0df04db
              • Instruction Fuzzy Hash: 59D1D122A0864686EF688E298D5027D27A0FFC5BCCF144235CE0DA7795DF3DE845E342
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 1eba3d994d9e09831c82d6d523c03ad57a90d2b8b640b188b3895bc5c2f80ffc
              • Instruction ID: 79d360a61512abb7244fc38979bc17bd08117c1ee5a36e15abcdbef4234416e5
              • Opcode Fuzzy Hash: 1eba3d994d9e09831c82d6d523c03ad57a90d2b8b640b188b3895bc5c2f80ffc
              • Instruction Fuzzy Hash: B9D1C032204E4886EBAA8E29D5903ED37A0F74DBC8F248215EE09476D5EF35CA69C740
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
              • String ID:
              • API String ID: 4023145424-0
              • Opcode ID: 11d17aaadda87904e3cd56c6064876ecdc8233e1ef198966c662d1c74fc6bdf3
              • Instruction ID: da80c38c35addc4f834f47a6226508bef59b08810ad961806ce3aef3a1ad865c
              • Opcode Fuzzy Hash: 11d17aaadda87904e3cd56c6064876ecdc8233e1ef198966c662d1c74fc6bdf3
              • Instruction Fuzzy Hash: 5EC1AD26A0868285EF609F669C107BA26A0FFD47CCF504035DE8DE7699EF3CE545E702
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
              • String ID:
              • API String ID: 4023145424-0
              • Opcode ID: ec77053dc5e10bf16219e11bd631ab886521ce53185d8ffa127bbb562c4fc86c
              • Instruction ID: 0097a73c13b49f266f77b90ad2e19d639f14367bcaa197988bf85d167749bc53
              • Opcode Fuzzy Hash: ec77053dc5e10bf16219e11bd631ab886521ce53185d8ffa127bbb562c4fc86c
              • Instruction Fuzzy Hash: AAC1D636604A8885EBA29B6695503EA77A9F79CBC8F40C015FE49C7BD5DF38C649C700
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$Value_invalid_parameter_noinfo
              • String ID:
              • API String ID: 1500699246-0
              • Opcode ID: ab284c3fdd63390c126f0ea02b30aaf12d109f2597680bdac67f1314cfd3d57d
              • Instruction ID: 00a9fa9ba24cb43c004d2b750ac4ac6d81236614d1f6d9a9fa2e0cf69b89a862
              • Opcode Fuzzy Hash: ab284c3fdd63390c126f0ea02b30aaf12d109f2597680bdac67f1314cfd3d57d
              • Instruction Fuzzy Hash: C2B1C222A1A64682FF649F21DC116B933A1FBD0B88F484935DE5DC36C9DF3CE5519342
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$Value_invalid_parameter_noinfo
              • String ID:
              • API String ID: 1500699246-0
              • Opcode ID: 12a5222bb7eeb9c58d0b9ce8abc9dce7b067e47c6561fe4f7cf386d57eef5764
              • Instruction ID: 759a94b789877c7e8f7aae48417cca113c6d9db3d1b22d9bb577228dbafc9267
              • Opcode Fuzzy Hash: 12a5222bb7eeb9c58d0b9ce8abc9dce7b067e47c6561fe4f7cf386d57eef5764
              • Instruction Fuzzy Hash: A7B1D272A0468C82EBA7EF21D5117EA33A0F798BC9F50C221EE55836D9DF38C659C740
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 4fe3a20954eaf19cca18b720aca6cea66dcaf64d55a17c7986fbc43ae61592d0
              • Instruction ID: 2fa6ef24c8f33aec69b3a591c84fb80e9c2c89b217812fab5b6203a02a3678fe
              • Opcode Fuzzy Hash: 4fe3a20954eaf19cca18b720aca6cea66dcaf64d55a17c7986fbc43ae61592d0
              • Instruction Fuzzy Hash: E2B18E7290868985EF648F29C85427C3BA0FB89F8CF244139CF4EA7399CF29D545E706
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID:
              • API String ID: 3215553584-0
              • Opcode ID: c484f4bf9c85890dca3b74b1c0e4021a385e0861b6d640475f03e576205a2167
              • Instruction ID: 9878fe606e0532eddcdbf31503cdcd8726b23259f096eb6f9ec38fe60172dda8
              • Opcode Fuzzy Hash: c484f4bf9c85890dca3b74b1c0e4021a385e0861b6d640475f03e576205a2167
              • Instruction Fuzzy Hash: B4818F72A04A1186EF68CF65D88137D27A0FB84BD8F148636EE5EE7B99DF38D4419301
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID:
              • API String ID: 3215553584-0
              • Opcode ID: e43fecee6737fd796d23e2183491c0887104ca4f8c5e70360fa4e36a5dc14c65
              • Instruction ID: 8a2268ee84debd9f81d75c99fb4fe9e34b5ce3adf0bc9385ce003d10b90dbb3f
              • Opcode Fuzzy Hash: e43fecee6737fd796d23e2183491c0887104ca4f8c5e70360fa4e36a5dc14c65
              • Instruction Fuzzy Hash: 81818E32201F5886EBA6CE69D4953AD2360F788BE8F548616FE5E9B7D5CF34C249C340
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: aa2f4ae56baf169408e60df2444458542a3c73068db43e6345bf2ec4a63d4b14
              • Instruction ID: dbb4bd7699e544734205ce4bd953353c27c87cc79d46f20fc055fb59ecf8839f
              • Opcode Fuzzy Hash: aa2f4ae56baf169408e60df2444458542a3c73068db43e6345bf2ec4a63d4b14
              • Instruction Fuzzy Hash: C581B372A0C78146EB748F19988036A6691FBCABD8F144239EE9D93B99DF3CD4009B01
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f89918cc19af052acc9bb33a695f17cf2f3b3f9976a30a93db7f0615986ff604
              • Instruction ID: 584f4d44caf3597909211bd92b16433803661f15e7630ee66e3340f50ec0aa33
              • Opcode Fuzzy Hash: f89918cc19af052acc9bb33a695f17cf2f3b3f9976a30a93db7f0615986ff604
              • Instruction Fuzzy Hash: C781D572208B8846E7B6CB59D4803DA7A91F34E7D4F548229FB9E47B95DF3DC6488B00
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f6f6a1a1a1cf9baf0de81f1e4df80e775a01d7d2970379cd065fadcfc056c7f6
              • Instruction ID: 910c297ef46c992858f3c05a583a2b77276b13014d44464f31284237e4e2e936
              • Opcode Fuzzy Hash: f6f6a1a1a1cf9baf0de81f1e4df80e775a01d7d2970379cd065fadcfc056c7f6
              • Instruction Fuzzy Hash: 3661F862B14B8982DF208F19E8416E9A360F7A97D0F545235EBDC87B54EF7DE190D340
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
              • Instruction ID: 9198c874b4c7ee685122d571b4fef67c157513534a1db9a1f511572e4f6a415e
              • Opcode Fuzzy Hash: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
              • Instruction Fuzzy Hash: DF517172A18A5186EB348F29C85423837A1EB84BACF245131DE4DA7795CF3AE847E741
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
              • Instruction ID: 8382e96a8a9ab2a7ac325d6e2b8518ab53cc13d3df6c7bb38c2883323a69e56f
              • Opcode Fuzzy Hash: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
              • Instruction Fuzzy Hash: D8517536A1865686EF348F29C45433833A0EB85BACF284131DE4DA7795DF3AE853D781
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
              • Instruction ID: 5d98a4bb20c577d921db90875bd2eca354ea87ba14b90c810a4c029e80823784
              • Opcode Fuzzy Hash: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
              • Instruction Fuzzy Hash: 57515136A18651C6EB348F29D45423837A1EBC4BACF244131CE4DA7795CF3AE853D781
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f6a3dccb135ddd09f63c505db29ff29986bf9dd63497299e7c799fac6b959aa4
              • Instruction ID: e8865af0cd51ad08a9fd39d9a8d8796932e692f89b6a556a1c89fbd8370ed8b0
              • Opcode Fuzzy Hash: f6a3dccb135ddd09f63c505db29ff29986bf9dd63497299e7c799fac6b959aa4
              • Instruction Fuzzy Hash: 06518176A1865186EF748F29D84423837A0EB88B9CF244131CE4DA7795CF3AF842E781
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: db363646d287334b7a31293e9082935613ba5dde14aee32d187fc7345eaa1eeb
              • Instruction ID: dc9f2b602b353181a9c2fa5185740934e264ad205c5cb0129b59025fa37a0d30
              • Opcode Fuzzy Hash: db363646d287334b7a31293e9082935613ba5dde14aee32d187fc7345eaa1eeb
              • Instruction Fuzzy Hash: 70516136A1865187EF248F29C44823837A1FB95F9CF284131CE4DA7B94DF3AE852D781
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: e46230d8c0bb23a9b26f12389beaf27d8e9063d4bba2e4d98de2a57eaa924be5
              • Instruction ID: ba53b74b282f1f1580b301fb78d670bccbfa8500e6dfdcce67154104ca6f6f88
              • Opcode Fuzzy Hash: e46230d8c0bb23a9b26f12389beaf27d8e9063d4bba2e4d98de2a57eaa924be5
              • Instruction Fuzzy Hash: B0517436A18A51C6EB348F29C94423937A1EBC4F9CF244131CE5DA77A5DF3AE842D741
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: ac8362b94cbf271fd23ce0d6965fdbbec26e6817efc2dd1af2fcdc0b4ee58872
              • Instruction ID: 69ce7fafe062b7bf0daf2475fbe0303e80f6d711cee97aefa02f5902bffd20ae
              • Opcode Fuzzy Hash: ac8362b94cbf271fd23ce0d6965fdbbec26e6817efc2dd1af2fcdc0b4ee58872
              • Instruction Fuzzy Hash: 8C51C336215E988AE7AA8B29C0903EC37A1E74CF99F64C111EE4907794DF36CE57C780
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 45278502b4de115ed76afef2690a2838d0b28876f14c66dd069eb4612fa83dd3
              • Instruction ID: 81cc48cdb92e235dedfe908b42cc4b49bbdeea6af0f3315fd620730d2acf89f4
              • Opcode Fuzzy Hash: 45278502b4de115ed76afef2690a2838d0b28876f14c66dd069eb4612fa83dd3
              • Instruction Fuzzy Hash: 9A519136614E688AE7AA8B29D0403EC37A1E74DFD9F248111EE4957794CF36CA57CB80
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: c9c3f90e6787dc6e65e60abd648d80575bcfa0207306300bab00d1ff848a11e7
              • Instruction ID: 3c68459a076e07c58586976f10bbae96bc5b5fe1d404af2b9a9b0f7ed6a470b1
              • Opcode Fuzzy Hash: c9c3f90e6787dc6e65e60abd648d80575bcfa0207306300bab00d1ff848a11e7
              • Instruction Fuzzy Hash: B451C136610E58CAE7AA8B29C0443E837E0E34DF99F28C115EE8907794DF32CA57C780
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorFreeHeapLast
              • String ID:
              • API String ID: 485612231-0
              • Opcode ID: 4d1d88932efd7b63ecfdde29945dfc17fd218d95b7e0763bafd054a92f058063
              • Instruction ID: ed64e8427f961244881bdbd6bed557fd769d7e56d2afcb20d1cecee979cda566
              • Opcode Fuzzy Hash: 4d1d88932efd7b63ecfdde29945dfc17fd218d95b7e0763bafd054a92f058063
              • Instruction Fuzzy Hash: 0E41D372B18A5582EF08CF2ADD2456973A1BB88FD4B49A036EE4DE7B58DE3CD0419341
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorFreeHeapLast
