Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
sUlHfYQxNw.dll

Overview

General Information

Sample name:sUlHfYQxNw.dll
renamed because original name is a hash value
Original sample name:68165b3d89166ec828062f5c356e0e1b.dll
Analysis ID:1591279
MD5:68165b3d89166ec828062f5c356e0e1b
SHA1:208485739bbab56c7998f952c3d742527cfdeeb7
SHA256:22085c67126368a27c68cb62a147c0895f3e4d76d30c704952dcd356cf68b53f
Tags:dllexeuser-mentality
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Wannacry ransomware
AI detected suspicious sample
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses insecure TLS / SSL version for HTTPS connection
Yara signature match

Classification

  • System is w10x64
  • loaddll32.exe (PID: 7676 cmdline: loaddll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 7684 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 7728 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 7752 cmdline: rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
        • mssecsvr.exe (PID: 7816 cmdline: C:\WINDOWS\mssecsvr.exe MD5: B01DB44786F461C9415813F968A7664A)
    • rundll32.exe (PID: 7736 cmdline: rundll32.exe C:\Users\user\Desktop\sUlHfYQxNw.dll,PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7960 cmdline: rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
      • mssecsvr.exe (PID: 7976 cmdline: C:\WINDOWS\mssecsvr.exe MD5: B01DB44786F461C9415813F968A7664A)
  • mssecsvr.exe (PID: 7920 cmdline: C:\WINDOWS\mssecsvr.exe -m security MD5: B01DB44786F461C9415813F968A7664A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
sUlHfYQxNw.dllJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    sUlHfYQxNw.dllWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x353d0:$x3: tasksche.exe
    • 0x353a8:$x8: C:\%s\qeriuwjhrf
    • 0x3014:$s1: C:\%s\%s
    • 0x12098:$s1: C:\%s\%s
    • 0x1b39c:$s1: C:\%s\%s
    • 0x353bc:$s1: C:\%s\%s
    • 0x326f0:$s5: \\192.168.56.20\IPC$
    • 0x1fae5:$s6: \\172.16.99.5\IPC$
    • 0xd195:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
    • 0x78da:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
    • 0x5449:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
    SourceRuleDescriptionAuthorStrings
    00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      00000006.00000000.1356648127.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          00000008.00000002.2032119796.00000000024E9000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            0000000A.00000000.1385339292.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
              Click to see the 6 entries
              SourceRuleDescriptionAuthorStrings
              8.2.mssecsvr.exe.24da8c8.7.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
              • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
              • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
              • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
              8.2.mssecsvr.exe.1fa9084.3.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
              • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
              • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
              • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
              8.2.mssecsvr.exe.24e9948.9.raw.unpackJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
                8.2.mssecsvr.exe.24e9948.9.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x222ec:$x3: tasksche.exe
                • 0x222c4:$x8: C:\%s\qeriuwjhrf
                • 0x82b8:$s1: C:\%s\%s
                • 0x222d8:$s1: C:\%s\%s
                • 0x1f60c:$s5: \\192.168.56.20\IPC$
                • 0xca01:$s6: \\172.16.99.5\IPC$
                8.2.mssecsvr.exe.24e9948.9.raw.unpackWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
                • 0xca4c:$s1: __TREEID__PLACEHOLDER__
                • 0xcae8:$s1: __TREEID__PLACEHOLDER__
                • 0xd354:$s1: __TREEID__PLACEHOLDER__
                • 0xe3b9:$s1: __TREEID__PLACEHOLDER__
                • 0xf420:$s1: __TREEID__PLACEHOLDER__
                • 0x10488:$s1: __TREEID__PLACEHOLDER__
                • 0x114f0:$s1: __TREEID__PLACEHOLDER__
                • 0x12558:$s1: __TREEID__PLACEHOLDER__
                • 0x135c0:$s1: __TREEID__PLACEHOLDER__
                • 0x14628:$s1: __TREEID__PLACEHOLDER__
                • 0x15690:$s1: __TREEID__PLACEHOLDER__
                • 0x166f8:$s1: __TREEID__PLACEHOLDER__
                • 0x17760:$s1: __TREEID__PLACEHOLDER__
                • 0x187c8:$s1: __TREEID__PLACEHOLDER__
                • 0x19830:$s1: __TREEID__PLACEHOLDER__
                • 0x1a898:$s1: __TREEID__PLACEHOLDER__
                • 0x1b900:$s1: __TREEID__PLACEHOLDER__
                • 0x1bb14:$s1: __TREEID__PLACEHOLDER__
                • 0x1bb74:$s1: __TREEID__PLACEHOLDER__
                • 0x1f244:$s1: __TREEID__PLACEHOLDER__
                • 0x1f2c0:$s1: __TREEID__PLACEHOLDER__
                Click to see the 35 entries
                No Sigma rule has matched
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-01-14T21:06:32.939526+010028033043Unknown Traffic192.168.2.949742103.224.212.21580TCP
                2025-01-14T21:06:34.454699+010028033043Unknown Traffic192.168.2.949754103.224.212.21580TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-01-14T21:06:31.993258+010028300181A Network Trojan was detected192.168.2.9580341.1.1.153UDP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: sUlHfYQxNw.dllAvira: detected
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3aAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/BAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3a01Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e6972fAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c837Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c83701Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e697Avira URL Cloud: Label: malware
                Source: C:\WINDOWS\qeriuwjhrf (copy)ReversingLabs: Detection: 65%
                Source: C:\Windows\tasksche.exeReversingLabs: Detection: 65%
                Source: sUlHfYQxNw.dllReversingLabs: Detection: 92%
                Source: sUlHfYQxNw.dllVirustotal: Detection: 94%Perma Link
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.1% probability
                Source: C:\Windows\tasksche.exeJoe Sandbox ML: detected
                Source: sUlHfYQxNw.dllJoe Sandbox ML: detected

                Exploits

                barindex
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: sUlHfYQxNw.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: unknownHTTPS traffic detected: 23.206.229.209:443 -> 192.168.2.9:49986 version: TLS 1.0

                Networking

                barindex
                Source: Network trafficSuricata IDS: 2830018 - Severity 1 - ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup) : 192.168.2.9:58034 -> 1.1.1.1:53
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-0706-326f-9c7c-3821cc5c3a01 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736885192.5042682
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-0706-3461-b88e-f77f83c83701 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-0706-350f-b72d-c6b0b8e6972f HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=8462b0ae-2235-4789-ae47-4c74deb8c66f
                Source: Joe Sandbox ViewJA3 fingerprint: 1138de370e523e824bbca92d049a3777
                Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.9:49742 -> 103.224.212.215:80
                Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.9:49754 -> 103.224.212.215:80
                Source: unknownHTTPS traffic detected: 23.206.229.209:443 -> 192.168.2.9:49986 version: TLS 1.0
                Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.11
                Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.209
                Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.209
                Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.209
                Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.11
                Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.11
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
                Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.209
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.223
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.223
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.223
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.1
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.223
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.1
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.1
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.1
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.1
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.1
                Source: unknownTCP traffic detected without corresponding DNS query: 3.157.171.1
                Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.209
                Source: unknownTCP traffic detected without corresponding DNS query: 23.206.229.209
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.210
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.210
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.210
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.1
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.1
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.1
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.210
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.1
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.1
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.1
                Source: unknownTCP traffic detected without corresponding DNS query: 116.209.81.1
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.173
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.173
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.173
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.173
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 15.212.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.245.156.111
                Source: unknownTCP traffic detected without corresponding DNS query: 126.245.156.111
                Source: unknownTCP traffic detected without corresponding DNS query: 126.245.156.111
                Source: unknownTCP traffic detected without corresponding DNS query: 126.245.156.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.245.156.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.245.156.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.245.156.1
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-0706-326f-9c7c-3821cc5c3a01 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736885192.5042682
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-0706-3461-b88e-f77f83c83701 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-0706-350f-b72d-c6b0b8e6972f HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=8462b0ae-2235-4789-ae47-4c74deb8c66f
                Source: global trafficDNS traffic detected: DNS query: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: global trafficDNS traffic detected: DNS query: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: mssecsvr.exe, 00000006.00000002.1396004769.0000000000C1F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3a
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c837
                Source: mssecsvr.exe, 0000000A.00000002.1401202588.0000000000C1D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e697
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/B
                Source: sUlHfYQxNw.dllString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: mssecsvr.exe, 0000000A.00000002.1401202588.0000000000C1D000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 0000000A.00000002.1401202588.0000000000C3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: mssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/#
                Source: mssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/L
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/R
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/b
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/r
                Source: mssecsvr.exe, 00000008.00000002.2030892381.000000000019D000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJ
                Source: mssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comQ
                Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49986
                Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49986 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704

                Spam, unwanted Advertisements and Ransom Demands

                barindex
                Source: Yara matchFile source: sUlHfYQxNw.dll, type: SAMPLE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.24e9948.9.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.1fb8104.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.1fa9084.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.24da8c8.7.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.1fb8104.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.1fb40a4.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.24e58e8.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvr.exe.24e9948.9.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000006.00000000.1356648127.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.2032119796.00000000024E9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 0000000A.00000000.1385339292.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.2031833962.0000000001FB8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 0000000A.00000002.1400701115.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000000.1379865895.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 7816, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 7920, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 7976, type: MEMORYSTR

                System Summary

                barindex
                Source: sUlHfYQxNw.dll, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.24da8c8.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.1fa9084.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.24e9948.9.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.24e9948.9.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvr.exe.1fb8104.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.1fb8104.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvr.exe.1fa9084.3.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.1fa9084.3.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvr.exe.24da8c8.7.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.24da8c8.7.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvr.exe.1fb8104.2.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.1fb40a4.4.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.24e58e8.6.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvr.exe.24e9948.9.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: tasksche.exe.6.drStatic PE information: No import functions for PE file found
                Source: sUlHfYQxNw.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: sUlHfYQxNw.dll, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.24da8c8.7.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.1fa9084.3.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.24e9948.9.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.24e9948.9.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvr.exe.1fb8104.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.1fb8104.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvr.exe.1fa9084.3.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.1fa9084.3.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvr.exe.24da8c8.7.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.24da8c8.7.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvr.exe.1fb8104.2.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.1fb40a4.4.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.24e58e8.6.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvr.exe.24e9948.9.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: tasksche.exe.6.drStatic PE information: Section: .rdata ZLIB complexity 1.0007621951219512
                Source: tasksche.exe.6.drStatic PE information: Section: .data ZLIB complexity 1.001953125
                Source: classification engineClassification label: mal100.rans.expl.evad.winDLL@18/2@2/100
                Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,8_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: 6_2_00407CE0 InternetCloseHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessA,FindResourceA,LoadResource,LockResource,SizeofResource,sprintf,sprintf,sprintf,MoveFileExA,CreateFileA,WriteFile,CloseHandle,CreateProcessA,CloseHandle,CloseHandle,6_2_00407CE0
                Source: C:\Windows\mssecsvr.exeCode function: 6_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: 6_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,6_2_00408090
                Source: C:\Windows\mssecsvr.exeCode function: 8_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,8_2_00408090
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7684:120:WilError_03
                Source: sUlHfYQxNw.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\sUlHfYQxNw.dll,PlayGame
                Source: sUlHfYQxNw.dllReversingLabs: Detection: 92%
                Source: sUlHfYQxNw.dllVirustotal: Detection: 94%
                Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll"
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\sUlHfYQxNw.dll,PlayGame
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                Source: unknownProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe -m security
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",PlayGame
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1Jump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\sUlHfYQxNw.dll,PlayGameJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",PlayGameJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1Jump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
                Source: sUlHfYQxNw.dllStatic file information: File size 5267459 > 1048576
                Source: sUlHfYQxNw.dllStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x501000
                Source: tasksche.exe.6.drStatic PE information: section name: .text entropy: 6.811395527809462

                Persistence and Installation Behavior

                barindex
                Source: C:\Windows\SysWOW64\rundll32.exeExecutable created and started: C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exeCode function: 6_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exe TID: 8048Thread sleep count: 98 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 8048Thread sleep time: -196000s >= -30000sJump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 8052Thread sleep count: 125 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 8052Thread sleep count: 44 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 8048Thread sleep time: -86400000s >= -30000sJump to behavior
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\loaddll32.exeThread delayed: delay time: 120000Jump to behavior
                Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                Source: mssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW ^
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000AFE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%
                Source: mssecsvr.exe, 00000006.00000002.1396004769.0000000000C07000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000006.00000002.1396004769.0000000000C3D000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2031364988.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 0000000A.00000002.1401202588.0000000000C3C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                Source: mssecsvr.exe, 00000006.00000002.1396004769.0000000000C3D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWc
                Source: mssecsvr.exe, 00000008.00000002.2031364988.0000000000AB8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW0V
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1Jump to behavior
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                Service Execution
                4
                Windows Service
                4
                Windows Service
                12
                Masquerading
                OS Credential Dumping1
                Network Share Discovery
                Remote ServicesData from Local System2
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/Job1
                DLL Side-Loading
                11
                Process Injection
                21
                Virtualization/Sandbox Evasion
                LSASS Memory11
                Security Software Discovery
                Remote Desktop ProtocolData from Removable Media1
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                11
                Process Injection
                Security Account Manager21
                Virtualization/Sandbox Evasion
                SMB/Windows Admin SharesData from Network Shared Drive2
                Non-Application Layer Protocol
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                Obfuscated Files or Information
                NTDS1
                System Information Discovery
                Distributed Component Object ModelInput Capture3
                Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Rundll32
                LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
                Software Packing
                Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                DLL Side-Loading
                DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1591279 Sample: sUlHfYQxNw.dll Startdate: 14/01/2025 Architecture: WINDOWS Score: 100 36 www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->36 38 ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->38 40 77026.bodis.com 2->40 48 Suricata IDS alerts for network traffic 2->48 50 Malicious sample detected (through community Yara rule) 2->50 52 Antivirus detection for URL or domain 2->52 54 7 other signatures 2->54 9 loaddll32.exe 1 2->9         started        11 mssecsvr.exe 12 2->11         started        signatures3 process4 dnsIp5 15 rundll32.exe 9->15         started        18 cmd.exe 1 9->18         started        20 conhost.exe 9->20         started        22 rundll32.exe 1 9->22         started        42 192.168.2.104 unknown unknown 11->42 44 192.168.2.90 unknown unknown 11->44 46 98 other IPs or domains 11->46 56 Connects to many different private IPs via SMB (likely to spread or exploit) 11->56 58 Connects to many different private IPs (likely to spread or exploit) 11->58 signatures6 process7 signatures8 60 Drops executables to the windows directory (C:\Windows) and starts them 15->60 24 mssecsvr.exe 13 15->24         started        27 rundll32.exe 18->27         started        process9 file10 32 C:\WINDOWS\qeriuwjhrf (copy), PE32 24->32 dropped 29 mssecsvr.exe 13 27->29         started        process11 file12 34 C:\Windows\tasksche.exe, PE32 29->34 dropped

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                sUlHfYQxNw.dll92%ReversingLabsWin32.Ransomware.WannaCry
                sUlHfYQxNw.dll95%VirustotalBrowse
                sUlHfYQxNw.dll100%AviraTR/Ransom.Gen
                sUlHfYQxNw.dll100%Joe Sandbox ML
                SourceDetectionScannerLabelLink
                C:\Windows\tasksche.exe100%Joe Sandbox ML
                C:\WINDOWS\qeriuwjhrf (copy)65%ReversingLabsWin32.Trojan.Generic
                C:\Windows\tasksche.exe65%ReversingLabsWin32.Trojan.Generic
                No Antivirus matches
                No Antivirus matches
                SourceDetectionScannerLabelLink
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3a100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/B100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3a01100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJ0%Avira URL Cloudsafe
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e6972f100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comQ0%Avira URL Cloudsafe
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c837100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c83701100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e697100%Avira URL Cloudmalware
                NameIPActiveMaliciousAntivirus DetectionReputation
                77026.bodis.com
                199.59.243.228
                truefalse
                  high
                  s-part-0017.t-0009.t-msedge.net
                  13.107.246.45
                  truefalse
                    high
                    www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                    103.224.212.215
                    truefalse
                      high
                      ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                      unknown
                      unknownfalse
                        unknown
                        NameMaliciousAntivirus DetectionReputation
                        http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3a01false
                        • Avira URL Cloud: malware
                        unknown
                        http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c83701false
                        • Avira URL Cloud: malware
                        unknown
                        http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/false
                          high
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e6972ffalse
                          • Avira URL Cloud: malware
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Lmssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e697mssecsvr.exe, 0000000A.00000002.1401202588.0000000000C1D000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: malware
                            unknown
                            http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: malware
                            unknown
                            http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comsUlHfYQxNw.dllfalse
                              high
                              http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3amssecsvr.exe, 00000006.00000002.1396004769.0000000000C1F000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: malware
                              unknown
                              http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/bmssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comQmssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/#mssecsvr.exe, 0000000A.00000002.1401202588.0000000000BE8000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c837mssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: malware
                                  unknown
                                  http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJmssecsvr.exe, 00000008.00000002.2030892381.000000000019D000.00000004.00000010.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Rmssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/rmssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Bmssecsvr.exe, 00000008.00000002.2031364988.0000000000ADB000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: malware
                                      unknown
                                      • No. of IPs < 25%
                                      • 25% < No. of IPs < 50%
                                      • 50% < No. of IPs < 75%
                                      • 75% < No. of IPs
                                      IPDomainCountryFlagASNASN NameMalicious
                                      16.10.57.2
                                      unknownUnited States
                                      unknownunknownfalse
                                      16.10.57.1
                                      unknownUnited States
                                      unknownunknownfalse
                                      51.159.121.244
                                      unknownFrance
                                      12876OnlineSASFRfalse
                                      15.212.96.173
                                      unknownUnited States
                                      71HP-INTERNET-ASUSfalse
                                      103.42.206.1
                                      unknownIndia
                                      134307CLASSIC-JOISTER-ASClassicnetBroadbandNetworkINfalse
                                      15.212.96.2
                                      unknownUnited States
                                      71HP-INTERNET-ASUSfalse
                                      15.212.96.1
                                      unknownUnited States
                                      71HP-INTERNET-ASUSfalse
                                      132.227.104.105
                                      unknownFrance
                                      1307FR-U-JUSSIEU-PARISEUfalse
                                      62.129.107.104
                                      unknownUnited Kingdom
                                      8309SIPARTECHFRfalse
                                      116.209.81.2
                                      unknownChina
                                      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                                      116.209.81.1
                                      unknownChina
                                      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                                      71.110.186.84
                                      unknownUnited States
                                      5650FRONTIER-FRTRUSfalse
                                      71.110.186.1
                                      unknownUnited States
                                      5650FRONTIER-FRTRUSfalse
                                      186.17.232.1
                                      unknownParaguay
                                      23201TelecelSAPYfalse
                                      223.92.131.20
                                      unknownChina
                                      56041CMNET-ZHEJIANG-APChinaMobilecommunicationscorporationCfalse
                                      138.57.247.2
                                      unknownUnited States
                                      2611BELNETBEfalse
                                      138.57.247.1
                                      unknownUnited States
                                      2611BELNETBEfalse
                                      136.127.160.1
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      34.81.201.226
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      3.157.171.223
                                      unknownUnited States
                                      16509AMAZON-02USfalse
                                      126.245.156.111
                                      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                                      178.11.150.1
                                      unknownGermany
                                      3209VODANETInternationalIP-BackboneofVodafoneDEfalse
                                      50.121.163.1
                                      unknownUnited States
                                      5650FRONTIER-FRTRUSfalse
                                      199.83.239.1
                                      unknownUnited States
                                      32458INDCONETUSfalse
                                      199.83.239.2
                                      unknownUnited States
                                      32458INDCONETUSfalse
                                      63.166.202.107
                                      unknownUnited States
                                      1239SPRINTLINKUSfalse
                                      3.157.171.2
                                      unknownUnited States
                                      16509AMAZON-02USfalse
                                      3.157.171.1
                                      unknownUnited States
                                      16509AMAZON-02USfalse
                                      150.135.181.70
                                      unknownUnited States
                                      1706UNIV-ARIZUSfalse
                                      144.69.237.2
                                      unknownUnited States
                                      36351SOFTLAYERUSfalse
                                      51.159.121.1
                                      unknownFrance
                                      12876OnlineSASFRfalse
                                      144.69.237.1
                                      unknownUnited States
                                      36351SOFTLAYERUSfalse
                                      103.42.206.197
                                      unknownIndia
                                      134307CLASSIC-JOISTER-ASClassicnetBroadbandNetworkINfalse
                                      IP
                                      192.168.2.148
                                      192.168.2.149
                                      192.168.2.146
                                      192.168.2.147
                                      192.168.2.140
                                      192.168.2.141
                                      192.168.2.144
                                      192.168.2.145
                                      192.168.2.142
                                      192.168.2.143
                                      192.168.2.159
                                      192.168.2.157
                                      192.168.2.158
                                      192.168.2.151
                                      192.168.2.152
                                      192.168.2.150
                                      192.168.2.155
                                      192.168.2.156
                                      192.168.2.153
                                      192.168.2.154
                                      192.168.2.126
                                      192.168.2.247
                                      192.168.2.127
                                      192.168.2.248
                                      192.168.2.124
                                      192.168.2.245
                                      192.168.2.125
                                      192.168.2.246
                                      192.168.2.128
                                      192.168.2.249
                                      192.168.2.129
                                      192.168.2.240
                                      192.168.2.122
                                      192.168.2.243
                                      192.168.2.123
                                      192.168.2.244
                                      192.168.2.120
                                      192.168.2.241
                                      192.168.2.121
                                      192.168.2.242
                                      192.168.2.97
                                      192.168.2.137
                                      192.168.2.96
                                      192.168.2.138
                                      192.168.2.99
                                      192.168.2.135
                                      192.168.2.98
                                      192.168.2.136
                                      192.168.2.139
                                      192.168.2.250
                                      192.168.2.130
                                      192.168.2.251
                                      192.168.2.91
                                      192.168.2.90
                                      192.168.2.93
                                      192.168.2.133
                                      192.168.2.254
                                      192.168.2.92
                                      192.168.2.134
                                      192.168.2.95
                                      192.168.2.131
                                      192.168.2.252
                                      192.168.2.94
                                      192.168.2.132
                                      192.168.2.253
                                      192.168.2.104
                                      192.168.2.225
                                      Joe Sandbox version:42.0.0 Malachite
                                      Analysis ID:1591279
                                      Start date and time:2025-01-14 21:05:37 +01:00
                                      Joe Sandbox product:CloudBasic
                                      Overall analysis duration:0h 4m 25s
                                      Hypervisor based Inspection enabled:false
                                      Report type:full
                                      Cookbook file name:default.jbs
                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                      Number of analysed new started processes analysed:16
                                      Number of new started drivers analysed:0
                                      Number of existing processes analysed:0
                                      Number of existing drivers analysed:0
                                      Number of injected processes analysed:0
                                      Technologies:
                                      • HCA enabled
                                      • EGA enabled
                                      • AMSI enabled
                                      Analysis Mode:default
                                      Analysis stop reason:Timeout
                                      Sample name:sUlHfYQxNw.dll
                                      renamed because original name is a hash value
                                      Original Sample Name:68165b3d89166ec828062f5c356e0e1b.dll
                                      Detection:MAL
                                      Classification:mal100.rans.expl.evad.winDLL@18/2@2/100
                                      EGA Information:
                                      • Successful, ratio: 100%
                                      HCA Information:Failed
                                      Cookbook Comments:
                                      • Found application associated with file extension: .dll
                                      • Stop behavior analysis, all processes terminated
                                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, conhost.exe
                                      • Excluded IPs from analysis (whitelisted): 2.17.190.73, 13.107.246.45, 20.109.210.53
                                      • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, azureedge-t-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
                                      • Not all processes where analyzed, report is missing behavior information
                                      • Report size getting too big, too many NtQueryValueKey calls found.
                                      TimeTypeDescription
                                      15:06:33API Interceptor1x Sleep call for process: loaddll32.exe modified
                                      15:07:08API Interceptor112x Sleep call for process: mssecsvr.exe modified
                                      No context
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      s-part-0017.t-0009.t-msedge.netlogitix.pdfGet hashmaliciousHTMLPhisherBrowse
                                      • 13.107.246.45
                                      DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.45
                                      DHL AWB CUSTOM CLEARANCE.xlsGet hashmaliciousUnknownBrowse
                                      • 13.107.246.45
                                      EFT_Payment_Notification_Gheenirrigation.htmlGet hashmaliciousHTMLPhisherBrowse
                                      • 13.107.246.45
                                      Document_31055.pdfGet hashmaliciousUnknownBrowse
                                      • 13.107.246.45
                                      MissedCall_Record_3295935663.htmlGet hashmaliciousUnknownBrowse
                                      • 13.107.246.45
                                      62.122.184.98 (2).ps1Get hashmaliciousUnknownBrowse
                                      • 13.107.246.45
                                      87.247.158.212.ps1Get hashmaliciousLummaCBrowse
                                      • 13.107.246.45
                                      ithDgrzsHr.exeGet hashmaliciousUnknownBrowse
                                      • 13.107.246.45
                                      http://pomservicing.co.uk/pomservicing/Smtb/dGVzdF9tYWlsQGVtYWlsLmpw==%C3%A3%E2%82%AC%E2%80%9A$$%C3%A3%E2%82%AC%E2%80%9A/1/010001943914714a-a13d10fa-2f31-4a50-b2fa-f3854398d733-000000/CAe7zeJgIBBw_nSVrUkbbcG65_c=407Get hashmaliciousHTMLPhisherBrowse
                                      • 13.107.246.45
                                      77026.bodis.commlfk8sYaiy.dllGet hashmaliciousWannacryBrowse
                                      • 199.59.243.228
                                      jgd5ZGl1vA.dllGet hashmaliciousWannacryBrowse
                                      • 199.59.243.228
                                      8dPlV2lT8o.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      7ObLFE2iMK.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      UMwpXhA46R.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      1fWgBXPgiT.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      arxtPs1STE.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      Z8eHwAvqAh.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      WlCVLbzNph.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      Bpfz752pYZ.exeGet hashmaliciousSimda StealerBrowse
                                      • 199.59.243.227
                                      www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.commlfk8sYaiy.dllGet hashmaliciousWannacryBrowse
                                      • 103.224.212.215
                                      jgd5ZGl1vA.dllGet hashmaliciousWannacryBrowse
                                      • 103.224.212.215
                                      LisectAVT_2403002A_327.dllGet hashmaliciousWannacryBrowse
                                      • 103.224.212.215
                                      yrBA01LVo2.exeGet hashmaliciousWannacryBrowse
                                      • 103.224.212.215
                                      lJt3mQqCQl.dllGet hashmaliciousWannacryBrowse
                                      • 103.224.212.220
                                      xIwkOnjSIa.dllGet hashmaliciousWannacryBrowse
                                      • 103.224.212.220
                                      IU28r0EZFA.dllGet hashmaliciousWannacryBrowse