              • String ID:
              • API String ID: 485612231-0
              • Opcode ID: b40ccf0ec351453c4194ab82b5d213d9bf751758f4c888434c0963d491f70c48
              • Instruction ID: 6ab07859a9aabb5348fb03d35ae4175fdc00118970864eebd12fc2f9ed96f1fe
              • Opcode Fuzzy Hash: b40ccf0ec351453c4194ab82b5d213d9bf751758f4c888434c0963d491f70c48
              • Instruction Fuzzy Hash: 2A41B072310E5881EB89CF6ADA1439A73A1B74CFD0F49D126EE0997B98DE7CC6458700
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: adedd7d71663361c9609fa7dd9b6ae735d4b4198c7f2d5af982c0ea1da244318
              • Instruction ID: bc898212f53204ace61f7196a3a739c9ee7df0496818d6e7f6404db59ca6918f
              • Opcode Fuzzy Hash: adedd7d71663361c9609fa7dd9b6ae735d4b4198c7f2d5af982c0ea1da244318
              • Instruction Fuzzy Hash: D4F0FF71615A988FEBE58F28A8427D977A1F3583C9F908119E689C3A14DA3C85A58F08
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 174bfe62ffdb35f0a8b82215b8c446e4258c47945d5cfe3425f7157a53489505
              • Instruction ID: ba32f0782d6d674e76e796d06706af8cf46536b6b334c70610f694e50cf883b2
              • Opcode Fuzzy Hash: 174bfe62ffdb35f0a8b82215b8c446e4258c47945d5cfe3425f7157a53489505
              • Instruction Fuzzy Hash: ACA0016190980690EB088F00AD590606220FBD0354B468835D15D82060AE2CA940A206
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Event$Message$Reset$CloseCriticalErrorLastPeekSectionThread$CurrentDispatchEnterHandleLeaveMultipleObjectsSwitchTranslateWaitclosesocketsendshutdown
              • String ID:
              • API String ID: 4058177064-0
              • Opcode ID: 1d5cc57fb7fbf7527f04433d1c2939eb4b1b6e6938b0e21f75a258dbfa576023
              • Instruction ID: d6d5a5953ddc9e70982487f84cc85ed7bf7fbdf8c6c4eb75c1d6e16c010ce4f8
              • Opcode Fuzzy Hash: 1d5cc57fb7fbf7527f04433d1c2939eb4b1b6e6938b0e21f75a258dbfa576023
              • Instruction Fuzzy Hash: 5A915036709A8297EB589F25DD446A973A0FB84B80F048535CB6EC3790CF3CE464E712
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: lstrcatlstrlen$CreateEnvironmentExpandProcessStringslstrcpywsprintf
              • String ID: "%1$%s\shell\open\command$WinSta0\Default$h
              • API String ID: 1783372451-551013563
              • Opcode ID: 2aa4d3ebf5c45bd74505c1267e1058c2c24ed9b570e41b1434e0a24903c1c98a
              • Instruction ID: afbe3fee0686451adb9d81f81d17d148af53c277f9faba85130f728cd3c8a80b
              • Opcode Fuzzy Hash: 2aa4d3ebf5c45bd74505c1267e1058c2c24ed9b570e41b1434e0a24903c1c98a
              • Instruction Fuzzy Hash: 85615D22A19B8285FF20DF60DC402EA2361FBC9788F444536DE8D83A99EF3CD245D741
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ByteCharEventMultiWidelstrlensetsockopt$CreateErrorIoctlLastSelectconnectgethostbynamehtonssocket
              • String ID:
              • API String ID: 1455939504-0
              • Opcode ID: 4f9acce4ae6ad80aec03b8b5c09d7b116e02fc5318df3eeeff928d226ee1ccda
              • Instruction ID: 35f201a8cfc89c168e7cf210db9f1e8bc3667b118c69c7b8b8cbf3aebc7dd6c2
              • Opcode Fuzzy Hash: 4f9acce4ae6ad80aec03b8b5c09d7b116e02fc5318df3eeeff928d226ee1ccda
              • Instruction Fuzzy Hash: FE515032608B9186EB24CF21E84426A77A5FBC4BE4F144635EE9E83B98CF3CD545D702
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
              • String ID:
              • API String ID: 2081738530-0
              • Opcode ID: 86a4ff4925cbc545ad5961b211c5cb2ede80d6a6447645a52bcc9b3ede11fd42
              • Instruction ID: 574857fad1be8cc8346f4dc9acfc1b584ed0742ff69dc4f6daa1cd5696006c1b
              • Opcode Fuzzy Hash: 86a4ff4925cbc545ad5961b211c5cb2ede80d6a6447645a52bcc9b3ede11fd42
              • Instruction Fuzzy Hash: ED517C26E08A4285EE19DF15EC451B963A1FFC4BE4F580532DA9D83BA5DF3CE442E702
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$EventTimetime$EnumEventsNetworkResetSelectsend
              • String ID:
              • API String ID: 957247320-3916222277
              • Opcode ID: 70faab5df619376ecbd789658116d1a95d03484d4b81b7d6c2cb32eb3eab3399
              • Instruction ID: 9a7902c3911c7359738b438df7a9170f41cc4e1ca986237245f0c8f1fad75738
              • Opcode Fuzzy Hash: 70faab5df619376ecbd789658116d1a95d03484d4b81b7d6c2cb32eb3eab3399
              • Instruction Fuzzy Hash: E3715C72A086828BEB688F29D98436977E0FB84B98F148034CB4DC37D5CF7DE5459B52
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$EnterErrorLastLeave
              • String ID:
              • API String ID: 4082018349-0
              • Opcode ID: ce0fa88aebe3efe6d4cfa5056a018ff2338e1d011f624170396f62e2d62db8ee
              • Instruction ID: dccbd790811450dcec3cc4a7ebbffe1a7ec3aae5d74d12f8eb64488ebe7a24c9
              • Opcode Fuzzy Hash: ce0fa88aebe3efe6d4cfa5056a018ff2338e1d011f624170396f62e2d62db8ee
              • Instruction Fuzzy Hash: 21616932B09A4283EB689F26D94467A6365FBC4B81F848031CA1EC7798DF3CE455E712
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$EnterErrorLastLeave
              • String ID:
              • API String ID: 4082018349-0
              • Opcode ID: b12bcef403b9db2977f705d0ecef41abbd2038a6eeb512479f31e0cb207d576e
              • Instruction ID: fdaab8271d9cecc66c7a75ebf6db4b9c8ee1192eb2ee7a49a7b2deab2b2a2d24
              • Opcode Fuzzy Hash: b12bcef403b9db2977f705d0ecef41abbd2038a6eeb512479f31e0cb207d576e
              • Instruction Fuzzy Hash: 0C319C21B0DA8283EF589F269C882796261FFC5BC5F180035DE1EC6795CF2DE446E722
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Concurrency::cancel_current_taskstd::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
              • String ID: bad locale name$false$true
              • API String ID: 4121308752-1062449267
              • Opcode ID: 4d9a4bae47b79d40b7256d161a918d9ce49b1ce80b4b4b053ce15fe2b77d6c61
              • Instruction ID: 25289e7db44cb1a63330db8de0233808b059fb69907730fe826677cda66cee09
              • Opcode Fuzzy Hash: 4d9a4bae47b79d40b7256d161a918d9ce49b1ce80b4b4b053ce15fe2b77d6c61
              • Instruction Fuzzy Hash: FC517732706B448AFB97DFB0D4513EC33B6AB48788F048118AE4927B96DF34C61AD345
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CloseValue$CreateDeleteOpenlstrlen
              • String ID: Software$VenNetwork
              • API String ID: 3197061591-1820303132
              • Opcode ID: 977d34d6a8543d540e474d7a41a606a027e4303f67bb5f64f5b8d5885a1a35b1
              • Instruction ID: 02e4f9903be5de988c12bbdd41cd8228a3d84a7be6ccad6fc246637a4df5aad2
              • Opcode Fuzzy Hash: 977d34d6a8543d540e474d7a41a606a027e4303f67bb5f64f5b8d5885a1a35b1
              • Instruction Fuzzy Hash: 2A214F36608A8086EB109F22EC4425AB761FBC9FE1F488531DE5D83B68DF7CD15ADB05
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalErrorLastSection$EnterLeave
              • String ID:
              • API String ID: 2124651672-0
              • Opcode ID: ceb90cee31cb5c63e12923c504f4f75aed37da3cde6871e563f60f2bd9e0bfed
              • Instruction ID: 43738d2bc146257c4906fc4b73d6a71b689b9e3825ded2970953cca841a74be2
              • Opcode Fuzzy Hash: ceb90cee31cb5c63e12923c504f4f75aed37da3cde6871e563f60f2bd9e0bfed
              • Instruction Fuzzy Hash: 4D51ED32A096428BEB649F15E84067C77A5FB88B84F068139DE4EC7395DF3CE805D742
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: f$f$p$p$f
              • API String ID: 3215553584-1325933183
              • Opcode ID: 338c2a64cdc3021812c5b6ddca5db7159329e9a17ba8d876efc02d9e71b2fbd5
              • Instruction ID: f0b38dc0eb32edfae566383fea31a6a0b2d4ec7961a2eae2e34d6dc764c077c2
              • Opcode Fuzzy Hash: 338c2a64cdc3021812c5b6ddca5db7159329e9a17ba8d876efc02d9e71b2fbd5
              • Instruction Fuzzy Hash: 3B128322A1C18387FF249F15D8587B97661FBC07D8F944135EA8DA66C8DF3CE480AB16
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$setsockopt$CreateEventResetTimerWaitable
              • String ID:
              • API String ID: 2911610646-0
              • Opcode ID: 29f4db180f811eed727e115f3e9634c508b58a893b040440cf1ba2de9885e7b9
              • Instruction ID: 9271b68582ce5a6c9917f29d46abf0229e5768c1e569558bab32fd18bb387c76
              • Opcode Fuzzy Hash: 29f4db180f811eed727e115f3e9634c508b58a893b040440cf1ba2de9885e7b9
              • Instruction Fuzzy Hash: BC519C32A09B8287EB188F25E90436D73A0FB88784F044135DB8D87B90DF7DE066DB12
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$Leave$ErrorLastTimetime$EnterEvent
              • String ID:
              • API String ID: 3019579578-0
              • Opcode ID: 0f5c7540d6a6d13954bf3b0610fbdb20e4227d3d9c7ae04a05d2493569245aae
              • Instruction ID: 462641a1bae066b4542203373c4f41a4c7623d1c3bc3cc85fb8e8dc7d83cdf3a
              • Opcode Fuzzy Hash: 0f5c7540d6a6d13954bf3b0610fbdb20e4227d3d9c7ae04a05d2493569245aae
              • Instruction Fuzzy Hash: 97414E3291864287EB709F15D84423E7361FBC4B84F184535DA4E87B98DF3CF881A752
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$EnterErrorLastLeave
              • String ID:
              • API String ID: 4082018349-0
              • Opcode ID: 67fb679d431cd07a0a75245ad9faae6b58536de87acf8e54a525854fe2ab2b98
              • Instruction ID: 28d9f8c0500b1d4a2fd44954f698dd8573ce83fa2074447bad4e5c8a86c5396f
              • Opcode Fuzzy Hash: 67fb679d431cd07a0a75245ad9faae6b58536de87acf8e54a525854fe2ab2b98
              • Instruction Fuzzy Hash: 89314F32A19A8287EB909F25DC4427D33A4FF84B89F484431DA4ECA798DF3CD455E712
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
              • String ID: csm$csm$csm
              • API String ID: 849930591-393685449
              • Opcode ID: 2b2ef099c7c498c1f83d83cf8365c45f4a2add1e44776cae4b3bb5ec5925f551
              • Instruction ID: da388d4115c2ac4ba019b861e8d737f6d571f78e453cd237c340db872f9aaab1
              • Opcode Fuzzy Hash: 2b2ef099c7c498c1f83d83cf8365c45f4a2add1e44776cae4b3bb5ec5925f551
              • Instruction Fuzzy Hash: F7D16C22A087818AEF209F65D8403AD77A0FB957DCF100135EE8DA7B99DF38E195D742
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
              • String ID: csm$csm$csm
              • API String ID: 849930591-393685449
              • Opcode ID: 3a718ee7f8b6373924fa1ef36f33fea09a8afd655926d26086879ab94a1df2a9
              • Instruction ID: 11f02f1a1b6f2119d6ab1984a83f1249e0a72176be5e98c1a38744feb3c8c25a
              • Opcode Fuzzy Hash: 3a718ee7f8b6373924fa1ef36f33fea09a8afd655926d26086879ab94a1df2a9
              • Instruction Fuzzy Hash: D3D18C32604B888AEBA2DB65D4403DD77A0F75A7D8F108116FE8967B96DF34C299C701
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AddressFreeLibraryProc
              • String ID: api-ms-$ext-ms-
              • API String ID: 3013587201-537541572
              • Opcode ID: 7440c042807cac739352953deb803b73dd017de38a4217708bea05fa604c5186
              • Instruction ID: 95b7bec04ea13a58abb880cd373e1b921f289c6b06711ab661d193e60a98ef65
              • Opcode Fuzzy Hash: 7440c042807cac739352953deb803b73dd017de38a4217708bea05fa604c5186
              • Instruction Fuzzy Hash: 44419F21B1AA0285FF25CF16ED106BA2291BF85BA0F4D5A36DD0DD7794EE3CE445E302
              APIs
              • FreeLibrary.KERNEL32(?,?,?,000000018001DB38,?,?,?,?,0000000180013C41,?,?,?,?,0000000180007340), ref: 000000018001D5AC
              • GetProcAddress.KERNEL32(?,?,?,000000018001DB38,?,?,?,?,0000000180013C41,?,?,?,?,0000000180007340), ref: 000000018001D5B8
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: AddressFreeLibraryProc
              • String ID: api-ms-$ext-ms-
              • API String ID: 3013587201-537541572
              • Opcode ID: 9ca9f382646b4c989892281ad302a63fa07b97429ac017ba95ecba264538f1cf
              • Instruction ID: d8fc979b45583009b6d8f450d37dd7f080959f75dab4b2bcac9e25a23a010083
              • Opcode Fuzzy Hash: 9ca9f382646b4c989892281ad302a63fa07b97429ac017ba95ecba264538f1cf
              • Instruction Fuzzy Hash: 8D41E031311E0C92FB97CB16A9007DA2392B74DBE8F59C526AD1A87784EF78CA498704
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Filelstrcatlstrlenwsprintf$CloseCreateEnvironmentExpandHandleStringsWritelstrcpy
              • String ID: %s %s
              • API String ID: 958574092-2939940506
              • Opcode ID: eceb82c3cd3af4ca55499d5fe9bd5fadc0488819e054981a88d383308b1fa06d
              • Instruction ID: 0d3cc53db14dda891c1ca2adf7b9b9b5a5c7eb3effd3ff223f81829c5442ed41
              • Opcode Fuzzy Hash: eceb82c3cd3af4ca55499d5fe9bd5fadc0488819e054981a88d383308b1fa06d
              • Instruction Fuzzy Hash: ED413122A18FC681EB118F28D9043FD2320FBD5B88F55A325DB4D56656EF39E2D9D700
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
              • String ID:
              • API String ID: 190073905-0
              • Opcode ID: aab2033705f31d13bb710668e14191793ff1325bb45cecf30cfdf4bf87d378c1
              • Instruction ID: b1da23782529deac30f099c77194b92e1a7a79ade0d699db9422c502c86d5b2b
              • Opcode Fuzzy Hash: aab2033705f31d13bb710668e14191793ff1325bb45cecf30cfdf4bf87d378c1
              • Instruction Fuzzy Hash: F081AF30A0064D86FAD3EB6599813D93390AB8DBC4F54C015FA48977A2DE78CB4DCF00
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$EnterLeave$ErrorLastsend
              • String ID:
              • API String ID: 3480985631-0
              • Opcode ID: dcbfb0b2159904ea6d1c624c1834ef820b2325ccb56d393d0a5f1f6bb36a758c
              • Instruction ID: c642d65c2065bb28f655640600f98d946f7a31c24fe2071c8c2ba0574be85075
              • Opcode Fuzzy Hash: dcbfb0b2159904ea6d1c624c1834ef820b2325ccb56d393d0a5f1f6bb36a758c
              • Instruction Fuzzy Hash: 23414F36608B8182EB588F26E9442AC73B4FB88FC8F184535CE1D87B98DF38E555D761
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: f$p$p
              • API String ID: 3215553584-1995029353
              • Opcode ID: 42fb3e65d0f17d18353857ebdda260012259b146ac6ef5ada1715a4ca3ec7708
              • Instruction ID: 849ba80fc81c24bf1d6388740d27c5fe0727f3bc770b011e83112f7bc71e0ffd
              • Opcode Fuzzy Hash: 42fb3e65d0f17d18353857ebdda260012259b146ac6ef5ada1715a4ca3ec7708
              • Instruction Fuzzy Hash: E712AF22E0C14386FF249E15D8546BA7291FBC07D8F844036EE9AA76C4DF3DE584EB06
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID: f$p$p
              • API String ID: 3215553584-1995029353
              • Opcode ID: 730ec7c73464c0e22b00d9c6858c7d82ef3e1cdb4796676c72299090f6d48783
              • Instruction ID: 3e8c0ddebcf4747a76db19149277b4397ccf20279b0311ded7689cd40d5d188f
              • Opcode Fuzzy Hash: 730ec7c73464c0e22b00d9c6858c7d82ef3e1cdb4796676c72299090f6d48783
              • Instruction Fuzzy Hash: 7A12E872608A4986FBA65B15E0543F977A2FB887D0FD8C015F681476C8DF38C788EB15
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo
              • String ID:
              • API String ID: 3215553584-0
              • Opcode ID: 4088889be9819d41049a200a371a193d1a84681165ce87351eeee8399076b0a0
              • Instruction ID: 802ba34d1dba4c25a49d8928ede781a8ac287e4d5c7289e3b922aad4f9f43e26
              • Opcode Fuzzy Hash: 4088889be9819d41049a200a371a193d1a84681165ce87351eeee8399076b0a0
              • Instruction Fuzzy Hash: BFC1F532208B8D92E7E39B1594453EE7BA5F799BC0F658112FA4903393DFB9CA5D8700
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$ErrorLast$EnterLeave$CurrentThread$EventsMultipleTimerWaitWaitablesend
              • String ID:
              • API String ID: 2807917265-0
              • Opcode ID: 495490e7d3477735b75ad2edb0a11b0efccf73ea01b4538bcbeaf1220e2ab4c3
              • Instruction ID: f9a2916d2585a29fccabbe5094da2b2956a4db549eca48bf4f40c57e2d88760e
              • Opcode Fuzzy Hash: 495490e7d3477735b75ad2edb0a11b0efccf73ea01b4538bcbeaf1220e2ab4c3
              • Instruction Fuzzy Hash: D0514F71A0974286EF688F25DC4427923A4FB84B98F584635DE6EC77D8DF3CE440A722
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$GetctypeGetwctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
              • String ID: bad locale name
              • API String ID: 1386471777-1405518554
              • Opcode ID: 1e5e98c9536fad76aa215f10c33411828afcd6fe37bfa1046ea3f08e32c02a87
              • Instruction ID: 6f12afbecdbc6c8c4723a80e89689fdb05e51c173adb192a56656790785e7b5a
              • Opcode Fuzzy Hash: 1e5e98c9536fad76aa215f10c33411828afcd6fe37bfa1046ea3f08e32c02a87
              • Instruction Fuzzy Hash: 97514A22B09B818AFF15DFB0D8502BC2374EF94788F444139DE8DA6A5ADF38E556A311
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$GetctypeGetwctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
              • String ID: bad locale name
              • API String ID: 1386471777-1405518554
              • Opcode ID: 6b7ba6e8446f5de1a585bb9ac0d148b9ac44657668e99689077215057fe3328f
              • Instruction ID: 205fddb4c06c6aec178ab2adc66388c5105195ae8e8825034b4c358a251d3f20
              • Opcode Fuzzy Hash: 6b7ba6e8446f5de1a585bb9ac0d148b9ac44657668e99689077215057fe3328f
              • Instruction Fuzzy Hash: 53515A32B05B888AFB56DFB4D4513EC3375EB58B88F448115EF4926A96DF34C65AD300
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$GetcollLocinfo::_Locinfo_ctorLockit::_Lockit::~__invalid_parameter_noinfo_noreturn
              • String ID: bad locale name
              • API String ID: 3908275632-1405518554
              • Opcode ID: 9950391e219e3f38a391214971ba9392170c4fde7a5665b9737b79cfa968d01f
              • Instruction ID: 626a839d935aebb9807f0151c52938d44564025511633b86417f1046ba59aadc
              • Opcode Fuzzy Hash: 9950391e219e3f38a391214971ba9392170c4fde7a5665b9737b79cfa968d01f
              • Instruction Fuzzy Hash: 86515D22B09B8189FF14DFB0D8513EC33A5AF84B88F444135EE8DA7A99DF389546E301
              APIs
              • LoadLibraryExW.KERNEL32(?,?,?,00007FF6297F37DE,?,?,?,00007FF6297F34D0,?,?,?,00007FF6297F0109), ref: 00007FF6297F35B1
              • GetLastError.KERNEL32(?,?,?,00007FF6297F37DE,?,?,?,00007FF6297F34D0,?,?,?,00007FF6297F0109), ref: 00007FF6297F35BF
              • LoadLibraryExW.KERNEL32(?,?,?,00007FF6297F37DE,?,?,?,00007FF6297F34D0,?,?,?,00007FF6297F0109), ref: 00007FF6297F35E9
              • FreeLibrary.KERNEL32(?,?,?,00007FF6297F37DE,?,?,?,00007FF6297F34D0,?,?,?,00007FF6297F0109), ref: 00007FF6297F3657
              • GetProcAddress.KERNEL32(?,?,?,00007FF6297F37DE,?,?,?,00007FF6297F34D0,?,?,?,00007FF6297F0109), ref: 00007FF6297F3663
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Library$Load$AddressErrorFreeLastProc
              • String ID: api-ms-
              • API String ID: 2559590344-2084034818
              • Opcode ID: 79f1708f0d73a3895a2fe6d32fc30880b345232a89ca131bb8ab1f3b75cbd6b1
              • Instruction ID: a5d5fd9e9cf71cbeb4d52d23cb9dc688ee14259160678f4a8746fa217a374e7b
              • Opcode Fuzzy Hash: 79f1708f0d73a3895a2fe6d32fc30880b345232a89ca131bb8ab1f3b75cbd6b1
              • Instruction Fuzzy Hash: 1531CF21B1AA42D1EE25AF16AC005792394FFC8BE8F594536DD2DDB390EF3CE441A312
              APIs
              • LoadLibraryExW.KERNEL32(?,?,?,0000000180010E6B,?,?,?,000000018000DA44,?,?,?,?,000000018000D7E1), ref: 0000000180010D31
              • GetLastError.KERNEL32(?,?,?,0000000180010E6B,?,?,?,000000018000DA44,?,?,?,?,000000018000D7E1), ref: 0000000180010D3F