                                      • 103.224.212.220
                                      ViNIRfmQmE.dllGet hashmaliciousWannacryBrowse
                                      • 103.224.212.220
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      HP-INTERNET-ASUShttps://4efd-190-162-38-36.ngrok-free.app/c4362ded87174b295ab48d90984741d52be4c31e.pdfGet hashmaliciousUnknownBrowse
                                      • 15.156.138.222
                                      https://email.analystratings.net/ls/click?upn=u001.WeKo-2BCuHku2kJmVIsYmGxsYmJ5tlN1JIFNOQtoSEGkLgECYxMchW4UXMllXUALJmesTsjgTR1H-2FvUTVSSAEe4R1GQy-2Bvbd8Zmmy4leDYmh9UNV6oDPX-2BT4wzcyKrfAdXvv6hKSBoru3q77depPs43qOB1DgUqmMdQP-2BNz7H62jYGp-2BH9nmpPKVjXmtKn9w5STVYGL4aqMBL65ruXSYeXZw-3D-3Didct_tUVFAbhJxF44ufbifaYzyYApcQooCC4WsuZoiwe419OCcA-2Bhorh4noX10R0htjc0oQD2shNvY2qd7sBvACS4ZxcOvRGqgf-2FzJzWjtjVb7R-2Fc1EPJdReLV-2BtujCvON-2Bc7V1MBDoLDS-2FjF655eEyLK512HQYbp-2FAbQ3P7q3sD01OmQtuWrJdDi7i9EqNYnB7vGsmi9YvC3tf2fi-2F59j5CgE2Yo8KxAbs4pwwxMvCRmFfOK49lsAVAfn3guJ7HTuaWXGet hashmaliciousUnknownBrowse
                                      • 15.156.12.46
                                      miori.ppc.elfGet hashmaliciousUnknownBrowse
                                      • 15.244.156.229
                                      miori.x86.elfGet hashmaliciousUnknownBrowse
                                      • 15.252.68.111
                                      miori.arm5.elfGet hashmaliciousUnknownBrowse
                                      • 15.136.34.126
                                      Mes_Drivers_3.0.4.exeGet hashmaliciousUnknownBrowse
                                      • 15.204.189.240
                                      Fantazy.sh4.elfGet hashmaliciousUnknownBrowse
                                      • 156.153.204.166
                                      armv6l.elfGet hashmaliciousUnknownBrowse
                                      • 16.143.138.218
                                      DF2.exeGet hashmaliciousUnknownBrowse
                                      • 15.204.11.249
                                      vcimanagement.armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      • 156.152.214.245
                                      HP-INTERNET-ASUShttps://4efd-190-162-38-36.ngrok-free.app/c4362ded87174b295ab48d90984741d52be4c31e.pdfGet hashmaliciousUnknownBrowse
                                      • 15.156.138.222
                                      https://email.analystratings.net/ls/click?upn=u001.WeKo-2BCuHku2kJmVIsYmGxsYmJ5tlN1JIFNOQtoSEGkLgECYxMchW4UXMllXUALJmesTsjgTR1H-2FvUTVSSAEe4R1GQy-2Bvbd8Zmmy4leDYmh9UNV6oDPX-2BT4wzcyKrfAdXvv6hKSBoru3q77depPs43qOB1DgUqmMdQP-2BNz7H62jYGp-2BH9nmpPKVjXmtKn9w5STVYGL4aqMBL65ruXSYeXZw-3D-3Didct_tUVFAbhJxF44ufbifaYzyYApcQooCC4WsuZoiwe419OCcA-2Bhorh4noX10R0htjc0oQD2shNvY2qd7sBvACS4ZxcOvRGqgf-2FzJzWjtjVb7R-2Fc1EPJdReLV-2BtujCvON-2Bc7V1MBDoLDS-2FjF655eEyLK512HQYbp-2FAbQ3P7q3sD01OmQtuWrJdDi7i9EqNYnB7vGsmi9YvC3tf2fi-2F59j5CgE2Yo8KxAbs4pwwxMvCRmFfOK49lsAVAfn3guJ7HTuaWXGet hashmaliciousUnknownBrowse
                                      • 15.156.12.46
                                      miori.ppc.elfGet hashmaliciousUnknownBrowse
                                      • 15.244.156.229
                                      miori.x86.elfGet hashmaliciousUnknownBrowse
                                      • 15.252.68.111
                                      miori.arm5.elfGet hashmaliciousUnknownBrowse
                                      • 15.136.34.126
                                      Mes_Drivers_3.0.4.exeGet hashmaliciousUnknownBrowse
                                      • 15.204.189.240
                                      Fantazy.sh4.elfGet hashmaliciousUnknownBrowse
                                      • 156.153.204.166
                                      armv6l.elfGet hashmaliciousUnknownBrowse
                                      • 16.143.138.218
                                      DF2.exeGet hashmaliciousUnknownBrowse
                                      • 15.204.11.249
                                      vcimanagement.armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      • 156.152.214.245
                                      OnlineSASFRTiOWA908TP.exeGet hashmaliciousUnknownBrowse
                                      • 51.159.14.89
                                      TiOWA908TP.exeGet hashmaliciousUnknownBrowse
                                      • 51.159.14.89
                                      TiOWA908TP.exeGet hashmaliciousUnknownBrowse
                                      • 51.159.14.89
                                      TiOWA908TP.exeGet hashmaliciousUnknownBrowse
                                      • 51.159.14.89
                                      TiOWA908TP.exeGet hashmaliciousUnknownBrowse
                                      • 51.159.14.89
                                      http://aeromorning.comGet hashmaliciousUnknownBrowse
                                      • 212.129.3.113
                                      12E56QE1Fc.exeGet hashmaliciousAzorultBrowse
                                      • 51.15.142.235
                                      4.elfGet hashmaliciousUnknownBrowse
                                      • 51.158.21.37
                                      miori.sh4.elfGet hashmaliciousUnknownBrowse
                                      • 212.129.5.22
                                      https://antiphishing.vadesecure.com/v4?f=bnJjU3hQT3pQSmNQZVE3aOMl-Yxz6sxP-_mvIRuY-wdnZ1bXTFIOIwMxyCDi0KedKx4XzS44_P2zUeNIsKUb0ScW6k1yl1_sQ4IsBBcClSw_vWV34HFG0fKKBNYTYHpo&i=SGI0YVJGNmxZNE90Z2thMHUqf298Dc88cJEXrW3w1lA&k=dFBm&r=SW5LV3JodE9QZkRVZ3JEYa6kbR5XAzhHFJ0zbTQRADrRG7ugnfE15pwrEQUVhgv3E2tVXwBw8NfFSkf3wOZ0VA&s=ecaab139c1f3315ccc0d88a6451dccec431e8ce1d856e71e5109e33657c13a3c&u=https%3A%2F%2Fsender5.zohoinsights-crm.com%2Fck1%2F2d6f.327230a%2F5f929700-cca4-11ef-973d-525400f92481%2F4cb2ae4047e7a38310b2b2641663917c123a5dec%2F2%3Fe%3DGKxHQ%252FSSm8D%252B%252B3g8VEcICaLHKdekhRU94ImygZ37tRI%253DGet hashmaliciousUnknownBrowse
                                      • 163.172.240.109
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      1138de370e523e824bbca92d049a3777MK9UBUl8t7.dllGet hashmaliciousWannacryBrowse
                                      • 23.206.229.209
                                      mCgW5qofxC.dllGet hashmaliciousWannacryBrowse
                                      • 23.206.229.209
                                      http://titanys.mindsetmatters.buzzGet hashmaliciousScreenConnect ToolBrowse
                                      • 23.206.229.209
                                      Document_31055.pdfGet hashmaliciousUnknownBrowse
                                      • 23.206.229.209
                                      Payment Receipt.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                                      • 23.206.229.209
                                      https://microsoft-visio.en.softonic.com/Get hashmaliciousUnknownBrowse
                                      • 23.206.229.209
                                      Subscription_Renewal_Receipt_2025.htmGet hashmaliciousHTMLPhisherBrowse
                                      • 23.206.229.209
                                      https://forms.office.com/e/xknrfCPQkRGet hashmaliciousHTMLPhisherBrowse
                                      • 23.206.229.209
                                      https://github.com/MscrmTools/XrmToolBox/releases/download/v1.2024.9.69/XrmToolbox.zipGet hashmaliciousUnknownBrowse
                                      • 23.206.229.209
                                      https://bccab.dynartis.it/TI_loc.csvGet hashmaliciousUnknownBrowse
                                      • 23.206.229.209
                                      No context
                                      Process:C:\Windows\mssecsvr.exe
                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):2061938
                                      Entropy (8bit):6.646184840465622
                                      Encrypted:false
                                      SSDEEP:24576:tiBclNmD8kIqRYoAdNLKz6626M+vbOSSqTPVXmiHkQg6eX6SASk+RdhAdmvm:N21INRx+TSqTdX1HkQo6SAARdhnvm
                                      MD5:C1F591A38185090B5A668B926DEA47CF
                                      SHA1:C6C6521F772E046BDEDC319A2198D452871D441C
                                      SHA-256:7FB287D17B7F1A87EB97F1DF23BAB6B9950BD28B4E9FA17C300F590543F8A329
                                      SHA-512:1B8A020BC170D3D11F677DDE442F4557272920911C8AB399CB0E535A2466AFC72E9C363601092678E3D1065F99D43CFC2BC3A200669F1D4479604454614134BA
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: ReversingLabs, Detection: 65%
                                      Reputation:low
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Windows\mssecsvr.exe
                                      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                      Category:dropped
                                      Size (bytes):2061938
                                      Entropy (8bit):6.646184840465622
                                      Encrypted:false
                                      SSDEEP:24576:tiBclNmD8kIqRYoAdNLKz6626M+vbOSSqTPVXmiHkQg6eX6SASk+RdhAdmvm:N21INRx+TSqTdX1HkQo6SAARdhnvm
                                      MD5:C1F591A38185090B5A668B926DEA47CF
                                      SHA1:C6C6521F772E046BDEDC319A2198D452871D441C
                                      SHA-256:7FB287D17B7F1A87EB97F1DF23BAB6B9950BD28B4E9FA17C300F590543F8A329
                                      SHA-512:1B8A020BC170D3D11F677DDE442F4557272920911C8AB399CB0E535A2466AFC72E9C363601092678E3D1065F99D43CFC2BC3A200669F1D4479604454614134BA
                                      Malicious:true
                                      Antivirus:
                                      • Antivirus: Joe Sandbox ML, Detection: 100%
                                      • Antivirus: ReversingLabs, Detection: 65%
                                      Reputation:low
                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                      File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                      Entropy (8bit):5.582594818250169
                                      TrID:
                                      • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                                      • Generic Win/DOS Executable (2004/3) 0.20%
                                      • DOS Executable Generic (2002/1) 0.20%
                                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                      File name:sUlHfYQxNw.dll
                                      File size:5'267'459 bytes
                                      MD5:68165b3d89166ec828062f5c356e0e1b
                                      SHA1:208485739bbab56c7998f952c3d742527cfdeeb7
                                      SHA256:22085c67126368a27c68cb62a147c0895f3e4d76d30c704952dcd356cf68b53f
                                      SHA512:b04f5d2f10dacf178223c2a2eebe9ba626ba74a13a534131bb88df2c1f39fb75f4cc4554d9d8435595b53a77a1ca489873c0e2792b8e738a110a8d881788feb5
                                      SSDEEP:49152:nnH21INRx+TSqTdX1HkQo6SAARdhnvxJM0H9PAMEcaEau3RCgHAD:nH21aRxcSUDk36SAEdhvxWa9P593R
                                      TLSH:80362346ED08D679D16A0A7045B30F2AB3A138EDC3A7285E935C5EE50DD37A337C2A1D
                                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}.r_9...9...9.......=...9...6.....A.:.......8.......8.......:...Rich9...........................PE..L...QW.Y...........!.......
                                      Icon Hash:7ae282899bbab082
                                      Entrypoint:0x100011e9
                                      Entrypoint Section:.text
                                      Digitally signed:false
                                      Imagebase:0x10000000
                                      Subsystem:windows gui
                                      Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                                      DLL Characteristics:
                                      Time Stamp:0x59145751 [Thu May 11 12:21:37 2017 UTC]
                                      TLS Callbacks:
                                      CLR (.Net) Version:
                                      OS Version Major:4
                                      OS Version Minor:0
                                      File Version Major:4
                                      File Version Minor:0
                                      Subsystem Version Major:4
                                      Subsystem Version Minor:0
                                      Import Hash:2e5708ae5fed0403e8117c645fb23e5b
                                      Instruction
                                      push ebp
                                      mov ebp, esp
                                      push ebx
                                      mov ebx, dword ptr [ebp+08h]
                                      push esi
                                      mov esi, dword ptr [ebp+0Ch]
                                      push edi
                                      mov edi, dword ptr [ebp+10h]
                                      test esi, esi
                                      jne 00007FDCD904B5BBh
                                      cmp dword ptr [10003140h], 00000000h
                                      jmp 00007FDCD904B5D8h
                                      cmp esi, 01h
                                      je 00007FDCD904B5B7h
                                      cmp esi, 02h
                                      jne 00007FDCD904B5D4h
                                      mov eax, dword ptr [10003150h]
                                      test eax, eax
                                      je 00007FDCD904B5BBh
                                      push edi
                                      push esi
                                      push ebx
                                      call eax
                                      test eax, eax
                                      je 00007FDCD904B5BEh
                                      push edi
                                      push esi
                                      push ebx
                                      call 00007FDCD904B4CAh
                                      test eax, eax
                                      jne 00007FDCD904B5B6h
                                      xor eax, eax
                                      jmp 00007FDCD904B600h
                                      push edi
                                      push esi
                                      push ebx
                                      call 00007FDCD904B37Ch
                                      cmp esi, 01h
                                      mov dword ptr [ebp+0Ch], eax
                                      jne 00007FDCD904B5BEh
                                      test eax, eax
                                      jne 00007FDCD904B5E9h
                                      push edi
                                      push eax
                                      push ebx
                                      call 00007FDCD904B4A6h
                                      test esi, esi
                                      je 00007FDCD904B5B7h
                                      cmp esi, 03h
                                      jne 00007FDCD904B5D8h
                                      push edi
                                      push esi
                                      push ebx
                                      call 00007FDCD904B495h
                                      test eax, eax
                                      jne 00007FDCD904B5B5h
                                      and dword ptr [ebp+0Ch], eax
                                      cmp dword ptr [ebp+0Ch], 00000000h
                                      je 00007FDCD904B5C3h
                                      mov eax, dword ptr [10003150h]
                                      test eax, eax
                                      je 00007FDCD904B5BAh
                                      push edi
                                      push esi
                                      push ebx
                                      call eax
                                      mov dword ptr [ebp+0Ch], eax
                                      mov eax, dword ptr [ebp+0Ch]
                                      pop edi
                                      pop esi
                                      pop ebx
                                      pop ebp
                                      retn 000Ch
                                      jmp dword ptr [10002028h]
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      add byte ptr [eax], al
                                      Programming Language:
                                      • [ C ] VS98 (6.0) build 8168
                                      • [C++] VS98 (6.0) build 8168
                                      • [RES] VS98 (6.0) cvtres build 1720
                                      • [LNK] VS98 (6.0) imp/exp build 8168
                                      NameVirtual AddressVirtual Size Is in Section
                                      IMAGE_DIRECTORY_ENTRY_EXPORT0x21900x48.rdata
                                      IMAGE_DIRECTORY_ENTRY_IMPORT0x203c0x3c.rdata
                                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x40000x500060.rsrc
                                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x5050000x5c.reloc
                                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                      IMAGE_DIRECTORY_ENTRY_IAT0x20000x3c.rdata
                                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                      .text0x10000x28c0x10008de9a2cb31e4c74bd008b871d14bfafcFalse0.13037109375data1.4429971244731552IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                      .rdata0x20000x1d80x10003dd394f95ab218593f2bc8eb65184db4False0.072509765625data0.7346018133622799IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                      .data0x30000x1540x10009b27c3f254416f775f5a51102ef8fb84False0.016845703125Matlab v4 mat-file (little endian) C:\%s\%s, numeric, rows 0, columns 00.085726967663312IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                      .rsrc0x40000x5000600x5010002834f3542e987c2fc907ff7445fb2e4aunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                      .reloc0x5050000x2ac0x1000620f0b67a91f7f74151bc5be745b7110False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                      NameRVASizeTypeLanguageCountryZLIB Complexity
                                      W0x40600x500000dataEnglishUnited States0.3548316955566406
                                      DLLImport
                                      KERNEL32.dllCloseHandle, WriteFile, CreateFileA, SizeofResource, LockResource, LoadResource, FindResourceA, CreateProcessA
                                      MSVCRT.dllfree, _initterm, malloc, _adjust_fdiv, sprintf
                                      NameOrdinalAddress
                                      PlayGame10x10001114
                                      Language of compilation systemCountry where language is spokenMap
                                      EnglishUnited States
                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                      2025-01-14T21:06:31.993258+01002830018ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup)1192.168.2.9580341.1.1.153UDP
                                      2025-01-14T21:06:32.939526+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.949742103.224.212.21580TCP
                                      2025-01-14T21:06:34.454699+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.949754103.224.212.21580TCP
                                      TimestampSource PortDest PortSource IPDest IP