              • LoadLibraryExW.KERNEL32(?,?,?,0000000180010E6B,?,?,?,000000018000DA44,?,?,?,?,000000018000D7E1), ref: 0000000180010D69
              • FreeLibrary.KERNEL32(?,?,?,0000000180010E6B,?,?,?,000000018000DA44,?,?,?,?,000000018000D7E1), ref: 0000000180010DD7
              • GetProcAddress.KERNEL32(?,?,?,0000000180010E6B,?,?,?,000000018000DA44,?,?,?,?,000000018000D7E1), ref: 0000000180010DE3
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Library$Load$AddressErrorFreeLastProc
              • String ID: api-ms-
              • API String ID: 2559590344-2084034818
              • Opcode ID: b09260a3b01b944e8a2ed352862a161e4ae98297871aeffd10098e1da1c3218e
              • Instruction ID: 6059c775b58af9673e93cb4f47e6f265eade308a4566bf057f510aae578ddb5e
              • Opcode Fuzzy Hash: b09260a3b01b944e8a2ed352862a161e4ae98297871aeffd10098e1da1c3218e
              • Instruction Fuzzy Hash: AE317E31212A4891FF93DB52A8007D533A4BB4CBE4F698525FE5947791EF78EA488300
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AttributesCreateErrorFileLastProcesslstrlen
              • String ID: WinSta0\Default$h
              • API String ID: 591566999-1620045033
              • Opcode ID: d2bab96cac4579f2c125ad1b394deb36b09c5d0372b7e3e75e386909ded7df42
              • Instruction ID: 1450cc19e274a78287a0c8757674557db9ff97d3f0b1a979ab46315b75bd617c
              • Opcode Fuzzy Hash: d2bab96cac4579f2c125ad1b394deb36b09c5d0372b7e3e75e386909ded7df42
              • Instruction Fuzzy Hash: 89316022E0D7C286EA608F25B9043BA6391FBD5790F045334EA9DC3B99EF2CE0949701
              APIs
              • GetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA63
              • FlsGetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA78
              • FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AA99
              • FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AAC6
              • FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AAD7
              • FlsSetValue.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AAE8
              • SetLastError.KERNEL32(?,?,?,0000000180016A8B,?,?,?,?,?,?,?,?,0000000180012466,?,?,?), ref: 000000018001AB03
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value$ErrorLast
              • String ID:
              • API String ID: 2506987500-0
              • Opcode ID: dbe77e66a7de49c6c9d3389502a61dbaa8101452699f92e69e049ceb59fb1c45
              • Instruction ID: 852cd9b20ebb93d6b7160b2014394db60870bae99b69435688c1eb5ffecd53cd
              • Opcode Fuzzy Hash: dbe77e66a7de49c6c9d3389502a61dbaa8101452699f92e69e049ceb59fb1c45
              • Instruction Fuzzy Hash: 29218134309A8C42FBDB637156463EA63966F8E7F0F44C715B93647AD6EF2886498301
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
              • String ID: CONOUT$
              • API String ID: 3230265001-3130406586
              • Opcode ID: c477bea2d07ef44c7e07df60decfd2619db83e7f0bc9226f08f6201d8069434b
              • Instruction ID: b9465909f93fbd94f0743acf662104d2fc5dc1aab1ed4cb7c9908387826e6dea
              • Opcode Fuzzy Hash: c477bea2d07ef44c7e07df60decfd2619db83e7f0bc9226f08f6201d8069434b
              • Instruction Fuzzy Hash: 63115E21A18B8186EB508F52EC54329A6A0FBC8FE4F594634EE5DC7BA4DF3CE8448741
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
              • String ID: CONOUT$
              • API String ID: 3230265001-3130406586
              • Opcode ID: 9a53dcf6b77aac4c641e8ca98971444a7ff2d0fa0d3f05d6ca1a50c7c06adfb9
              • Instruction ID: 554ccba47afcc93753359f4ddd31f1bcf11d1e9c05f01a0ab4e96358f6f9a8b8
              • Opcode Fuzzy Hash: 9a53dcf6b77aac4c641e8ca98971444a7ff2d0fa0d3f05d6ca1a50c7c06adfb9
              • Instruction Fuzzy Hash: BE118231724A8886E7D38B52E854359A3A0F78DFE4F148225FE5D877A4CF78CA498744
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: File$CloseCreateHandleMutexObjectPointerReleaseSingleWaitWritelstrlen
              • String ID:
              • API String ID: 4202892810-0
              • Opcode ID: 6d311e261bfe59e5949d3104aa2c883e73ffb96b44e413d4cc9c1204dacd56c9
              • Instruction ID: f2e3c8f8a04287ec608874a681af627e122746002cc76e70fd3169a28c7a491e
              • Opcode Fuzzy Hash: 6d311e261bfe59e5949d3104aa2c883e73ffb96b44e413d4cc9c1204dacd56c9
              • Instruction Fuzzy Hash: 47112175A08A4282FB109F11FD187657760FBC8BA4F588631DA5E43BA4CF7CD4499B05
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value$CloseDeleteOpen
              • String ID: Console$IpDatespecial
              • API String ID: 3183427449-1840232981
              • Opcode ID: f23957102dd5c337703c86b23f0909451c31f6d4053b1f337106711f9d04a52f
              • Instruction ID: a8b64fa2a20a05ffce74330380e974be99a1a4ee8e336144df254517704719e8
              • Opcode Fuzzy Hash: f23957102dd5c337703c86b23f0909451c31f6d4053b1f337106711f9d04a52f
              • Instruction Fuzzy Hash: F7015E36609AC186EB218F14EC107693760FBC5B59F488136CA5D83B58DF3CD199DB05
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Process$CommandCreateExitFileInfoLineModuleNameStartup
              • String ID:
              • API String ID: 3421218197-3916222277
              • Opcode ID: 190dd20226834de6593c2658ef490eeec5e65b5d977b517c4b94419b13326a92
              • Instruction ID: 4968b1871ba277bdfe5806ea7afa40a663fe0fea13ad6e356bb72be91edf55cb
              • Opcode Fuzzy Hash: 190dd20226834de6593c2658ef490eeec5e65b5d977b517c4b94419b13326a92
              • Instruction Fuzzy Hash: 79F03132619A8286DB608F24F84875EB3A0FBC8754F544635E68E87A64DF3CD145CB00
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ByteCharMultiStringWide
              • String ID:
              • API String ID: 2829165498-0
              • Opcode ID: 7971f062b65952515ec8212ac2e9a2c677d9c1fc3ecd3cd2358e8a062519809b
              • Instruction ID: 1f9fede53b954f8e5b43acc8c264839122ab766aaf11d3bb555b3b9be0801e50
              • Opcode Fuzzy Hash: 7971f062b65952515ec8212ac2e9a2c677d9c1fc3ecd3cd2358e8a062519809b
              • Instruction Fuzzy Hash: A481D77220074886EBA2CF15E44079D73D5FB4CBE4F548615FA5987BD5DF78C6498B00
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
              • String ID:
              • API String ID: 2081738530-0
              • Opcode ID: 120c1b7971d057f7d32ed189108cba4dc3bdaf4a53a91de180e5530db79fdb05
              • Instruction ID: 9bfdac23812655959e59ee9134ab68fe0fce2feb2ecedce451b1980171af903a
              • Opcode Fuzzy Hash: 120c1b7971d057f7d32ed189108cba4dc3bdaf4a53a91de180e5530db79fdb05
              • Instruction Fuzzy Hash: 1B416A36244B4881EA96DF26E4403EA77A0F788BD5F499522EE8D037A6DF38C649C700
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
              • String ID:
              • API String ID: 2081738530-0
              • Opcode ID: 7a4aba34b9ee0e7feb97e831a1f23563437c19ccbf85e67e868202ffd3c1e259
              • Instruction ID: 6e9778c85ceeebd191738d212a2141fb86d17769249ac1cf2784b10380d351a3
              • Opcode Fuzzy Hash: 7a4aba34b9ee0e7feb97e831a1f23563437c19ccbf85e67e868202ffd3c1e259
              • Instruction Fuzzy Hash: AC416B36640B8885EAA6DF26E5403E973A1F788BD4F489522EE4E077B5DF38C649C300
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
              • String ID:
              • API String ID: 2081738530-0
              • Opcode ID: 0a459d356615af1532279fea11b62472358ce995c90851a97120222909910ee1
              • Instruction ID: 921b1d8f41fd75cbe69ba934d7afaa04baeb3bfee234873a740bcb75f00e34e4
              • Opcode Fuzzy Hash: 0a459d356615af1532279fea11b62472358ce995c90851a97120222909910ee1
              • Instruction Fuzzy Hash: 9F31AE32242A4C81EA97DF95E5407E97361E788BE0F188122FE5D077A6DF78C60AC300
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLast$recv
              • String ID:
              • API String ID: 316788870-0
              • Opcode ID: 4d768c99772465553fa61935876ff201d4a32ce5a3f2b2de379ff66690b2a509
              • Instruction ID: 4a24e90cb70efb57f86e83306491009c33ae994541f1bee5ff0d0648edb4c7ec
              • Opcode Fuzzy Hash: 4d768c99772465553fa61935876ff201d4a32ce5a3f2b2de379ff66690b2a509
              • Instruction Fuzzy Hash: ED314132A1864282FF648F2AE88537D27A1FBC5B88F544535CA4DC63D8DF3DD844A712
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
              • String ID:
              • API String ID: 2081738530-0
              • Opcode ID: 01c04fa9871c3a39ffcf0a934f0e415b4afe528a6c6d455696e5ee859d00c823
              • Instruction ID: 17143bbf385a982bdb54c7383b9f9f07d2b43b60ea543350829077e0f004077e
              • Opcode Fuzzy Hash: 01c04fa9871c3a39ffcf0a934f0e415b4afe528a6c6d455696e5ee859d00c823
              • Instruction Fuzzy Hash: 28317032604A4895EA97DF15E8403E97362F79C7E4F4C8221FE4A473A6EF38C64AC300
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
              • String ID:
              • API String ID: 2081738530-0
              • Opcode ID: 4c84763795ff46bb11d74f9b0c05f5ef24f69a033a1c856c3f921719e211355b
              • Instruction ID: 188fe48b5b8d51294082f477e532e1cd5573214a1d4b025d7eb095671354e5f8
              • Opcode Fuzzy Hash: 4c84763795ff46bb11d74f9b0c05f5ef24f69a033a1c856c3f921719e211355b
              • Instruction Fuzzy Hash: EB317232601A4885FA97DB55D4403EA7361F798BD5F48D121FE59572A6EF38C64AC300
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
              • String ID: csm$csm$csm
              • API String ID: 3523768491-393685449
              • Opcode ID: 89a7cbb458af1ec799ed0823309e47d85c371afd6e512bd69dcc86c67ccd7e4c
              • Instruction ID: 593eff48ad15b6b49ab0b45c4fa8ba456fcbf2c42617504bc49abe841df2c596