                                      Jan 14, 2025 21:06:24.740194082 CET49677443192.168.2.920.189.173.11
                                      Jan 14, 2025 21:06:24.787090063 CET49676443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:25.427637100 CET49675443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:25.646358967 CET49674443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:27.146439075 CET49677443192.168.2.920.189.173.11
                                      Jan 14, 2025 21:06:31.958874941 CET49677443192.168.2.920.189.173.11
                                      Jan 14, 2025 21:06:32.315320969 CET4974280192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:32.320161104 CET8049742103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:32.320235968 CET4974280192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:32.322264910 CET4974280192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:32.327004910 CET8049742103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:32.939353943 CET8049742103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:32.939435005 CET8049742103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:32.939526081 CET4974280192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:32.947190046 CET4974280192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:32.952008963 CET8049742103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:33.132075071 CET4974880192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:33.136928082 CET8049748199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:33.136991024 CET4974880192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:33.138122082 CET4974880192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:33.142961025 CET8049748199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:33.161971092 CET49673443192.168.2.9204.79.197.203
                                      Jan 14, 2025 21:06:33.599946022 CET8049748199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:33.599968910 CET8049748199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:33.600034952 CET4974880192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:33.600034952 CET4974880192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:33.605577946 CET4974880192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:33.605577946 CET4974880192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:33.825721979 CET4975480192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:33.830563068 CET8049754103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:33.830634117 CET4975480192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:33.830791950 CET4975480192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:33.835545063 CET8049754103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:34.454596996 CET8049754103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:34.454699039 CET4975480192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:34.454747915 CET8049754103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:34.454816103 CET4975480192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:34.536020041 CET4975480192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:34.540851116 CET8049754103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:34.578728914 CET4976080192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:34.582751989 CET4976180192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:34.584099054 CET8049760103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:34.584177971 CET4976080192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:34.584914923 CET4976080192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:34.588551998 CET8049761199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:34.588655949 CET4976180192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:34.588896036 CET4976180192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:34.590177059 CET8049760103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:34.594305038 CET8049761199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:35.037007093 CET49675443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:35.044425011 CET8049761199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:35.044482946 CET8049761199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:35.044569969 CET4976180192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.075468063 CET4976180192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.075644016 CET4976180192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.170909882 CET49766445192.168.2.93.157.171.223
                                      Jan 14, 2025 21:06:35.175817013 CET445497663.157.171.223192.168.2.9
                                      Jan 14, 2025 21:06:35.176146984 CET49766445192.168.2.93.157.171.223
                                      Jan 14, 2025 21:06:35.176259995 CET49766445192.168.2.93.157.171.223
                                      Jan 14, 2025 21:06:35.178821087 CET49767445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:35.181272984 CET445497663.157.171.223192.168.2.9
                                      Jan 14, 2025 21:06:35.181400061 CET49766445192.168.2.93.157.171.223
                                      Jan 14, 2025 21:06:35.183662891 CET445497673.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:35.183739901 CET49767445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:35.183778048 CET49767445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:35.187822104 CET49768445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:35.188924074 CET445497673.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:35.189090967 CET49767445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:35.192774057 CET445497683.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:35.192858934 CET49768445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:35.192919016 CET49768445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:35.193245888 CET8049760103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:35.193319082 CET4976080192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:35.193530083 CET8049760103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:35.193955898 CET4976080192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:35.195910931 CET4976080192.168.2.9103.224.212.215
                                      Jan 14, 2025 21:06:35.197117090 CET4976980192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.197730064 CET445497683.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:35.200869083 CET8049760103.224.212.215192.168.2.9
                                      Jan 14, 2025 21:06:35.202164888 CET8049769199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:35.202225924 CET4976980192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.204560995 CET4976980192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.209419966 CET8049769199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:35.255755901 CET49674443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:35.670603037 CET8049769199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:35.670659065 CET8049769199.59.243.228192.168.2.9
                                      Jan 14, 2025 21:06:35.670691013 CET4976980192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.670741081 CET4976980192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.690795898 CET4976980192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:35.690845966 CET4976980192.168.2.9199.59.243.228
                                      Jan 14, 2025 21:06:36.966717005 CET4434970423.206.229.209192.168.2.9
                                      Jan 14, 2025 21:06:36.966816902 CET49704443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:37.166918039 CET49803445192.168.2.9116.209.81.210
                                      Jan 14, 2025 21:06:37.171705008 CET44549803116.209.81.210192.168.2.9
                                      Jan 14, 2025 21:06:37.172028065 CET49803445192.168.2.9116.209.81.210
                                      Jan 14, 2025 21:06:37.172028065 CET49803445192.168.2.9116.209.81.210
                                      Jan 14, 2025 21:06:37.172326088 CET49804445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:37.177057028 CET44549804116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:06:37.177124977 CET49804445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:37.177186012 CET49804445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:37.177294970 CET44549803116.209.81.210192.168.2.9
                                      Jan 14, 2025 21:06:37.177337885 CET49803445192.168.2.9116.209.81.210
                                      Jan 14, 2025 21:06:37.178433895 CET49805445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:37.182193041 CET44549804116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:06:37.182369947 CET49804445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:37.183252096 CET44549805116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:06:37.183322906 CET49805445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:37.183377981 CET49805445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:37.188306093 CET44549805116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:06:39.179359913 CET49842445192.168.2.915.212.96.173
                                      Jan 14, 2025 21:06:39.184403896 CET4454984215.212.96.173192.168.2.9
                                      Jan 14, 2025 21:06:39.184531927 CET49842445192.168.2.915.212.96.173
                                      Jan 14, 2025 21:06:39.184684992 CET49842445192.168.2.915.212.96.173
                                      Jan 14, 2025 21:06:39.185048103 CET49843445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:06:39.189821959 CET4454984215.212.96.173192.168.2.9
                                      Jan 14, 2025 21:06:39.189884901 CET49842445192.168.2.915.212.96.173
                                      Jan 14, 2025 21:06:39.190125942 CET4454984315.212.96.1192.168.2.9
                                      Jan 14, 2025 21:06:39.190329075 CET49843445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:06:39.190329075 CET49843445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:06:39.191915989 CET49845445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:06:39.195710897 CET4454984315.212.96.1192.168.2.9
                                      Jan 14, 2025 21:06:39.195799112 CET49843445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:06:39.197213888 CET4454984515.212.96.1192.168.2.9
                                      Jan 14, 2025 21:06:39.197303057 CET49845445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:06:39.197514057 CET49845445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:06:39.202822924 CET4454984515.212.96.1192.168.2.9
                                      Jan 14, 2025 21:06:41.195209026 CET49881445192.168.2.9126.245.156.111
                                      Jan 14, 2025 21:06:41.200151920 CET44549881126.245.156.111192.168.2.9
                                      Jan 14, 2025 21:06:41.200249910 CET49881445192.168.2.9126.245.156.111
                                      Jan 14, 2025 21:06:41.200299978 CET49881445192.168.2.9126.245.156.111
                                      Jan 14, 2025 21:06:41.200511932 CET49882445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:06:41.205297947 CET44549882126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:06:41.205382109 CET49882445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:06:41.205431938 CET49882445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:06:41.206751108 CET49883445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:06:41.208266973 CET44549881126.245.156.111192.168.2.9
                                      Jan 14, 2025 21:06:41.211643934 CET44549883126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:06:41.211728096 CET49883445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:06:41.211793900 CET49883445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:06:41.212249041 CET44549882126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:06:41.216556072 CET44549883126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:06:41.224739075 CET44549881126.245.156.111192.168.2.9
                                      Jan 14, 2025 21:06:41.224809885 CET49881445192.168.2.9126.245.156.111
                                      Jan 14, 2025 21:06:41.225176096 CET44549882126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:06:41.225363016 CET49882445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:06:41.568260908 CET49677443192.168.2.920.189.173.11
                                      Jan 14, 2025 21:06:43.211929083 CET49915445192.168.2.9138.57.247.187
                                      Jan 14, 2025 21:06:43.216861963 CET44549915138.57.247.187192.168.2.9
                                      Jan 14, 2025 21:06:43.217083931 CET49915445192.168.2.9138.57.247.187
                                      Jan 14, 2025 21:06:43.217143059 CET49915445192.168.2.9138.57.247.187
                                      Jan 14, 2025 21:06:43.217411041 CET49916445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:06:43.222325087 CET44549916138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:06:43.222402096 CET49916445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:06:43.222434998 CET49916445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:06:43.223417044 CET49917445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:06:43.224277020 CET44549915138.57.247.187192.168.2.9
                                      Jan 14, 2025 21:06:43.228305101 CET44549917138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:06:43.228413105 CET49917445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:06:43.228490114 CET49917445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:06:43.231060982 CET44549915138.57.247.187192.168.2.9
                                      Jan 14, 2025 21:06:43.231122017 CET49915445192.168.2.9138.57.247.187
                                      Jan 14, 2025 21:06:43.231256962 CET44549916138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:06:43.231321096 CET49916445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:06:43.233376980 CET44549917138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:06:45.226035118 CET49953445192.168.2.9144.69.237.198
                                      Jan 14, 2025 21:06:45.230942965 CET44549953144.69.237.198192.168.2.9
                                      Jan 14, 2025 21:06:45.231040001 CET49953445192.168.2.9144.69.237.198
                                      Jan 14, 2025 21:06:45.231113911 CET49953445192.168.2.9144.69.237.198
                                      Jan 14, 2025 21:06:45.231379032 CET49954445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:06:45.236124992 CET44549953144.69.237.198192.168.2.9
                                      Jan 14, 2025 21:06:45.236191034 CET49953445192.168.2.9144.69.237.198
                                      Jan 14, 2025 21:06:45.236262083 CET44549954144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:06:45.236330032 CET49954445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:06:45.236354113 CET49954445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:06:45.237394094 CET49955445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:06:45.241255045 CET44549954144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:06:45.241323948 CET49954445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:06:45.242249012 CET44549955144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:06:45.242311001 CET49955445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:06:45.242347956 CET49955445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:06:45.247088909 CET44549955144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:06:47.078052044 CET49704443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:47.078052044 CET49704443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:47.078625917 CET49986443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:47.078694105 CET4434998623.206.229.209192.168.2.9
                                      Jan 14, 2025 21:06:47.079457045 CET49986443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:47.079999924 CET49986443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:47.080015898 CET4434998623.206.229.209192.168.2.9
                                      Jan 14, 2025 21:06:47.083101988 CET4434970423.206.229.209192.168.2.9
                                      Jan 14, 2025 21:06:47.083144903 CET4434970423.206.229.209192.168.2.9
                                      Jan 14, 2025 21:06:47.240596056 CET49991445192.168.2.934.81.201.226
                                      Jan 14, 2025 21:06:47.245517015 CET4454999134.81.201.226192.168.2.9
                                      Jan 14, 2025 21:06:47.245876074 CET49991445192.168.2.934.81.201.226
                                      Jan 14, 2025 21:06:47.245876074 CET49991445192.168.2.934.81.201.226
                                      Jan 14, 2025 21:06:47.245877981 CET49992445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:06:47.250946045 CET4454999234.81.201.1192.168.2.9
                                      Jan 14, 2025 21:06:47.251020908 CET49992445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:06:47.251059055 CET49992445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:06:47.251157045 CET4454999134.81.201.226192.168.2.9
                                      Jan 14, 2025 21:06:47.251360893 CET49993445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:06:47.251368999 CET49991445192.168.2.934.81.201.226
                                      Jan 14, 2025 21:06:47.255987883 CET4454999234.81.201.1192.168.2.9
                                      Jan 14, 2025 21:06:47.256078005 CET49992445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:06:47.256300926 CET4454999334.81.201.1192.168.2.9
                                      Jan 14, 2025 21:06:47.256371975 CET49993445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:06:47.256428957 CET49993445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:06:47.261259079 CET4454999334.81.201.1192.168.2.9
                                      Jan 14, 2025 21:06:47.731780052 CET4434998623.206.229.209192.168.2.9
                                      Jan 14, 2025 21:06:47.731898069 CET49986443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:06:49.256302118 CET50025445192.168.2.9199.83.239.113
                                      Jan 14, 2025 21:06:49.261053085 CET44550025199.83.239.113192.168.2.9
                                      Jan 14, 2025 21:06:49.261118889 CET50025445192.168.2.9199.83.239.113
                                      Jan 14, 2025 21:06:49.261183023 CET50025445192.168.2.9199.83.239.113
                                      Jan 14, 2025 21:06:49.261297941 CET50026445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:49.266050100 CET44550026199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:49.266103029 CET50026445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:49.266149044 CET50026445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:49.266256094 CET44550025199.83.239.113192.168.2.9
                                      Jan 14, 2025 21:06:49.266298056 CET50025445192.168.2.9199.83.239.113
                                      Jan 14, 2025 21:06:49.266453981 CET50027445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:49.271166086 CET44550026199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:49.271203041 CET50026445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:49.271214008 CET44550027199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:49.271270037 CET50027445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:49.271291018 CET50027445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:49.276066065 CET44550027199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:50.939702034 CET44550027199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:50.939769983 CET50027445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:50.939814091 CET50027445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:50.939824104 CET50027445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:50.944612026 CET44550027199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:50.944761992 CET44550027199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:51.272068977 CET50062445192.168.2.916.10.57.179
                                      Jan 14, 2025 21:06:51.276902914 CET4455006216.10.57.179192.168.2.9
                                      Jan 14, 2025 21:06:51.276972055 CET50062445192.168.2.916.10.57.179
                                      Jan 14, 2025 21:06:51.277028084 CET50062445192.168.2.916.10.57.179
                                      Jan 14, 2025 21:06:51.277255058 CET50063445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:06:51.282049894 CET4455006316.10.57.1192.168.2.9
                                      Jan 14, 2025 21:06:51.282119989 CET50063445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:06:51.282175064 CET50063445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:06:51.282279015 CET4455006216.10.57.179192.168.2.9
                                      Jan 14, 2025 21:06:51.282324076 CET50062445192.168.2.916.10.57.179
                                      Jan 14, 2025 21:06:51.282443047 CET50064445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:06:51.287245989 CET4455006416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:06:51.287257910 CET4455006316.10.57.1192.168.2.9
                                      Jan 14, 2025 21:06:51.287312984 CET50063445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:06:51.287319899 CET50064445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:06:51.287450075 CET50064445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:06:51.292253017 CET4455006416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:06:53.287383080 CET50099445192.168.2.968.234.13.186
                                      Jan 14, 2025 21:06:53.292284966 CET4455009968.234.13.186192.168.2.9
                                      Jan 14, 2025 21:06:53.292390108 CET50099445192.168.2.968.234.13.186
                                      Jan 14, 2025 21:06:53.292418003 CET50099445192.168.2.968.234.13.186
                                      Jan 14, 2025 21:06:53.292478085 CET50100445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:06:53.297302008 CET4455010068.234.13.1192.168.2.9
                                      Jan 14, 2025 21:06:53.297333956 CET4455009968.234.13.186192.168.2.9
                                      Jan 14, 2025 21:06:53.297369003 CET50100445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:06:53.297391891 CET50099445192.168.2.968.234.13.186
                                      Jan 14, 2025 21:06:53.297561884 CET50100445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:06:53.297975063 CET50101445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:06:53.302583933 CET4455010068.234.13.1192.168.2.9
                                      Jan 14, 2025 21:06:53.302664042 CET50100445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:06:53.302747011 CET4455010168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:06:53.302793980 CET50101445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:06:53.302823067 CET50101445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:06:53.307595015 CET4455010168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:06:53.943464994 CET50114445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:53.948304892 CET44550114199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:53.948401928 CET50114445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:53.948441029 CET50114445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:53.953257084 CET44550114199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:55.303224087 CET50137445192.168.2.977.120.13.118
                                      Jan 14, 2025 21:06:55.308386087 CET4455013777.120.13.118192.168.2.9
                                      Jan 14, 2025 21:06:55.308487892 CET50137445192.168.2.977.120.13.118
                                      Jan 14, 2025 21:06:55.308562994 CET50137445192.168.2.977.120.13.118
                                      Jan 14, 2025 21:06:55.308727026 CET50138445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:06:55.313512087 CET4455013777.120.13.118192.168.2.9
                                      Jan 14, 2025 21:06:55.313555002 CET4455013877.120.13.1192.168.2.9
                                      Jan 14, 2025 21:06:55.313585043 CET50137445192.168.2.977.120.13.118
                                      Jan 14, 2025 21:06:55.313625097 CET50138445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:06:55.313698053 CET50138445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:06:55.313971043 CET50139445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:06:55.318650007 CET4455013877.120.13.1192.168.2.9
                                      Jan 14, 2025 21:06:55.318701982 CET50138445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:06:55.318763018 CET4455013977.120.13.1192.168.2.9
                                      Jan 14, 2025 21:06:55.318821907 CET50139445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:06:55.318855047 CET50139445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:06:55.323585033 CET4455013977.120.13.1192.168.2.9
                                      Jan 14, 2025 21:06:55.456173897 CET44550114199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:55.456310987 CET50114445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:55.456310987 CET50114445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:55.456409931 CET50114445192.168.2.9199.83.239.1
                                      Jan 14, 2025 21:06:55.462426901 CET44550114199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:55.462440014 CET44550114199.83.239.1192.168.2.9
                                      Jan 14, 2025 21:06:55.521994114 CET50144445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:06:55.526901960 CET44550144199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:06:55.526961088 CET50144445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:06:55.527085066 CET50144445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:06:55.527370930 CET50145445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:06:55.531986952 CET44550144199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:06:55.532030106 CET50144445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:06:55.532201052 CET44550145199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:06:55.532249928 CET50145445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:06:55.532290936 CET50145445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:06:55.536990881 CET44550145199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:06:56.602248907 CET445497683.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:56.602329969 CET49768445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:56.602372885 CET49768445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:56.602432013 CET49768445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:56.607249022 CET445497683.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:56.607289076 CET445497683.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:57.318914890 CET50177445192.168.2.951.159.121.244
                                      Jan 14, 2025 21:06:57.323822021 CET4455017751.159.121.244192.168.2.9
                                      Jan 14, 2025 21:06:57.323913097 CET50177445192.168.2.951.159.121.244
                                      Jan 14, 2025 21:06:57.323981047 CET50177445192.168.2.951.159.121.244
                                      Jan 14, 2025 21:06:57.324081898 CET50179445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:06:57.328983068 CET4455017951.159.121.1192.168.2.9
                                      Jan 14, 2025 21:06:57.329056978 CET50179445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:06:57.329096079 CET50179445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:06:57.329123974 CET4455017751.159.121.244192.168.2.9
                                      Jan 14, 2025 21:06:57.329183102 CET50177445192.168.2.951.159.121.244
                                      Jan 14, 2025 21:06:57.329355955 CET50180445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:06:57.334244013 CET4455017951.159.121.1192.168.2.9
                                      Jan 14, 2025 21:06:57.334315062 CET4455018051.159.121.1192.168.2.9
                                      Jan 14, 2025 21:06:57.334314108 CET50179445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:06:57.334379911 CET50180445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:06:57.334422112 CET50180445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:06:57.339281082 CET4455018051.159.121.1192.168.2.9
                                      Jan 14, 2025 21:06:58.573316097 CET44549805116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:06:58.573385954 CET49805445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:58.573430061 CET49805445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:58.573489904 CET49805445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:06:58.578238964 CET44549805116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:06:58.578291893 CET44549805116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:06:59.334610939 CET50214445192.168.2.9222.113.31.86
                                      Jan 14, 2025 21:06:59.339553118 CET44550214222.113.31.86192.168.2.9
                                      Jan 14, 2025 21:06:59.339684963 CET50214445192.168.2.9222.113.31.86
                                      Jan 14, 2025 21:06:59.339729071 CET50214445192.168.2.9222.113.31.86
                                      Jan 14, 2025 21:06:59.339937925 CET50215445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:06:59.344805956 CET44550215222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:06:59.344922066 CET44550214222.113.31.86192.168.2.9
                                      Jan 14, 2025 21:06:59.344949961 CET50215445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:06:59.344949961 CET50215445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:06:59.344988108 CET50214445192.168.2.9222.113.31.86
                                      Jan 14, 2025 21:06:59.345417023 CET50216445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:06:59.350209951 CET44550215222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:06:59.350233078 CET44550216222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:06:59.350286961 CET50215445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:06:59.350322962 CET50216445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:06:59.350368023 CET50216445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:06:59.355165958 CET44550216222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:06:59.615489006 CET50220445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:59.621562958 CET445502203.157.171.1192.168.2.9
                                      Jan 14, 2025 21:06:59.621642113 CET50220445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:59.621692896 CET50220445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:06:59.627793074 CET445502203.157.171.1192.168.2.9
                                      Jan 14, 2025 21:07:00.585601091 CET4454984515.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:00.585675001 CET49845445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:00.585751057 CET49845445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:00.585827112 CET49845445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:00.590662003 CET4454984515.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:00.590675116 CET4454984515.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:01.350361109 CET50232445192.168.2.9150.135.181.70
                                      Jan 14, 2025 21:07:01.355521917 CET44550232150.135.181.70192.168.2.9
                                      Jan 14, 2025 21:07:01.355659962 CET50232445192.168.2.9150.135.181.70
                                      Jan 14, 2025 21:07:01.355696917 CET50232445192.168.2.9150.135.181.70
                                      Jan 14, 2025 21:07:01.355885983 CET50233445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:01.360852003 CET44550233150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:01.360891104 CET44550232150.135.181.70192.168.2.9
                                      Jan 14, 2025 21:07:01.360929966 CET50233445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:01.360960007 CET50232445192.168.2.9150.135.181.70
                                      Jan 14, 2025 21:07:01.361074924 CET50233445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:01.361438036 CET50234445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:01.366307974 CET44550233150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:01.366375923 CET50233445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:01.366588116 CET44550234150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:01.366662025 CET50234445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:01.366722107 CET50234445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:01.371514082 CET44550234150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:01.595710993 CET50237445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:07:01.600641012 CET44550237116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:07:01.600720882 CET50237445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:07:01.600914955 CET50237445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:07:01.605833054 CET44550237116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:07:02.584920883 CET44549883126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:02.585098028 CET49883445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:02.585098028 CET49883445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:02.585138083 CET49883445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:02.590991020 CET44549883126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:02.591027021 CET44549883126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:03.365673065 CET50249445192.168.2.9103.42.206.197
                                      Jan 14, 2025 21:07:03.370675087 CET44550249103.42.206.197192.168.2.9
                                      Jan 14, 2025 21:07:03.370812893 CET50249445192.168.2.9103.42.206.197
                                      Jan 14, 2025 21:07:03.370872974 CET50249445192.168.2.9103.42.206.197
                                      Jan 14, 2025 21:07:03.370920897 CET50250445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:03.375818968 CET44550250103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:03.375897884 CET50250445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:03.375927925 CET50250445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:03.375969887 CET44550249103.42.206.197192.168.2.9
                                      Jan 14, 2025 21:07:03.376035929 CET50249445192.168.2.9103.42.206.197
                                      Jan 14, 2025 21:07:03.376470089 CET50251445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:03.380934000 CET44550250103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:03.381005049 CET50250445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:03.381342888 CET44550251103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:03.381500959 CET50251445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:03.381500959 CET50251445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:03.386322021 CET44550251103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:03.600297928 CET50254445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:03.605274916 CET4455025415.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:03.605350018 CET50254445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:03.605415106 CET50254445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:03.610270977 CET4455025415.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:04.585298061 CET44549917138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:04.585413933 CET49917445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:04.585593939 CET49917445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:04.585593939 CET49917445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:04.591378927 CET44549917138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:04.591391087 CET44549917138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:05.381438017 CET50265445192.168.2.9181.171.88.204
                                      Jan 14, 2025 21:07:05.406852961 CET44550265181.171.88.204192.168.2.9
                                      Jan 14, 2025 21:07:05.406991959 CET50265445192.168.2.9181.171.88.204
                                      Jan 14, 2025 21:07:05.407128096 CET50265445192.168.2.9181.171.88.204
                                      Jan 14, 2025 21:07:05.407373905 CET50266445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:05.411953926 CET44550265181.171.88.204192.168.2.9
                                      Jan 14, 2025 21:07:05.412024021 CET50265445192.168.2.9181.171.88.204
                                      Jan 14, 2025 21:07:05.412204981 CET44550266181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:05.412261009 CET50266445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:05.412286043 CET50266445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:05.412609100 CET50267445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:05.417205095 CET44550266181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:05.417264938 CET50266445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:05.417462111 CET44550267181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:05.417524099 CET50267445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:05.417576075 CET50267445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:05.422398090 CET44550267181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:05.599931002 CET50270445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:05.604852915 CET44550270126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:05.604958057 CET50270445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:05.604999065 CET50270445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:05.609901905 CET44550270126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:06.600840092 CET44549955144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:06.601044893 CET49955445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:06.601046085 CET49955445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:06.601140022 CET49955445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:06.605962992 CET44549955144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:06.605974913 CET44549955144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:07.222497940 CET4434998623.206.229.209192.168.2.9
                                      Jan 14, 2025 21:07:07.222712040 CET49986443192.168.2.923.206.229.209
                                      Jan 14, 2025 21:07:07.256303072 CET44550267181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:07.256495953 CET50267445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:07.256496906 CET50267445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:07.256496906 CET50267445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:07.261708021 CET44550267181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:07.261739969 CET44550267181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:07.400202036 CET50282445192.168.2.952.145.247.111
                                      Jan 14, 2025 21:07:07.405515909 CET4455028252.145.247.111192.168.2.9
                                      Jan 14, 2025 21:07:07.405596972 CET50282445192.168.2.952.145.247.111
                                      Jan 14, 2025 21:07:07.405697107 CET50282445192.168.2.952.145.247.111
                                      Jan 14, 2025 21:07:07.405869961 CET50283445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:07.411056995 CET4455028352.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:07.411185026 CET50283445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:07.411237955 CET4455028252.145.247.111192.168.2.9