              • Opcode Fuzzy Hash: 89a7cbb458af1ec799ed0823309e47d85c371afd6e512bd69dcc86c67ccd7e4c
              • Instruction Fuzzy Hash: 43E1B172A086828AEF60DF64D8402BD77A0FB9578CF100135DE8DA7B96DF38E585D742
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
              • String ID: csm$csm$csm
              • API String ID: 3523768491-393685449
              • Opcode ID: 52fd8afce82c30d52040a3feb8681f15f7a184bd3fac23872912cd14114af7cf
              • Instruction ID: 8cd4f6dfc1cbc8e28258d450a9c7c49759c218ec614c58e15a5991c5420c4a6a
              • Opcode Fuzzy Hash: 52fd8afce82c30d52040a3feb8681f15f7a184bd3fac23872912cd14114af7cf
              • Instruction Fuzzy Hash: 40E19D33604AC88AE7A2DF74D4803ED7BA0F74A798F148126FA9957796DF34C689C700
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: EventReset$Thread$CurrentErrorLastObjectSingleSwitchTimeWait_invalid_parameter_noinfotime
              • String ID:
              • API String ID: 2235205178-0
              • Opcode ID: 6797ce520ad4e8d809bfec53c9e8342f43c56bbc6854028e75bb9cf567634471
              • Instruction ID: 9c602ce3abf147759e50565a600919ddff9992367fa40080a3f45b1d80796e19
              • Opcode Fuzzy Hash: 6797ce520ad4e8d809bfec53c9e8342f43c56bbc6854028e75bb9cf567634471
              • Instruction Fuzzy Hash: 48212A32A08A8186EB50CF26EC442A973A4FF88F98F188531DE5DD7768CF3CD5859761
              APIs
              • GetLastError.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEBF7
              • FlsSetValue.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEC2D
              • FlsSetValue.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEC5A
              • FlsSetValue.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEC6B
              • FlsSetValue.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEC7C
              • SetLastError.KERNEL32(?,?,000026134426113E,00007FF6297F8B05,?,?,?,?,00007FF629802546,?,?,00000000,00007FF6297FA3FB,?,?,?), ref: 00007FF6297FEC97
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value$ErrorLast
              • String ID:
              • API String ID: 2506987500-0
              • Opcode ID: ae6f202f78a3fef56879520fe118d2f33bae8a9cde3df911dcd1aef05bcedbfe
              • Instruction ID: a98ebd735a8f5e52b87e9c906a5877ef38575e7d57bc267a0180db2e4ef8892a
              • Opcode Fuzzy Hash: ae6f202f78a3fef56879520fe118d2f33bae8a9cde3df911dcd1aef05bcedbfe
              • Instruction Fuzzy Hash: 73112C20E0E68282FF546F259E5513962425FC47F8F584B35EC6ED66D6DE2CB801B202
              APIs
              • GetLastError.KERNEL32(?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000,000000018002397F,?,?,?), ref: 000000018001ABDB
              • FlsSetValue.KERNEL32(?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000,000000018002397F,?,?,?), ref: 000000018001AC11
              • FlsSetValue.KERNEL32(?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000,000000018002397F,?,?,?), ref: 000000018001AC3E
              • FlsSetValue.KERNEL32(?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000,000000018002397F,?,?,?), ref: 000000018001AC4F
              • FlsSetValue.KERNEL32(?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000,000000018002397F,?,?,?), ref: 000000018001AC60
              • SetLastError.KERNEL32(?,?,000037B719E332F5,0000000180013B69,?,?,?,?,0000000180021DA2,?,?,00000000,000000018002397F,?,?,?), ref: 000000018001AC7B
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value$ErrorLast
              • String ID:
              • API String ID: 2506987500-0
              • Opcode ID: 29a142ae4fc881daeb50b9aa613c13a0e560aed2600cb0c3b1d23bed98e67ab8
              • Instruction ID: 6336c9d8f692e95d9c5df55ebe11836466add78df9332ca103cf2cef11a9400d
              • Opcode Fuzzy Hash: 29a142ae4fc881daeb50b9aa613c13a0e560aed2600cb0c3b1d23bed98e67ab8
              • Instruction Fuzzy Hash: DD11BE34309A4C82FBDBA37596553EA22929B8E7F0F00C725B93A477D6EF2886494740
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$GetctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
              • String ID: bad locale name
              • API String ID: 2967684691-1405518554
              • Opcode ID: 64695b106198e755eff40ccbe4da75bf0a5c8355beaa60347c6da880a5ccc215
              • Instruction ID: 457f4921bcab4821e7849c5fbe6ac6fb891d93ee2024ee1270cc27e04b4c7c73
              • Opcode Fuzzy Hash: 64695b106198e755eff40ccbe4da75bf0a5c8355beaa60347c6da880a5ccc215
              • Instruction Fuzzy Hash: 6D416D32706B84C9FB96DFB0D4913EC3365EB58B88F448415EE4926A9ADF34C61AD344
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AddressFreeHandleLibraryModuleProc
              • String ID: CorExitProcess$mscoree.dll
              • API String ID: 4061214504-1276376045
              • Opcode ID: 4e200ac4912f663bf200d97a0492af6b570e41165da9f834e6f0b0fe5145a0ad
              • Instruction ID: c9539bdbe1e0af41db58c38bc29884689a4c60464496cbe7552e4c5931c0243a
              • Opcode Fuzzy Hash: 4e200ac4912f663bf200d97a0492af6b570e41165da9f834e6f0b0fe5145a0ad
              • Instruction Fuzzy Hash: 9EF09C61B1AA0281EF108F24EC547796320FFC97A5F584739C96D865F4CF2DD045E301
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: AddressFreeHandleLibraryModuleProc
              • String ID: CorExitProcess$mscoree.dll
              • API String ID: 4061214504-1276376045
              • Opcode ID: 48794384edd42f76f01b31abd9b3a34649d66c0a4991f16342a82150d828e30c
              • Instruction ID: c7981282e32efebeccc1285cf22a27b487855ed529e36011a4ef044e0089154f
              • Opcode Fuzzy Hash: 48794384edd42f76f01b31abd9b3a34649d66c0a4991f16342a82150d828e30c
              • Instruction Fuzzy Hash: 49F09671315B4C91FB938B24E4843E95370FB4D7E1F548216E669455E4CF6CC64CC340
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CloseDeleteOpenValue
              • String ID: Console$IpDatespecial
              • API String ID: 849931509-1840232981
              • Opcode ID: 6e7d2c7a670a32b5de56c4a84771261a6cdbf4bc2880aa7204407435697e958c
              • Instruction ID: d0f135d333ed34cdb3a80c26b7af543e8f834325804b47843e23b7057cda21c2
              • Opcode Fuzzy Hash: 6e7d2c7a670a32b5de56c4a84771261a6cdbf4bc2880aa7204407435697e958c
              • Instruction Fuzzy Hash: 0DF06D36608DC185EB208F18EC107A93320EBC476AF044131CD1D93B68DF3CD1DA9B00
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: AdjustPointer
              • String ID:
              • API String ID: 1740715915-0
              • Opcode ID: f957c6767cf5b81622e8ff6fae34e0b794288dc4cc0809d74a0a7b197e878a35
              • Instruction ID: 29e735cccd4f84951349abf238d6aff62fe317cb202f1ac11ebacade39afa949
              • Opcode Fuzzy Hash: f957c6767cf5b81622e8ff6fae34e0b794288dc4cc0809d74a0a7b197e878a35
              • Instruction Fuzzy Hash: C8B1F222E0AB42C1FE65DF159D406796390EFE4BC8F088435DE8DA7B95DE3CE441A742
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: AdjustPointer
              • String ID:
              • API String ID: 1740715915-0
              • Opcode ID: ebc393b52b48cc04e5c9b1c97f52e56d944419017ee65fad25771533bcdc82d9
              • Instruction ID: eb3b7977ae8f9180934a4530bb566c5a25c1755e12ee0d79c43d3515dd016e81
              • Opcode Fuzzy Hash: ebc393b52b48cc04e5c9b1c97f52e56d944419017ee65fad25771533bcdc82d9
              • Instruction Fuzzy Hash: D9B1B232202A8C82FAE7DB15D5407E97794AB5CBC4F19C427BE490B789DF74C68AC360
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task__std_exception_copy__std_exception_destroy
              • String ID:
              • API String ID: 1087005451-0
              • Opcode ID: 983f63db59c9861a35ee25389b91e130b78b440a4239188d788a671ee2a4fa99
              • Instruction ID: 7d43b0d82526ce2b3402540fb6dd75848486498bac8023869180411ce6b44045
              • Opcode Fuzzy Hash: 983f63db59c9861a35ee25389b91e130b78b440a4239188d788a671ee2a4fa99
              • Instruction Fuzzy Hash: EF81AF32B15B98C9FB52CBA4D8403DC7371A7597E8F109316EE6C26B96EF749689C300
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _set_statfp
              • String ID:
              • API String ID: 1156100317-0
              • Opcode ID: f4dd79240b51b0c21704e83aaa589ed4fa802d8d7f161a743a50b312269a4b72
              • Instruction ID: 6f0f603976d273e0bc5ee1cbab8870c9e96500b15387b1fad05b17080fc10dd3
              • Opcode Fuzzy Hash: f4dd79240b51b0c21704e83aaa589ed4fa802d8d7f161a743a50b312269a4b72
              • Instruction Fuzzy Hash: 8381B232114E8C49F3B38B35A451BEB6760AF9D7D8F04C305FD5A265A4DF34CA89874A
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _set_statfp
              • String ID:
              • API String ID: 1156100317-0
              • Opcode ID: 3a9c703ea5aaac55ee3dcba71a43574e980d604707a0521e319b1fc91c9c8b59
              • Instruction ID: 4d9009d8388b1806cf22da908af1d726b1d6aea3e21d47e98268cbd2eee6fa2b
              • Opcode Fuzzy Hash: 3a9c703ea5aaac55ee3dcba71a43574e980d604707a0521e319b1fc91c9c8b59
              • Instruction Fuzzy Hash: 42119A22E0EA0202FFA41D6CEC5237900416FD4364E1D0E35EB7FC62DAAF1CAC456206
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: _set_statfp
              • String ID:
              • API String ID: 1156100317-0
              • Opcode ID: e65ba792651367d839098e214d5891407b2dde01c0b567b7a4e043ebbfca8b6f
              • Instruction ID: 30e523d46bf6013ddc2793ce494e8919f7ebf68a2be9d27671f3a3569b69be40
              • Opcode Fuzzy Hash: e65ba792651367d839098e214d5891407b2dde01c0b567b7a4e043ebbfca8b6f
              • Instruction Fuzzy Hash: 6411A332A18F0D03F7E72165E55A3E652416BDE3F0F08C625B976062D78F9CCB488301
              APIs
              • FlsGetValue.KERNEL32(?,?,?,00007FF6297F39FB,?,?,00000000,00007FF6297F3C96,?,?,?,?,?,00007FF6297F3C22), ref: 00007FF6297FECCF
              • FlsSetValue.KERNEL32(?,?,?,00007FF6297F39FB,?,?,00000000,00007FF6297F3C96,?,?,?,?,?,00007FF6297F3C22), ref: 00007FF6297FECEE
              • FlsSetValue.KERNEL32(?,?,?,00007FF6297F39FB,?,?,00000000,00007FF6297F3C96,?,?,?,?,?,00007FF6297F3C22), ref: 00007FF6297FED16
              • FlsSetValue.KERNEL32(?,?,?,00007FF6297F39FB,?,?,00000000,00007FF6297F3C96,?,?,?,?,?,00007FF6297F3C22), ref: 00007FF6297FED27
              • FlsSetValue.KERNEL32(?,?,?,00007FF6297F39FB,?,?,00000000,00007FF6297F3C96,?,?,?,?,?,00007FF6297F3C22), ref: 00007FF6297FED38
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value
              • String ID:
              • API String ID: 3702945584-0
              • Opcode ID: 86bd21252e8a794773a6d9a19f3f969acd0493724c29e180940389d540fd6514
              • Instruction ID: 16bc470df03d3bb1439f8fe2008d4615524f3ef6ceef2e63c98157b4908e8243
              • Opcode Fuzzy Hash: 86bd21252e8a794773a6d9a19f3f969acd0493724c29e180940389d540fd6514
              • Instruction Fuzzy Hash: A3111F10E0E64241FF585F25AD5117962416FC47F4F584B35EC7D96AD5DE2CF801B603
              APIs
              • FlsGetValue.KERNEL32(?,?,?,00000001800136B7,?,?,00000000,0000000180013952,?,?,?,?,?,00000001800138DE), ref: 000000018001ACB3
              • FlsSetValue.KERNEL32(?,?,?,00000001800136B7,?,?,00000000,0000000180013952,?,?,?,?,?,00000001800138DE), ref: 000000018001ACD2
              • FlsSetValue.KERNEL32(?,?,?,00000001800136B7,?,?,00000000,0000000180013952,?,?,?,?,?,00000001800138DE), ref: 000000018001ACFA
              • FlsSetValue.KERNEL32(?,?,?,00000001800136B7,?,?,00000000,0000000180013952,?,?,?,?,?,00000001800138DE), ref: 000000018001AD0B
              • FlsSetValue.KERNEL32(?,?,?,00000001800136B7,?,?,00000000,0000000180013952,?,?,?,?,?,00000001800138DE), ref: 000000018001AD1C
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value
              • String ID:
              • API String ID: 3702945584-0
              • Opcode ID: 8cce4c5f0e70d6ca29b97c32849cd69abf9369bf703c258e938afac22d0a3fb6
              • Instruction ID: 914c458ab6939188e9ccdfceb6abdbeee0fcfecafaff658cabf852f1a111cb68
              • Opcode Fuzzy Hash: 8cce4c5f0e70d6ca29b97c32849cd69abf9369bf703c258e938afac22d0a3fb6
              • Instruction Fuzzy Hash: 5A118630309E4C41FBDB633566413EA22566F8E7F0F44D725B93A46BD6EE28C7494301
              APIs
              • FlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F), ref: 00007FF6297FEB55
              • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F), ref: 00007FF6297FEB74
              • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F), ref: 00007FF6297FEB9C
              • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F), ref: 00007FF6297FEBAD
              • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF629806E73,?,?,?,00007FF6297FF1A4,?,?,?,00007FF6297F819F), ref: 00007FF6297FEBBE
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value
              • String ID:
              • API String ID: 3702945584-0
              • Opcode ID: 40b480678b9e6ae03057fc20160df1cacf0cc2b8c5d9a605f457dfc538dbbb21
              • Instruction ID: 0aaa24ac0983e4ceec15ef9662407e0f71e486cf1a0fab1fbf67c9fe5e47bc59
              • Opcode Fuzzy Hash: 40b480678b9e6ae03057fc20160df1cacf0cc2b8c5d9a605f457dfc538dbbb21
              • Instruction Fuzzy Hash: 03110C50E0E64742FE986F255C11A7922425FC53B8F580F39ED3EEA6C2ED2CB841B213
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Value
              • String ID:
              • API String ID: 3702945584-0
              • Opcode ID: 0b6fabc1bf916e6fe8f7c00df96862480aef0449f5eee41e3fa08a1f5a2bb8cc
              • Instruction ID: a5c9708106037e6e2b64533c798d2982eec532633ece3afbdf1fdeffa0088a54
              • Opcode Fuzzy Hash: 0b6fabc1bf916e6fe8f7c00df96862480aef0449f5eee41e3fa08a1f5a2bb8cc
              • Instruction Fuzzy Hash: 5A115B3020DA8D42FBEBA37548967EA12475B8E7F0F18CB2579364A2D3EF2C97494300
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$EnterLeave
              • String ID:
              • API String ID: 3168844106-0
              • Opcode ID: ec8515e0b6118a22be018e0c36bf8043355ac570717b599eb6440d7a0495df03
              • Instruction ID: d061d15f5dfd88e3428c8af66797456c5c2e8aa6351da48576f0db0b3be6bdf0
              • Opcode Fuzzy Hash: ec8515e0b6118a22be018e0c36bf8043355ac570717b599eb6440d7a0495df03
              • Instruction Fuzzy Hash: 3B11F132625941C3EF909F26F8943AA6360FB84759F485431DB8F82A55CF3CE486D701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$Enter$DeleteGdiplusLeaveObjectShutdown
              • String ID:
              • API String ID: 1513102227-0
              • Opcode ID: cdd56314798a8dc9bb9b375cd871b4762f9b413abb23fcd634828e7dcd198d12
              • Instruction ID: a22751f7a37490299cafe8ada58241cad68ff005f0ba35d981cac4d83149e871
              • Opcode Fuzzy Hash: cdd56314798a8dc9bb9b375cd871b4762f9b413abb23fcd634828e7dcd198d12
              • Instruction Fuzzy Hash: 14112832506B52C1EF108F29E84006973B4FB88FA8B288636DA5D867A4DF3DD953D381
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CloseHandleObjectSingleThreadWait$CurrentErrorLastSleepSwitch
              • String ID:
              • API String ID: 1535946027-0
              • Opcode ID: 6bee8a0a4dea1eafbbaf25a2cc800b23e58b43f259c7b6e2f946ecae76c8c5a2
              • Instruction ID: ec2d20cc81a53a0507fb93430a4b8e6144af2bf0cf324dd87459a879f30dd0a1
              • Opcode Fuzzy Hash: 6bee8a0a4dea1eafbbaf25a2cc800b23e58b43f259c7b6e2f946ecae76c8c5a2
              • Instruction Fuzzy Hash: C1F09736A09E4586EB049F26EC541783321EBC9F65F588630DE2E873A4CF3CD886D361
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CallEncodePointerTranslator
              • String ID: MOC$RCC
              • API String ID: 3544855599-2084237596
              • Opcode ID: a53d2363c14758023286afc4a6ab41b9c25c1dd74b553e4400a7d45858c9584b
              • Instruction ID: 2b3de1982482fee92ab8f24a271b879fab510b9f7843fdb508eebe4c85833017
              • Opcode Fuzzy Hash: a53d2363c14758023286afc4a6ab41b9c25c1dd74b553e4400a7d45858c9584b
              • Instruction Fuzzy Hash: 7B919E73A08B818AEB10DF64D8402AD7BA0FB857C8F14413AEE8DA7B55DF38D195DB01
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: CallEncodePointerTranslator
              • String ID: MOC$RCC
              • API String ID: 3544855599-2084237596
              • Opcode ID: 4bd709b9b59f72ec3c139efe9d7ce1a27f3884a3c59f33a9b2d37d482ef38b49
              • Instruction ID: 0108a547061a6338346a1fd8d7bfab91135ecffd3b7bd265e3fcb74934dd1a34
              • Opcode Fuzzy Hash: 4bd709b9b59f72ec3c139efe9d7ce1a27f3884a3c59f33a9b2d37d482ef38b49
              • Instruction Fuzzy Hash: A9917173604B888AE7A2DB65D4503ED7BA0F3487C8F14812AFB8957B55DF38C299CB00
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
              • String ID: csm
              • API String ID: 2395640692-1018135373
              • Opcode ID: 97e6136df740a7f50eb7a5892aa497e90dc07242db7e08e9cb4e882c62b2f360
              • Instruction ID: a70401c98a6fa97f25aa09595eeaeae0d0d85a566f00d3635b5625c699437a8d
              • Opcode Fuzzy Hash: 97e6136df740a7f50eb7a5892aa497e90dc07242db7e08e9cb4e882c62b2f360
              • Instruction Fuzzy Hash: 1B51C532B196028AEF14CF25E8546B87791EB84BC8F558131DE8D87B98EF7CE841E701
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
              • String ID: csm
              • API String ID: 2395640692-1018135373
              • Opcode ID: 13c358311fadf4f3df844621465b603840deb53ac7d28d89eec5d6156f6e5895
              • Instruction ID: 86b998f5bf12b8c96b234125250119a7e6b940c65465f7b73c8d9d992c02ae69
              • Opcode Fuzzy Hash: 13c358311fadf4f3df844621465b603840deb53ac7d28d89eec5d6156f6e5895
              • Instruction Fuzzy Hash: A151B436315A0C8AEB96CF19E444BAC7795F348BD8F50C126FA4947788EF79CA49C710
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
              • String ID: csm$csm
              • API String ID: 3896166516-3733052814
              • Opcode ID: 1c7f32590a0a5e31803e0cd6c6efa8edac5466215bfbb7b2d07330e269dc0479
              • Instruction ID: 556d4a35c659a9ea5809b2ac00787c21a934c1624523c64735421b2c58417cac
              • Opcode Fuzzy Hash: 1c7f32590a0a5e31803e0cd6c6efa8edac5466215bfbb7b2d07330e269dc0479
              • Instruction Fuzzy Hash: D4516C32A0928286EF748F22984436876A0FB94BD9F184175DE9DA7BD5CF3CE451E702
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CallEncodePointerTranslator
              • String ID: MOC$RCC
              • API String ID: 3544855599-2084237596
              • Opcode ID: b953805b3f16366bb71475c1063139944ec3feeea47b818f87e78a0e56bad00b
              • Instruction ID: 357190531dd89134c82788ee97ea0b3982e746c2eb19df7e4e1ccb1ddfe7ae03
              • Opcode Fuzzy Hash: b953805b3f16366bb71475c1063139944ec3feeea47b818f87e78a0e56bad00b
              • Instruction Fuzzy Hash: B4616C32908B8586EB608F15E8407AAB7A0FBD5BD8F044225EE9C97B55DF7CE190CB01
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
              • String ID: csm$csm
              • API String ID: 3896166516-3733052814
              • Opcode ID: b0850b60aa430e1cd45b4dfe011a4f88f42e9d6e7321bba01b274de4dab42dce
              • Instruction ID: 7d909c39642bbe28e3b4d0590481b9fc60b29fe1a352d34aa78265810ee218f3
              • Opcode Fuzzy Hash: b0850b60aa430e1cd45b4dfe011a4f88f42e9d6e7321bba01b274de4dab42dce
              • Instruction Fuzzy Hash: 6C518F32108B888AEBB6CF2195443A877A0F759BD4F14C126FA9947FD5CF38C659DB02