                                      Jan 14, 2025 21:07:07.411254883 CET50283445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:07.411298037 CET50282445192.168.2.952.145.247.111
                                      Jan 14, 2025 21:07:07.414243937 CET50284445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:07.416518927 CET4455028352.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:07.416569948 CET50283445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:07.418983936 CET4455028452.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:07.419054985 CET50284445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:07.419126034 CET50284445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:07.424412012 CET4455028452.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:07.600502014 CET50287445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:07.605284929 CET44550287138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:07.605400085 CET50287445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:07.607326984 CET50287445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:07.612142086 CET44550287138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:08.679481030 CET4454999334.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:08.679568052 CET49993445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:08.679610014 CET49993445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:08.679636955 CET49993445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:08.684462070 CET4454999334.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:08.684469938 CET4454999334.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:09.412564993 CET50297445192.168.2.9186.17.232.223
                                      Jan 14, 2025 21:07:09.417356014 CET44550297186.17.232.223192.168.2.9
                                      Jan 14, 2025 21:07:09.418178082 CET50297445192.168.2.9186.17.232.223
                                      Jan 14, 2025 21:07:09.418234110 CET50297445192.168.2.9186.17.232.223
                                      Jan 14, 2025 21:07:09.418343067 CET50298445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:09.423067093 CET44550298186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:09.423140049 CET44550297186.17.232.223192.168.2.9
                                      Jan 14, 2025 21:07:09.423209906 CET50297445192.168.2.9186.17.232.223
                                      Jan 14, 2025 21:07:09.423223019 CET50298445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:09.423343897 CET50298445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:09.423602104 CET50299445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:09.428159952 CET44550298186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:09.428407907 CET44550299186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:09.428456068 CET50298445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:09.428479910 CET50299445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:09.428544044 CET50299445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:09.433253050 CET44550299186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:09.615710020 CET50300445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:09.620532990 CET44550300144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:09.620630980 CET50300445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:09.620695114 CET50300445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:09.625505924 CET44550300144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:10.271790981 CET50301445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:10.276896954 CET44550301181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:10.277040005 CET50301445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:10.277091026 CET50301445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:10.281927109 CET44550301181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:11.287533045 CET50302445192.168.2.950.121.163.147
                                      Jan 14, 2025 21:07:11.292783976 CET4455030250.121.163.147192.168.2.9
                                      Jan 14, 2025 21:07:11.292870045 CET50302445192.168.2.950.121.163.147
                                      Jan 14, 2025 21:07:11.292893887 CET50302445192.168.2.950.121.163.147
                                      Jan 14, 2025 21:07:11.293056965 CET50303445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:11.297878981 CET4455030250.121.163.147192.168.2.9
                                      Jan 14, 2025 21:07:11.297986031 CET50302445192.168.2.950.121.163.147
                                      Jan 14, 2025 21:07:11.298027992 CET4455030350.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:11.298096895 CET50303445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:11.298151970 CET50303445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:11.298392057 CET50304445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:11.303286076 CET4455030350.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:11.303302050 CET4455030450.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:11.303356886 CET50303445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:11.303383112 CET50304445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:11.303405046 CET50304445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:11.308873892 CET4455030450.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:11.693725109 CET50305445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:11.698611021 CET4455030534.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:11.701180935 CET50305445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:11.701203108 CET50305445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:11.705986977 CET4455030534.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:12.178122997 CET44550301181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:12.178263903 CET50301445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:12.178311110 CET50301445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:12.178311110 CET50301445192.168.2.9181.171.88.1
                                      Jan 14, 2025 21:07:12.183192015 CET44550301181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:12.183203936 CET44550301181.171.88.1192.168.2.9
                                      Jan 14, 2025 21:07:12.240653992 CET50306445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:12.245734930 CET44550306181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:12.245836973 CET50306445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:12.245862007 CET50306445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:12.246256113 CET50307445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:12.250823021 CET44550306181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:12.250897884 CET50306445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:12.251094103 CET44550307181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:12.251159906 CET50307445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:12.251204967 CET50307445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:12.256023884 CET44550307181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:12.698312998 CET4455006416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:12.698424101 CET50064445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:12.698462009 CET50064445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:12.698487043 CET50064445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:12.703272104 CET4455006416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:12.703282118 CET4455006416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:13.037676096 CET50308445192.168.2.963.166.202.107
                                      Jan 14, 2025 21:07:13.043298960 CET4455030863.166.202.107192.168.2.9
                                      Jan 14, 2025 21:07:13.043425083 CET50308445192.168.2.963.166.202.107
                                      Jan 14, 2025 21:07:13.043451071 CET50308445192.168.2.963.166.202.107
                                      Jan 14, 2025 21:07:13.043623924 CET50309445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:13.048947096 CET4455030963.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:13.049038887 CET50309445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:13.049067974 CET4455030863.166.202.107192.168.2.9
                                      Jan 14, 2025 21:07:13.049115896 CET50308445192.168.2.963.166.202.107
                                      Jan 14, 2025 21:07:13.049144030 CET50309445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:13.049416065 CET50310445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:13.054744005 CET4455031063.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:13.054755926 CET4455030963.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:13.054804087 CET50310445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:13.054827929 CET50309445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:13.054876089 CET50310445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:13.060184002 CET4455031063.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:14.678436041 CET50311445192.168.2.971.110.186.84
                                      Jan 14, 2025 21:07:14.683391094 CET4455031171.110.186.84192.168.2.9
                                      Jan 14, 2025 21:07:14.683460951 CET50311445192.168.2.971.110.186.84
                                      Jan 14, 2025 21:07:14.683497906 CET50311445192.168.2.971.110.186.84
                                      Jan 14, 2025 21:07:14.683636904 CET50312445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:14.684411049 CET4455010168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:07:14.684470892 CET50101445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:14.684500933 CET50101445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:14.684530020 CET50101445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:14.688472033 CET4455031271.110.186.1192.168.2.9
                                      Jan 14, 2025 21:07:14.688486099 CET4455031171.110.186.84192.168.2.9
                                      Jan 14, 2025 21:07:14.688590050 CET50311445192.168.2.971.110.186.84
                                      Jan 14, 2025 21:07:14.688605070 CET50312445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:14.688944101 CET50313445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:14.689287901 CET4455010168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:07:14.689297915 CET4455010168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:07:14.693559885 CET4455031271.110.186.1192.168.2.9
                                      Jan 14, 2025 21:07:14.693722963 CET50312445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:14.693746090 CET4455031371.110.186.1192.168.2.9
                                      Jan 14, 2025 21:07:14.693803072 CET50313445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:14.693836927 CET50313445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:14.698662043 CET4455031371.110.186.1192.168.2.9
                                      Jan 14, 2025 21:07:15.709264040 CET50314445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:15.714234114 CET4455031416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:15.714303970 CET50314445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:15.714337111 CET50314445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:15.719111919 CET4455031416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:16.210197926 CET50315445192.168.2.9120.193.75.236
                                      Jan 14, 2025 21:07:16.215066910 CET44550315120.193.75.236192.168.2.9
                                      Jan 14, 2025 21:07:16.215190887 CET50315445192.168.2.9120.193.75.236
                                      Jan 14, 2025 21:07:16.215326071 CET50315445192.168.2.9120.193.75.236
                                      Jan 14, 2025 21:07:16.215337038 CET50316445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:16.220112085 CET44550316120.193.75.1192.168.2.9
                                      Jan 14, 2025 21:07:16.220212936 CET50316445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:16.220216990 CET44550315120.193.75.236192.168.2.9
                                      Jan 14, 2025 21:07:16.220246077 CET50316445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:16.220838070 CET50317445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:16.222666979 CET44550315120.193.75.236192.168.2.9
                                      Jan 14, 2025 21:07:16.222739935 CET50315445192.168.2.9120.193.75.236
                                      Jan 14, 2025 21:07:16.225184917 CET44550316120.193.75.1192.168.2.9
                                      Jan 14, 2025 21:07:16.225243092 CET50316445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:16.225644112 CET44550317120.193.75.1192.168.2.9
                                      Jan 14, 2025 21:07:16.225711107 CET50317445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:16.225739956 CET50317445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:16.230482101 CET44550317120.193.75.1192.168.2.9
                                      Jan 14, 2025 21:07:16.678889036 CET4455013977.120.13.1192.168.2.9
                                      Jan 14, 2025 21:07:16.678975105 CET50139445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:07:16.679012060 CET50139445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:07:16.679039955 CET50139445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:07:16.683795929 CET4455013977.120.13.1192.168.2.9
                                      Jan 14, 2025 21:07:16.683809042 CET4455013977.120.13.1192.168.2.9
                                      Jan 14, 2025 21:07:16.899449110 CET44550145199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:07:16.899595976 CET50145445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:07:16.899636984 CET50145445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:07:16.899677038 CET50145445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:07:16.904536963 CET44550145199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:07:16.904550076 CET44550145199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:07:17.631359100 CET50318445192.168.2.9136.127.160.37
                                      Jan 14, 2025 21:07:17.636383057 CET44550318136.127.160.37192.168.2.9
                                      Jan 14, 2025 21:07:17.636470079 CET50318445192.168.2.9136.127.160.37
                                      Jan 14, 2025 21:07:17.636538029 CET50318445192.168.2.9136.127.160.37
                                      Jan 14, 2025 21:07:17.636709929 CET50319445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:17.641469002 CET44550318136.127.160.37192.168.2.9
                                      Jan 14, 2025 21:07:17.641485929 CET44550319136.127.160.1192.168.2.9
                                      Jan 14, 2025 21:07:17.641541958 CET50318445192.168.2.9136.127.160.37
                                      Jan 14, 2025 21:07:17.641561031 CET50319445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:17.641680002 CET50319445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:17.642009020 CET50320445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:17.646548033 CET44550319136.127.160.1192.168.2.9
                                      Jan 14, 2025 21:07:17.646611929 CET50319445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:17.646770000 CET44550320136.127.160.1192.168.2.9
                                      Jan 14, 2025 21:07:17.646826029 CET50320445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:17.646868944 CET50320445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:17.651722908 CET44550320136.127.160.1192.168.2.9
                                      Jan 14, 2025 21:07:17.693648100 CET50321445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:17.698633909 CET4455032168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:07:17.698745012 CET50321445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:17.698802948 CET50321445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:17.703634024 CET4455032168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:07:18.699086905 CET4455018051.159.121.1192.168.2.9
                                      Jan 14, 2025 21:07:18.699242115 CET50180445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:07:18.699342966 CET50180445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:07:18.699342966 CET50180445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:07:18.704210997 CET4455018051.159.121.1192.168.2.9
                                      Jan 14, 2025 21:07:18.704243898 CET4455018051.159.121.1192.168.2.9
                                      Jan 14, 2025 21:07:18.962908983 CET50322445192.168.2.9134.238.213.215
                                      Jan 14, 2025 21:07:18.968027115 CET44550322134.238.213.215192.168.2.9
                                      Jan 14, 2025 21:07:18.968173981 CET50322445192.168.2.9134.238.213.215
                                      Jan 14, 2025 21:07:18.968286037 CET50322445192.168.2.9134.238.213.215
                                      Jan 14, 2025 21:07:18.968482971 CET50323445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:18.973330021 CET44550323134.238.213.1192.168.2.9
                                      Jan 14, 2025 21:07:18.973433018 CET50323445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:18.973475933 CET50323445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:18.973761082 CET50324445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:18.974982023 CET44550322134.238.213.215192.168.2.9
                                      Jan 14, 2025 21:07:18.975037098 CET50322445192.168.2.9134.238.213.215
                                      Jan 14, 2025 21:07:18.978624105 CET44550323134.238.213.1192.168.2.9
                                      Jan 14, 2025 21:07:18.978694916 CET50323445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:18.978729963 CET44550324134.238.213.1192.168.2.9
                                      Jan 14, 2025 21:07:18.978792906 CET50324445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:18.978837967 CET50324445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:18.983717918 CET44550324134.238.213.1192.168.2.9
                                      Jan 14, 2025 21:07:19.695394993 CET50325445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:07:19.700551033 CET4455032577.120.13.1192.168.2.9
                                      Jan 14, 2025 21:07:19.700694084 CET50325445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:07:19.703042984 CET50325445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:07:19.707969904 CET4455032577.120.13.1192.168.2.9
                                      Jan 14, 2025 21:07:19.912314892 CET50326445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:07:19.917296886 CET44550326199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:07:19.917380095 CET50326445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:07:19.917399883 CET50326445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:07:19.922147989 CET44550326199.83.239.2192.168.2.9
                                      Jan 14, 2025 21:07:20.209774971 CET50327445192.168.2.930.228.189.78
                                      Jan 14, 2025 21:07:20.214728117 CET4455032730.228.189.78192.168.2.9
                                      Jan 14, 2025 21:07:20.214848042 CET50327445192.168.2.930.228.189.78
                                      Jan 14, 2025 21:07:20.214901924 CET50327445192.168.2.930.228.189.78
                                      Jan 14, 2025 21:07:20.215121984 CET50328445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:20.219856977 CET4455032830.228.189.1192.168.2.9