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: CallEncodePointerTranslator
              • String ID: MOC$RCC
              • API String ID: 3544855599-2084237596
              • Opcode ID: 07b4155514e20e92ecf9f64cf41b237b3d8f1a0173dca8fd81025e83db01d437
              • Instruction ID: c2457d181eea9d09e04ac9aac13fdd46311119c7a2a8b61cb530facff3a1096e
              • Opcode Fuzzy Hash: 07b4155514e20e92ecf9f64cf41b237b3d8f1a0173dca8fd81025e83db01d437
              • Instruction Fuzzy Hash: B7619072508BC881E7A2DB15E4407EAB7A0F799BD4F048216FB9857B95DF78C298CB00
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
              • String ID: bad locale name
              • API String ID: 2775327233-1405518554
              • Opcode ID: 7f1a061b8976af83d8b946719d0ec26aa59b87afe9c014548f265c5772a16625
              • Instruction ID: 5a1a701f3471aaf2f3f08e489f1841eccae9a4ca403c690e0dbf9b0557de1cd2
              • Opcode Fuzzy Hash: 7f1a061b8976af83d8b946719d0ec26aa59b87afe9c014548f265c5772a16625
              • Instruction Fuzzy Hash: 97416F72702B48D9FB96DFB0D4913EC33A5EB48B88F048424AE4967A66DF34C619D344
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: FileWrite$ConsoleErrorLastOutput
              • String ID:
              • API String ID: 2718003287-0
              • Opcode ID: 77dd5d4aa20de0d79966c3f830593b01910af74af4cc21fda2ecf357b99f0be0
              • Instruction ID: f149ccf31613eed957a5b3d83f623237b30543a1e9b396b27607d153b1e5abb9
              • Opcode Fuzzy Hash: 77dd5d4aa20de0d79966c3f830593b01910af74af4cc21fda2ecf357b99f0be0
              • Instruction Fuzzy Hash: E4D10432B19A818AEB10CF65C8446EC37B6FB847D8B084636CE5D97B99DE3CE446D301
              APIs
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: FileWrite$ConsoleErrorLastOutput
              • String ID:
              • API String ID: 2718003287-0
              • Opcode ID: 861a04f167a145640bfa4ac565840c1d7945a4f9820a114d807eab6d418f50fa
              • Instruction ID: b3bd019fd41701119b6a00839c2f359c3c6b0fb5a801230ecd94157a94045758
              • Opcode Fuzzy Hash: 861a04f167a145640bfa4ac565840c1d7945a4f9820a114d807eab6d418f50fa
              • Instruction Fuzzy Hash: 54D1FF72704E888AE752CF69D4403DC37B2F359BD8F548216EE5997B99EE34C65AC300
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo_noreturn
              • String ID:
              • API String ID: 3668304517-0
              • Opcode ID: d257f816be6d76ad57501a7a9538cdd953e8241577ca37a1fb4d3e277f8092b9
              • Instruction ID: 55176166aec22014731139f5ace4be198c66c66621901e05806da7531c644016
              • Opcode Fuzzy Hash: d257f816be6d76ad57501a7a9538cdd953e8241577ca37a1fb4d3e277f8092b9
              • Instruction Fuzzy Hash: 6BB18B62F14B5585EF008FA5C8447EC23B1FB94BD8F409226DFAC67A99DF78A881D305
              APIs
              • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00000000,00007FF62980B0CF), ref: 00007FF62980B200
              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00000000,00007FF62980B0CF), ref: 00007FF62980B28B
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ConsoleErrorLastMode
              • String ID:
              • API String ID: 953036326-0
              • Opcode ID: 8d852cd364b953300601feb318994bc5f66eb9b85f3205e0d4ed1d6cdd918134
              • Instruction ID: 75fabd387341c5d9e422c9f1b679628e867df6a7065ee9fb9cb36d4f96e14b89
              • Opcode Fuzzy Hash: 8d852cd364b953300601feb318994bc5f66eb9b85f3205e0d4ed1d6cdd918134
              • Instruction Fuzzy Hash: ED91A532E1965185FF508F659C502BD2BA0BB84B98F28453DDE0E97695EF3CD441E702
              APIs
              • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000018001EA2F), ref: 000000018001EB60
              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,000000018001EA2F), ref: 000000018001EBEB
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ConsoleErrorLastMode
              • String ID:
              • API String ID: 953036326-0
              • Opcode ID: 49a2e42ec551f1b941d191485315cc1d7aab3ab981fb49e9029b938607fd3b67
              • Instruction ID: 968b22b41c18c0cc5373cbc988b2759c4878e4006f223ace9c89d3772c01036f
              • Opcode Fuzzy Hash: 49a2e42ec551f1b941d191485315cc1d7aab3ab981fb49e9029b938607fd3b67
              • Instruction Fuzzy Hash: 2D91D672714ED885F792CF6598803ED6BA0B74ABC8F54810AFE0A57A85DF74C64AC701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
              • String ID:
              • API String ID: 3936042273-0
              • Opcode ID: cedb37415d28f0d5fc81d2be32ad27eefc419e6366b4b4598dc6ad78484c38c0
              • Instruction ID: 6ecd68b3d803b353f0423e529fd414302e0fe79ff39b43187e346bf4fff6d25b
              • Opcode Fuzzy Hash: cedb37415d28f0d5fc81d2be32ad27eefc419e6366b4b4598dc6ad78484c38c0
              • Instruction Fuzzy Hash: 17719C62F18B8585EE04DF65D8083AC6361EB84FE4F558631DFAC57B95DF38E4809301
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Process32$CreateFirstNextSnapshotToolhelp32_invalid_parameter_noinfo_invalid_parameter_noinfo_noreturn
              • String ID:
              • API String ID: 4260596558-0
              • Opcode ID: c6f38536b4c1532cb70b46ea82a55bc7ea5d3f0e8f222eae863a7f2387986adb
              • Instruction ID: 8191bf8aab4a40097e3584ea3351650f41a4a5ca5d29c36ed45000c58bfb08db
              • Opcode Fuzzy Hash: c6f38536b4c1532cb70b46ea82a55bc7ea5d3f0e8f222eae863a7f2387986adb
              • Instruction Fuzzy Hash: 9071C062B29A8681EF208F25D84426E6261FFC5BE0F458631EA6E837D4DF3CE540D711
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: Virtual$AllocInfoProtectQuerySystem
              • String ID:
              • API String ID: 3562403962-0
              • Opcode ID: 8276b17d3f0086b027f55cc71dd443fed715192864dd3a3d0b6a65bee2902499
              • Instruction ID: 18a09071ddf4af796529a35456134d5dcc9025b3f7ae00dc221d276b675b2ec5
              • Opcode Fuzzy Hash: 8276b17d3f0086b027f55cc71dd443fed715192864dd3a3d0b6a65bee2902499
              • Instruction Fuzzy Hash: 66313532714A819EDB20CF25DC547E923A5FB88B88F888436EE4D97B48DF38E645D701
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CriticalSection$Leave$EnterEvent
              • String ID:
              • API String ID: 3394196147-0
              • Opcode ID: ee59a16ddcb61b2f30476306e2c70f7e991c931b41d410101ed0a7d795a74e2b
              • Instruction ID: 38dbee3eed2c21c4c8fe75ecf57f88ab982d64c3ff09f26fdc2c1b92b82e169a
              • Opcode Fuzzy Hash: ee59a16ddcb61b2f30476306e2c70f7e991c931b41d410101ed0a7d795a74e2b
              • Instruction Fuzzy Hash: FA21FB36704B8193DB48CF2AE9802ADB3A4FB88B84F548535DB6D83765DF38E4A1C740
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
              • String ID:
              • API String ID: 2933794660-0
              • Opcode ID: cc56691cd60568e6146a7dde9c83608ec099c6c6a56f3e0ff612a8b3836fe06a
              • Instruction ID: 4d51b21c62c0c7e6ab8ba9702bc436374db4e3a21c76206736067fba1b1dad45
              • Opcode Fuzzy Hash: cc56691cd60568e6146a7dde9c83608ec099c6c6a56f3e0ff612a8b3836fe06a
              • Instruction Fuzzy Hash: 6D111826B15B018AEF008F60EC552B833A4FB99758F480E35EA6D86BA4DF7CD1549381
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ObjectSingleWait$Sleep
              • String ID:
              • API String ID: 2961732021-0
              • Opcode ID: 4ede45267323656183b3c0ec57ef8ecec2c46d3b5a24cc8965c2015fc5653a59
              • Instruction ID: f66e9a44c5e6a337cfef70bf03fa2874d5aa83e2c9158fd8b2452b591a5c1360
              • Opcode Fuzzy Hash: 4ede45267323656183b3c0ec57ef8ecec2c46d3b5a24cc8965c2015fc5653a59
              • Instruction Fuzzy Hash: 2EF0B762606E4586EB409F3ADC542283261EBC9B35F194730CE2D873E4CF2C84859355
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _invalid_parameter_noinfo_noreturn
              • String ID: ^(T[A-Za-z0-9]*|0x[A-Za-z0-9]*)$
              • API String ID: 3668304517-660079095
              • Opcode ID: d6e9319f76612da4129a7a39a2785b1a8ebb768b0e5a827b01119e51270e07b9
              • Instruction ID: f2111a22b3ec5e73563fddef4291b14b917c2cf07f1575ec677274acde973764
              • Opcode Fuzzy Hash: d6e9319f76612da4129a7a39a2785b1a8ebb768b0e5a827b01119e51270e07b9
              • Instruction Fuzzy Hash: 0581AB72A15B818AEF68CF64D8417FC33A5EB88B98F044235EA9D83B88DF38D550D341
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: __except_validate_context_record
              • String ID: csm$csm
              • API String ID: 1467352782-3733052814
              • Opcode ID: 2e13650262a6f61ea207b4025eb27adbf5cb157b43e28d55221f4b040b54e9a1
              • Instruction ID: 2a20dacaf5853cee2ae1db919de77a8f874f0ee5830d43ded3d274625670ec99
              • Opcode Fuzzy Hash: 2e13650262a6f61ea207b4025eb27adbf5cb157b43e28d55221f4b040b54e9a1
              • Instruction Fuzzy Hash: 3E71B072A0868186DF609F25984067D7BA0FB95BC8F148135DE8CA7B89CF3CD551E782
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: __except_validate_context_record
              • String ID: csm$csm
              • API String ID: 1467352782-3733052814
              • Opcode ID: 895abce1613108e09bf91c6752ff72b91439e2e548a11cd7f7d4602d38364546
              • Instruction ID: becc8f7099377ae79f9dd4482b5ba2fdf4c1387738658b329dfe7b8e2f24bcde
              • Opcode Fuzzy Hash: 895abce1613108e09bf91c6752ff72b91439e2e548a11cd7f7d4602d38364546
              • Instruction Fuzzy Hash: D5717D722046C486EBB2CF25D4907B97BA0F349BC8F14C126EE8947B96DF38C699D741
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: _get_daylight$_invalid_parameter_noinfo
              • String ID: ?