                                      Jan 14, 2025 21:07:20.219923019 CET50328445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:20.219950914 CET50328445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:20.220273972 CET50329445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:20.220293999 CET4455032730.228.189.78192.168.2.9
                                      Jan 14, 2025 21:07:20.225066900 CET4455032930.228.189.1192.168.2.9
                                      Jan 14, 2025 21:07:20.225128889 CET50329445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:20.225158930 CET50329445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:20.225868940 CET4455032730.228.189.78192.168.2.9
                                      Jan 14, 2025 21:07:20.225909948 CET50327445192.168.2.930.228.189.78
                                      Jan 14, 2025 21:07:20.226289034 CET4455032830.228.189.1192.168.2.9
                                      Jan 14, 2025 21:07:20.226334095 CET50328445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:20.229939938 CET4455032930.228.189.1192.168.2.9
                                      Jan 14, 2025 21:07:20.741570950 CET44550216222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:07:20.743438959 CET50216445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:07:20.743530035 CET50216445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:07:20.743530035 CET50216445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:07:20.748538971 CET44550216222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:07:20.748554945 CET44550216222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:07:20.997224092 CET445502203.157.171.1192.168.2.9
                                      Jan 14, 2025 21:07:21.001209021 CET50220445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:07:21.001266003 CET50220445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:07:21.001331091 CET50220445192.168.2.93.157.171.1
                                      Jan 14, 2025 21:07:21.006165028 CET445502203.157.171.1192.168.2.9
                                      Jan 14, 2025 21:07:21.006181002 CET445502203.157.171.1192.168.2.9
                                      Jan 14, 2025 21:07:21.053312063 CET50330445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:21.058350086 CET445503303.157.171.2192.168.2.9
                                      Jan 14, 2025 21:07:21.061237097 CET50330445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:21.061337948 CET50330445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:21.061713934 CET50331445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:21.066351891 CET445503303.157.171.2192.168.2.9
                                      Jan 14, 2025 21:07:21.066529036 CET445503313.157.171.2192.168.2.9
                                      Jan 14, 2025 21:07:21.066606045 CET50330445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:21.066639900 CET50331445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:21.066720009 CET50331445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:21.071605921 CET445503313.157.171.2192.168.2.9
                                      Jan 14, 2025 21:07:21.365773916 CET50332445192.168.2.9132.227.104.105
                                      Jan 14, 2025 21:07:21.370815039 CET44550332132.227.104.105192.168.2.9
                                      Jan 14, 2025 21:07:21.373326063 CET50332445192.168.2.9132.227.104.105
                                      Jan 14, 2025 21:07:21.373424053 CET50332445192.168.2.9132.227.104.105
                                      Jan 14, 2025 21:07:21.373599052 CET50333445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:21.378421068 CET44550333132.227.104.1192.168.2.9
                                      Jan 14, 2025 21:07:21.381052971 CET50333445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:21.381182909 CET50333445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:21.381268978 CET44550332132.227.104.105192.168.2.9
                                      Jan 14, 2025 21:07:21.381591082 CET50332445192.168.2.9132.227.104.105
                                      Jan 14, 2025 21:07:21.381587029 CET50334445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:21.388916016 CET44550334132.227.104.1192.168.2.9
                                      Jan 14, 2025 21:07:21.388967991 CET44550333132.227.104.1192.168.2.9
                                      Jan 14, 2025 21:07:21.389074087 CET50334445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:21.389163017 CET50334445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:21.392478943 CET44550333132.227.104.1192.168.2.9
                                      Jan 14, 2025 21:07:21.393170118 CET50333445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:21.394278049 CET44550334132.227.104.1192.168.2.9
                                      Jan 14, 2025 21:07:21.709299088 CET50335445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:07:21.731307030 CET4455033551.159.121.1192.168.2.9
                                      Jan 14, 2025 21:07:21.731403112 CET50335445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:07:21.731450081 CET50335445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:07:21.736219883 CET4455033551.159.121.1192.168.2.9
                                      Jan 14, 2025 21:07:21.920603991 CET4970580192.168.2.9199.232.214.172
                                      Jan 14, 2025 21:07:21.927094936 CET8049705199.232.214.172192.168.2.9
                                      Jan 14, 2025 21:07:21.927217007 CET4970580192.168.2.9199.232.214.172
                                      Jan 14, 2025 21:07:22.449079990 CET50336445192.168.2.9178.61.232.175
                                      Jan 14, 2025 21:07:22.455528975 CET44550336178.61.232.175192.168.2.9
                                      Jan 14, 2025 21:07:22.455611944 CET50336445192.168.2.9178.61.232.175
                                      Jan 14, 2025 21:07:22.455697060 CET50336445192.168.2.9178.61.232.175
                                      Jan 14, 2025 21:07:22.455863953 CET50337445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:22.462179899 CET44550336178.61.232.175192.168.2.9
                                      Jan 14, 2025 21:07:22.462249041 CET50336445192.168.2.9178.61.232.175
                                      Jan 14, 2025 21:07:22.462296963 CET44550337178.61.232.1192.168.2.9
                                      Jan 14, 2025 21:07:22.462358952 CET50337445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:22.462436914 CET50337445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:22.462825060 CET50338445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:22.469327927 CET44550338178.61.232.1192.168.2.9
                                      Jan 14, 2025 21:07:22.469424963 CET50338445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:22.469760895 CET44550337178.61.232.1192.168.2.9
                                      Jan 14, 2025 21:07:22.470050097 CET44550337178.61.232.1192.168.2.9
                                      Jan 14, 2025 21:07:22.470091105 CET50337445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:22.472920895 CET50338445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:22.479372978 CET44550338178.61.232.1192.168.2.9
                                      Jan 14, 2025 21:07:22.727760077 CET44550234150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:22.728009939 CET50234445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:22.728009939 CET50234445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:22.728060007 CET50234445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:22.732913017 CET44550234150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:22.732925892 CET44550234150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:22.961093903 CET44550237116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:07:22.961182117 CET50237445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:07:22.961240053 CET50237445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:07:22.961282969 CET50237445192.168.2.9116.209.81.1
                                      Jan 14, 2025 21:07:22.966140985 CET44550237116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:07:22.966175079 CET44550237116.209.81.1192.168.2.9
                                      Jan 14, 2025 21:07:23.021981955 CET50339445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:23.026974916 CET44550339116.209.81.2192.168.2.9
                                      Jan 14, 2025 21:07:23.027040958 CET50339445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:23.027246952 CET50339445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:23.027591944 CET50340445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:23.032072067 CET44550339116.209.81.2192.168.2.9
                                      Jan 14, 2025 21:07:23.032131910 CET50339445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:23.032401085 CET44550340116.209.81.2192.168.2.9
                                      Jan 14, 2025 21:07:23.032481909 CET50340445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:23.032540083 CET50340445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:23.037343025 CET44550340116.209.81.2192.168.2.9
                                      Jan 14, 2025 21:07:23.459613085 CET50342445192.168.2.990.4.176.57
                                      Jan 14, 2025 21:07:23.464517117 CET4455034290.4.176.57192.168.2.9
                                      Jan 14, 2025 21:07:23.464632034 CET50342445192.168.2.990.4.176.57
                                      Jan 14, 2025 21:07:23.464673996 CET50342445192.168.2.990.4.176.57
                                      Jan 14, 2025 21:07:23.464845896 CET50343445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:23.469715118 CET4455034390.4.176.1192.168.2.9
                                      Jan 14, 2025 21:07:23.469786882 CET50343445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:23.469857931 CET4455034290.4.176.57192.168.2.9
                                      Jan 14, 2025 21:07:23.469903946 CET50343445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:23.469911098 CET50342445192.168.2.990.4.176.57
                                      Jan 14, 2025 21:07:23.470285892 CET50344445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:23.475059032 CET4455034390.4.176.1192.168.2.9
                                      Jan 14, 2025 21:07:23.475115061 CET4455034490.4.176.1192.168.2.9
                                      Jan 14, 2025 21:07:23.475142002 CET50343445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:23.475178003 CET50344445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:23.475217104 CET50344445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:23.480011940 CET4455034490.4.176.1192.168.2.9
                                      Jan 14, 2025 21:07:23.756180048 CET50345445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:07:23.761786938 CET44550345222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:07:23.765235901 CET50345445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:07:23.768184900 CET50345445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:07:23.772999048 CET44550345222.113.31.1192.168.2.9
                                      Jan 14, 2025 21:07:24.397135973 CET50346445192.168.2.962.129.107.104
                                      Jan 14, 2025 21:07:24.402057886 CET4455034662.129.107.104192.168.2.9
                                      Jan 14, 2025 21:07:24.402115107 CET50346445192.168.2.962.129.107.104
                                      Jan 14, 2025 21:07:24.402163029 CET50346445192.168.2.962.129.107.104
                                      Jan 14, 2025 21:07:24.402331114 CET50347445192.168.2.962.129.107.1
                                      Jan 14, 2025 21:07:24.407119989 CET4455034762.129.107.1192.168.2.9
                                      Jan 14, 2025 21:07:24.407430887 CET4455034662.129.107.104192.168.2.9
                                      Jan 14, 2025 21:07:24.407522917 CET50346445192.168.2.962.129.107.104
                                      Jan 14, 2025 21:07:24.407542944 CET50347445192.168.2.962.129.107.1
                                      Jan 14, 2025 21:07:24.408019066 CET50348445192.168.2.962.129.107.1
                                      Jan 14, 2025 21:07:24.412604094 CET4455034762.129.107.1192.168.2.9
                                      Jan 14, 2025 21:07:24.412750006 CET4455034862.129.107.1192.168.2.9
                                      Jan 14, 2025 21:07:24.412818909 CET50347445192.168.2.962.129.107.1
                                      Jan 14, 2025 21:07:24.412847042 CET50348445192.168.2.962.129.107.1
                                      Jan 14, 2025 21:07:24.412882090 CET50348445192.168.2.962.129.107.1
                                      Jan 14, 2025 21:07:24.417644024 CET4455034862.129.107.1192.168.2.9
                                      Jan 14, 2025 21:07:24.761132002 CET44550251103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:24.761229038 CET50251445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:24.761313915 CET50251445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:24.761315107 CET50251445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:24.766156912 CET44550251103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:24.766170979 CET44550251103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:24.979916096 CET4455025415.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:24.979990959 CET50254445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:24.980103016 CET50254445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:24.980165958 CET50254445192.168.2.915.212.96.1
                                      Jan 14, 2025 21:07:24.984894991 CET4455025415.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:24.984987020 CET4455025415.212.96.1192.168.2.9
                                      Jan 14, 2025 21:07:25.038537979 CET50349445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:25.043529987 CET4455034915.212.96.2192.168.2.9
                                      Jan 14, 2025 21:07:25.043634892 CET50349445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:25.043634892 CET50349445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:25.043977022 CET50350445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:25.048707962 CET4455034915.212.96.2192.168.2.9
                                      Jan 14, 2025 21:07:25.048767090 CET50349445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:25.048777103 CET4455035015.212.96.2192.168.2.9
                                      Jan 14, 2025 21:07:25.048827887 CET50350445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:25.048858881 CET50350445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:25.053708076 CET4455035015.212.96.2192.168.2.9
                                      Jan 14, 2025 21:07:25.272119045 CET50351445192.168.2.9178.11.150.145
                                      Jan 14, 2025 21:07:25.277168036 CET44550351178.11.150.145192.168.2.9
                                      Jan 14, 2025 21:07:25.277331114 CET50351445192.168.2.9178.11.150.145
                                      Jan 14, 2025 21:07:25.277332067 CET50351445192.168.2.9178.11.150.145
                                      Jan 14, 2025 21:07:25.277437925 CET50352445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:25.282285929 CET44550352178.11.150.1192.168.2.9
                                      Jan 14, 2025 21:07:25.282367945 CET50352445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:25.282367945 CET50352445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:25.282402992 CET44550351178.11.150.145192.168.2.9
                                      Jan 14, 2025 21:07:25.282685041 CET50353445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:25.282701969 CET50351445192.168.2.9178.11.150.145
                                      Jan 14, 2025 21:07:25.287451982 CET44550352178.11.150.1192.168.2.9
                                      Jan 14, 2025 21:07:25.287487984 CET44550353178.11.150.1192.168.2.9
                                      Jan 14, 2025 21:07:25.287556887 CET50352445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:25.287902117 CET50353445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:25.287903070 CET50353445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:25.292764902 CET44550353178.11.150.1192.168.2.9
                                      Jan 14, 2025 21:07:25.740550041 CET50354445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:25.745579004 CET44550354150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:25.745671034 CET50354445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:25.745697975 CET50354445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:25.750524998 CET44550354150.135.181.1192.168.2.9
                                      Jan 14, 2025 21:07:26.100070953 CET50355445192.168.2.9111.205.61.88
                                      Jan 14, 2025 21:07:26.105015039 CET44550355111.205.61.88192.168.2.9
                                      Jan 14, 2025 21:07:26.105091095 CET50355445192.168.2.9111.205.61.88
                                      Jan 14, 2025 21:07:26.105124950 CET50355445192.168.2.9111.205.61.88
                                      Jan 14, 2025 21:07:26.105287075 CET50356445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:26.110028028 CET44550356111.205.61.1192.168.2.9
                                      Jan 14, 2025 21:07:26.110115051 CET44550355111.205.61.88192.168.2.9
                                      Jan 14, 2025 21:07:26.110198021 CET50355445192.168.2.9111.205.61.88
                                      Jan 14, 2025 21:07:26.110198021 CET50356445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:26.110532999 CET50357445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:26.110544920 CET50356445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:26.115345955 CET44550357111.205.61.1192.168.2.9
                                      Jan 14, 2025 21:07:26.115356922 CET44550356111.205.61.1192.168.2.9
                                      Jan 14, 2025 21:07:26.115434885 CET50356445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:26.115463018 CET50357445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:26.115463018 CET50357445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:26.120235920 CET44550357111.205.61.1192.168.2.9
                                      Jan 14, 2025 21:07:26.865784883 CET50358445192.168.2.9223.92.131.20
                                      Jan 14, 2025 21:07:26.871970892 CET44550358223.92.131.20192.168.2.9
                                      Jan 14, 2025 21:07:26.872204065 CET50358445192.168.2.9223.92.131.20
                                      Jan 14, 2025 21:07:26.872402906 CET50358445192.168.2.9223.92.131.20
                                      Jan 14, 2025 21:07:26.872405052 CET50359445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:26.877243042 CET44550359223.92.131.1192.168.2.9
                                      Jan 14, 2025 21:07:26.877258062 CET44550358223.92.131.20192.168.2.9
                                      Jan 14, 2025 21:07:26.877306938 CET50359445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:26.877320051 CET50359445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:26.877337933 CET50358445192.168.2.9223.92.131.20
                                      Jan 14, 2025 21:07:26.877762079 CET50360445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:26.882219076 CET44550359223.92.131.1192.168.2.9
                                      Jan 14, 2025 21:07:26.882282972 CET50359445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:26.883599997 CET44550360223.92.131.1192.168.2.9
                                      Jan 14, 2025 21:07:26.883656025 CET50360445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:26.883687973 CET50360445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:26.888386011 CET44550360223.92.131.1192.168.2.9
                                      Jan 14, 2025 21:07:26.960309982 CET44550270126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:26.960552931 CET50270445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:26.960553885 CET50270445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:26.960553885 CET50270445192.168.2.9126.245.156.1