              • API String ID: 1286766494-1684325040
              • Opcode ID: 0b7c1d742c13ddddedbe4d6e2c5e7ad1023c035335ca7369220edd5dde904ae5
              • Instruction ID: f1a313a7732f399a8f6fdb74c98e838623c8f62c12f31b245ed70066ee2b4549
              • Opcode Fuzzy Hash: 0b7c1d742c13ddddedbe4d6e2c5e7ad1023c035335ca7369220edd5dde904ae5
              • Instruction Fuzzy Hash: B5411622A0978242FF649F25D85137A6AA1EFC0BB4F184635EF5C86AE6DF3CD441D702
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: CreateFrameInfo__except_validate_context_record
              • String ID: csm
              • API String ID: 2558813199-1018135373
              • Opcode ID: 503767daf86984436527780b72ab736630531d0d6d2b9058069c45c3b2766ca2
              • Instruction ID: 799e951ae0fdb5f81a127acf1cc72753be883b6d32636c4ebea3726602971c86
              • Opcode Fuzzy Hash: 503767daf86984436527780b72ab736630531d0d6d2b9058069c45c3b2766ca2
              • Instruction Fuzzy Hash: 9A516932A1874196EA20AF25E84026E7BA4FBD9BD4F140134EF8D97B55CF3CE460DB46
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: CreateFrameInfo__except_validate_context_record
              • String ID: csm
              • API String ID: 2558813199-1018135373
              • Opcode ID: 5b34568935c4705788cbef81ace7358cb1415b5559f1a6b740380e12c6fe9909
              • Instruction ID: ba345324194aeead1a7fd208c2bc7d11cf1416831069b0cac38a44b55e278ebe
              • Opcode Fuzzy Hash: 5b34568935c4705788cbef81ace7358cb1415b5559f1a6b740380e12c6fe9909
              • Instruction Fuzzy Hash: E3514F36615B4886E7A1EF25E44039E77A4F38CBE0F14911AFB8907B56CF38D5A5CB00
              APIs
              • _invalid_parameter_noinfo.LIBCMT ref: 00007FF6297FBFB6
                • Part of subcall function 00007FF6297FE6BC: RtlFreeHeap.NTDLL(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6D2
                • Part of subcall function 00007FF6297FE6BC: GetLastError.KERNEL32(?,?,?,00007FF6298065C2,?,?,?,00007FF62980693F,?,?,00000000,00007FF629806D85,?,?,?,00007FF629806CB7), ref: 00007FF6297FE6DC
              • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF6297EDF31), ref: 00007FF6297FBFD4
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
              • String ID: C:\Users\user\Desktop\A74lw30K2g.exe
              • API String ID: 3580290477-2153160974
              • Opcode ID: 3a5b6248115956fb8c5867fcb2c099a73d6e8c573ad95eb16c3a51b61da9d299
              • Instruction ID: f5912d0d4350123a54b65037ea0bac5f551820f25442068f393ec6b307b61aa6
              • Opcode Fuzzy Hash: 3a5b6248115956fb8c5867fcb2c099a73d6e8c573ad95eb16c3a51b61da9d299
              • Instruction Fuzzy Hash: 0C419F36A08B5285EF14EF25AC501B82794FFC47C8B58403AED4E97B85DF3DE4419342
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorFileLastWrite
              • String ID: U
              • API String ID: 442123175-4171548499
              • Opcode ID: 54112263acd02f42df0a8cef6501b04abbfb211da2f70ad802a6942ee1910395
              • Instruction ID: 3522acb50541d42a5e285a12178ff4fa27169ee78b4990959fe0e773d2fef328
              • Opcode Fuzzy Hash: 54112263acd02f42df0a8cef6501b04abbfb211da2f70ad802a6942ee1910395
              • Instruction Fuzzy Hash: 9941BF72A19A8182DB208F65E8483AA67A0FB88784F444531EE4DC7B98EF3CD441D741
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorFileLastWrite
              • String ID: U
              • API String ID: 442123175-4171548499
              • Opcode ID: f24d4360071c80fb71cad35b825f144506e0bf8956c3b6e5e033a727242eb68e
              • Instruction ID: 6ca80f441ea9d728a68e55209c120f710e03378b6947d59e009682c10d2f7603
              • Opcode Fuzzy Hash: f24d4360071c80fb71cad35b825f144506e0bf8956c3b6e5e033a727242eb68e
              • Instruction Fuzzy Hash: D841B232614A8881DBA1CF25E8443EAA7A1F79C7D4F558022FE4D87798EF78C549CB40
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: __std_exception_copy_invalid_parameter_noinfo_noreturn
              • String ID: ios_base::failbit set
              • API String ID: 1109970293-3924258884
              • Opcode ID: f48672037dbc756fe4a3c608245e54b90e6796cb79f5c20c2a751e4f68631c12
              • Instruction ID: ebe7e70430f3d93ff5bac542733ca5d67b21a4867189b9d29e9eb3c82015a28f
              • Opcode Fuzzy Hash: f48672037dbc756fe4a3c608245e54b90e6796cb79f5c20c2a751e4f68631c12
              • Instruction Fuzzy Hash: 44217272A14B8881EA428B25E5413E9B320EB6D7E4F54D312BAAC12795EF68C2D5C300
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_Yarn
              • String ID: bad locale name
              • API String ID: 1838369231-1405518554
              • Opcode ID: 7fa6409ea9060c50129f46dd6aba4315dbb287674bbff41f9bc8a706b28e0065
              • Instruction ID: 7684f1584dce57dd15b1b76c37149e27feac844ddba349f45601ed614675140c
              • Opcode Fuzzy Hash: 7fa6409ea9060c50129f46dd6aba4315dbb287674bbff41f9bc8a706b28e0065
              • Instruction Fuzzy Hash: 2D016232206B8489D786DF75A84038D77A5F76CB88F189129DA8C8371AEF34C694C340
              APIs
              • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297D1111), ref: 00007FF6297F00A0
              • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF6297D1111), ref: 00007FF6297F00E1
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionFileHeaderRaise
              • String ID: csm
              • API String ID: 2573137834-1018135373
              • Opcode ID: 3c98ac448948905eff4ad47a47963f754950c65019d46630b15deedf807f34ab
              • Instruction ID: 341e40689b852a4ca7ad78c98e3ce4b06414885ae3be24b6d43b321a0c6ba952
              • Opcode Fuzzy Hash: 3c98ac448948905eff4ad47a47963f754950c65019d46630b15deedf807f34ab
              • Instruction Fuzzy Hash: 3F115B32609B8082EB208F15E800269B7E1FB88B98F588231DE8C87B58DF3CC5518B01
              APIs
              • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00000001800075C6), ref: 000000018000D4F8
              • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00000001800075C6), ref: 000000018000D539
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: ExceptionFileHeaderRaise
              • String ID: csm
              • API String ID: 2573137834-1018135373
              • Opcode ID: b4b2e42f82535f6cd8f43ede81a42d412f061f5a20d12d5532239127ba30e230
              • Instruction ID: f9483296fcb1112b1c41b7b709c5cb24d3e63c0f5610d76f34831a106a2daeab
              • Opcode Fuzzy Hash: b4b2e42f82535f6cd8f43ede81a42d412f061f5a20d12d5532239127ba30e230
              • Instruction Fuzzy Hash: 3A11FE36214B4882EBA2CF15E44039977E5F788B98F588226EE8D07B55DF38C655CB00
              APIs
              Strings
              Memory Dump Source
              • Source File: 00000000.00000003.3996677593.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
              • Associated: 00000000.00000003.1789807836.000000018002D000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.1789823968.000000018003E000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3569772161.0000000180042000.00000002.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996578342.0000000180046000.00000004.00001000.00020000.00000000.sdmpDownload File
              • Associated: 00000000.00000003.3996629569.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_3_180000000_A74lw30K2g.jbxd
              Similarity
              • API ID: LockitLockit::_std::_
              • String ID: ios_base::failbit set
              • API String ID: 3382485803-3924258884
              • Opcode ID: 97d73ab2c9be66f3b8356052de4806099d5498c412a7310db58eab878f6b97e3
              • Instruction ID: 2400c2c62faab8a80a5c937cb35b6122776fcd50979075003f5fae5a11897ed5
              • Opcode Fuzzy Hash: 97d73ab2c9be66f3b8356052de4806099d5498c412a7310db58eab878f6b97e3
              • Instruction Fuzzy Hash: FE01DB32B4158854FB97DB55DA447E97711D7A87D4F08D021BE0C076A6DF38CA8BC310
              APIs
              Memory Dump Source
              • Source File: 00000000.00000002.4142841260.00007FF6297D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6297D0000, based on PE: true
              • Associated: 00000000.00000002.4142818118.00007FF6297D0000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142877004.00007FF62980F000.00000002.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142905980.00007FF629825000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142927877.00007FF629828000.00000008.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142949532.00007FF62982C000.00000004.00000001.01000000.00000003.sdmpDownload File
              • Associated: 00000000.00000002.4142974460.00007FF629830000.00000002.00000001.01000000.00000003.sdmpDownload File
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_7ff6297d0000_A74lw30K2g.jbxd
              Similarity
              • API ID: ErrorLastRead
              • String ID:
              • API String ID: 4100373531-0
              • Opcode ID: e0e517c51036cec7b570afbeb596ed896a79d3929b09d4426d0e27ecdcf8b3b8
              • Instruction ID: 0f4dbe309900bf8d1fe3d77bb41d12914ff171afcb61098837021e7e965d82fe
              • Opcode Fuzzy Hash: e0e517c51036cec7b570afbeb596ed896a79d3929b09d4426d0e27ecdcf8b3b8
              • Instruction Fuzzy Hash: 1A411962B09B4287EF148F2AE84426923A0FB89B94F095435DF8E87754DF3CE4A1D711