                                      Jan 14, 2025 21:07:26.965413094 CET44550270126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:26.965852022 CET44550270126.245.156.1192.168.2.9
                                      Jan 14, 2025 21:07:27.021817923 CET50361445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:27.027009010 CET44550361126.245.156.2192.168.2.9
                                      Jan 14, 2025 21:07:27.027129889 CET50361445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:27.027228117 CET50361445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:27.027455091 CET50362445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:27.032272100 CET44550361126.245.156.2192.168.2.9
                                      Jan 14, 2025 21:07:27.032366037 CET50361445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:27.032454967 CET44550362126.245.156.2192.168.2.9
                                      Jan 14, 2025 21:07:27.032532930 CET50362445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:27.032574892 CET50362445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:27.037466049 CET44550362126.245.156.2192.168.2.9
                                      Jan 14, 2025 21:07:27.771889925 CET50364445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:27.777028084 CET44550364103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:27.777160883 CET50364445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:27.777204037 CET50364445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:27.782030106 CET44550364103.42.206.1192.168.2.9
                                      Jan 14, 2025 21:07:28.772981882 CET4455028452.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:28.773092031 CET50284445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:28.773178101 CET50284445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:28.773178101 CET50284445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:28.778114080 CET4455028452.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:28.778145075 CET4455028452.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:28.995608091 CET44550287138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:28.995748043 CET50287445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:28.998728037 CET50287445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:28.998784065 CET50287445192.168.2.9138.57.247.1
                                      Jan 14, 2025 21:07:29.003967047 CET44550287138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:29.003998041 CET44550287138.57.247.1192.168.2.9
                                      Jan 14, 2025 21:07:29.053055048 CET50368445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:29.058023930 CET44550368138.57.247.2192.168.2.9
                                      Jan 14, 2025 21:07:29.058128119 CET50368445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:29.058171034 CET50368445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:29.058583021 CET50369445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:29.063221931 CET44550368138.57.247.2192.168.2.9
                                      Jan 14, 2025 21:07:29.063296080 CET50368445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:29.063548088 CET44550369138.57.247.2192.168.2.9
                                      Jan 14, 2025 21:07:29.063625097 CET50369445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:29.063668013 CET50369445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:29.068531036 CET44550369138.57.247.2192.168.2.9
                                      Jan 14, 2025 21:07:30.835735083 CET44550299186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:30.835835934 CET50299445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:30.835902929 CET50299445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:30.835932970 CET50299445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:30.842681885 CET44550299186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:30.842721939 CET44550299186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:31.007494926 CET44550300144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:31.007668972 CET50300445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:31.007842064 CET50300445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:31.008050919 CET50300445192.168.2.9144.69.237.1
                                      Jan 14, 2025 21:07:31.012672901 CET44550300144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:31.013051987 CET44550300144.69.237.1192.168.2.9
                                      Jan 14, 2025 21:07:31.068988085 CET50380445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:31.074084997 CET44550380144.69.237.2192.168.2.9
                                      Jan 14, 2025 21:07:31.074235916 CET50380445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:31.074430943 CET50380445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:31.074896097 CET50381445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:31.079478025 CET44550380144.69.237.2192.168.2.9
                                      Jan 14, 2025 21:07:31.079555035 CET50380445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:31.079876900 CET44550381144.69.237.2192.168.2.9
                                      Jan 14, 2025 21:07:31.079950094 CET50381445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:31.079991102 CET50381445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:31.085279942 CET44550381144.69.237.2192.168.2.9
                                      Jan 14, 2025 21:07:31.787441015 CET50388445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:31.792494059 CET4455038852.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:31.792561054 CET50388445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:31.792603016 CET50388445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:31.797365904 CET4455038852.145.247.1192.168.2.9
                                      Jan 14, 2025 21:07:32.679182053 CET4455030450.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:32.679399014 CET50304445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:32.679399014 CET50304445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:32.679399014 CET50304445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:32.684444904 CET4455030450.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:32.684478998 CET4455030450.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:33.069911957 CET4455030534.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:33.069998980 CET50305445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:33.070036888 CET50305445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:33.070094109 CET50305445192.168.2.934.81.201.1
                                      Jan 14, 2025 21:07:33.074940920 CET4455030534.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:33.074954987 CET4455030534.81.201.1192.168.2.9
                                      Jan 14, 2025 21:07:33.133160114 CET50402445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:33.138103008 CET4455040234.81.201.2192.168.2.9
                                      Jan 14, 2025 21:07:33.138458967 CET50402445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:33.138742924 CET50402445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:33.138986111 CET50403445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:33.143594980 CET4455040234.81.201.2192.168.2.9
                                      Jan 14, 2025 21:07:33.143654108 CET50402445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:33.143800020 CET4455040334.81.201.2192.168.2.9
                                      Jan 14, 2025 21:07:33.143872976 CET50403445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:33.143917084 CET50403445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:33.148710012 CET4455040334.81.201.2192.168.2.9
                                      Jan 14, 2025 21:07:33.618527889 CET44550307181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:33.618768930 CET50307445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:33.618834972 CET50307445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:33.618834972 CET50307445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:33.623723030 CET44550307181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:33.623733997 CET44550307181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:33.850050926 CET50414445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:33.855009079 CET44550414186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:33.855309963 CET50414445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:33.855309963 CET50414445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:33.860193968 CET44550414186.17.232.1192.168.2.9
                                      Jan 14, 2025 21:07:34.415513992 CET4455031063.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:34.415595055 CET50310445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:34.415673018 CET50310445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:34.415723085 CET50310445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:34.420402050 CET4455031063.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:34.420505047 CET4455031063.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:35.693619967 CET50451445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:35.698818922 CET4455045150.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:35.698892117 CET50451445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:35.698935032 CET50451445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:35.703990936 CET4455045150.121.163.1192.168.2.9
                                      Jan 14, 2025 21:07:36.070075989 CET4455031371.110.186.1192.168.2.9
                                      Jan 14, 2025 21:07:36.070362091 CET50313445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:36.070362091 CET50313445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:36.073194027 CET50313445192.168.2.971.110.186.1
                                      Jan 14, 2025 21:07:36.075233936 CET4455031371.110.186.1192.168.2.9
                                      Jan 14, 2025 21:07:36.078012943 CET4455031371.110.186.1192.168.2.9
                                      Jan 14, 2025 21:07:36.631247044 CET50478445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:36.636219978 CET44550478181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:36.636317015 CET50478445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:36.636341095 CET50478445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:36.641091108 CET44550478181.171.88.2192.168.2.9
                                      Jan 14, 2025 21:07:37.101341963 CET4455031416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:37.104330063 CET50314445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:37.104475975 CET50314445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:37.104476929 CET50314445192.168.2.916.10.57.1
                                      Jan 14, 2025 21:07:37.109265089 CET4455031416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:37.109270096 CET4455031416.10.57.1192.168.2.9
                                      Jan 14, 2025 21:07:37.162539959 CET50498445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:37.167408943 CET4455049816.10.57.2192.168.2.9
                                      Jan 14, 2025 21:07:37.167519093 CET50498445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:37.167875051 CET50500445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:37.168095112 CET50498445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:37.172669888 CET4455050016.10.57.2192.168.2.9
                                      Jan 14, 2025 21:07:37.174346924 CET50500445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:37.174395084 CET50500445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:37.176248074 CET4455049816.10.57.2192.168.2.9
                                      Jan 14, 2025 21:07:37.176517963 CET4455049816.10.57.2192.168.2.9
                                      Jan 14, 2025 21:07:37.176635027 CET50498445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:37.179188013 CET4455050016.10.57.2192.168.2.9
                                      Jan 14, 2025 21:07:37.428584099 CET50511445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:37.433496952 CET4455051163.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:37.435425043 CET50511445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:37.436156034 CET50511445192.168.2.963.166.202.1
                                      Jan 14, 2025 21:07:37.440948009 CET4455051163.166.202.1192.168.2.9
                                      Jan 14, 2025 21:07:37.586111069 CET44550317120.193.75.1192.168.2.9
                                      Jan 14, 2025 21:07:37.586229086 CET50317445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:37.586229086 CET50317445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:37.586306095 CET50317445192.168.2.9120.193.75.1
                                      Jan 14, 2025 21:07:37.591219902 CET44550317120.193.75.1192.168.2.9
                                      Jan 14, 2025 21:07:37.591237068 CET44550317120.193.75.1192.168.2.9
                                      Jan 14, 2025 21:07:39.007467985 CET44550320136.127.160.1192.168.2.9
                                      Jan 14, 2025 21:07:39.007544041 CET50320445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:39.105392933 CET4455032168.234.13.1192.168.2.9
                                      Jan 14, 2025 21:07:39.105467081 CET50321445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:39.936625957 CET50381445192.168.2.9144.69.237.2
                                      Jan 14, 2025 21:07:39.936741114 CET50414445192.168.2.9186.17.232.1
                                      Jan 14, 2025 21:07:39.936815977 CET50350445192.168.2.915.212.96.2
                                      Jan 14, 2025 21:07:39.936856985 CET50500445192.168.2.916.10.57.2
                                      Jan 14, 2025 21:07:39.936903000 CET50335445192.168.2.951.159.121.1
                                      Jan 14, 2025 21:07:39.936903954 CET50403445192.168.2.934.81.201.2
                                      Jan 14, 2025 21:07:39.936942101 CET50320445192.168.2.9136.127.160.1
                                      Jan 14, 2025 21:07:39.937021971 CET50321445192.168.2.968.234.13.1
                                      Jan 14, 2025 21:07:39.937050104 CET50324445192.168.2.9134.238.213.1
                                      Jan 14, 2025 21:07:39.937053919 CET50325445192.168.2.977.120.13.1
                                      Jan 14, 2025 21:07:39.937066078 CET50326445192.168.2.9199.83.239.2
                                      Jan 14, 2025 21:07:39.937091112 CET50329445192.168.2.930.228.189.1
                                      Jan 14, 2025 21:07:39.937114954 CET50331445192.168.2.93.157.171.2
                                      Jan 14, 2025 21:07:39.937144041 CET50334445192.168.2.9132.227.104.1
                                      Jan 14, 2025 21:07:39.937295914 CET50338445192.168.2.9178.61.232.1
                                      Jan 14, 2025 21:07:39.937334061 CET50344445192.168.2.990.4.176.1
                                      Jan 14, 2025 21:07:39.937362909 CET50345445192.168.2.9222.113.31.1
                                      Jan 14, 2025 21:07:39.937377930 CET50348445192.168.2.962.129.107.1
                                      Jan 14, 2025 21:07:39.937397957 CET50353445192.168.2.9178.11.150.1
                                      Jan 14, 2025 21:07:39.937421083 CET50340445192.168.2.9116.209.81.2
                                      Jan 14, 2025 21:07:39.937444925 CET50354445192.168.2.9150.135.181.1
                                      Jan 14, 2025 21:07:39.937482119 CET50357445192.168.2.9111.205.61.1
                                      Jan 14, 2025 21:07:39.937483072 CET50360445192.168.2.9223.92.131.1
                                      Jan 14, 2025 21:07:39.937500000 CET50362445192.168.2.9126.245.156.2
                                      Jan 14, 2025 21:07:39.937529087 CET50364445192.168.2.9103.42.206.1
                                      Jan 14, 2025 21:07:39.937546968 CET50369445192.168.2.9138.57.247.2
                                      Jan 14, 2025 21:07:39.937582016 CET50388445192.168.2.952.145.247.1
                                      Jan 14, 2025 21:07:39.937616110 CET50478445192.168.2.9181.171.88.2
                                      Jan 14, 2025 21:07:39.937654018 CET50451445192.168.2.950.121.163.1
                                      Jan 14, 2025 21:07:39.937728882 CET50511445192.168.2.963.166.202.1
                                      TimestampSource PortDest PortSource IPDest IP
                                      Jan 14, 2025 21:06:31.993257999 CET5803453192.168.2.91.1.1.1
                                      Jan 14, 2025 21:06:32.300337076 CET53580341.1.1.1192.168.2.9
                                      Jan 14, 2025 21:06:32.948096991 CET5743153192.168.2.91.1.1.1
                                      Jan 14, 2025 21:06:33.130820036 CET53574311.1.1.1192.168.2.9
                                      Jan 14, 2025 21:07:22.370839119 CET138138192.168.2.9192.168.2.255
                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                      Jan 14, 2025 21:06:31.993257999 CET192.168.2.91.1.1.10x99cbStandard query (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                      Jan 14, 2025 21:06:32.948096991 CET192.168.2.91.1.1.10xf302Standard query (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                      Jan 14, 2025 21:06:25.718956947 CET1.1.1.1192.168.2.90x60efNo error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                      Jan 14, 2025 21:06:25.718956947 CET1.1.1.1192.168.2.90x60efNo error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                                      Jan 14, 2025 21:06:32.300337076 CET1.1.1.1192.168.2.90x99cbNo error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com103.224.212.215A (IP address)IN (0x0001)false
                                      Jan 14, 2025 21:06:33.130820036 CET1.1.1.1192.168.2.90xf302No error (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com77026.bodis.comCNAME (Canonical name)IN (0x0001)false
                                      Jan 14, 2025 21:06:33.130820036 CET1.1.1.1192.168.2.90xf302No error (0)77026.bodis.com199.59.243.228A (IP address)IN (0x0001)false
                                      • www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      • ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      0192.168.2.949742103.224.212.215807816C:\Windows\mssecsvr.exe
                                      TimestampBytes transferredDirectionData
                                      Jan 14, 2025 21:06:32.322264910 CET100OUTGET / HTTP/1.1
                                      Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      Cache-Control: no-cache
                                      Jan 14, 2025 21:06:32.939353943 CET365INHTTP/1.1 302 Found
                                      date: Tue, 14 Jan 2025 20:06:32 GMT
                                      server: Apache
                                      set-cookie: __tad=1736885192.5042682; expires=Fri, 12-Jan-2035 20:06:32 GMT; Max-Age=315360000
                                      location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-326f-9c7c-3821cc5c3a01
                                      content-length: 2
                                      content-type: text/html; charset=UTF-8
                                      connection: close
                                      Data Raw: 0a 0a
                                      Data Ascii:


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      1192.168.2.949748199.59.243.228807816C:\Windows\mssecsvr.exe
                                      TimestampBytes transferredDirectionData
                                      Jan 14, 2025 21:06:33.138122082 CET169OUTGET /?subid1=20250115-0706-326f-9c7c-3821cc5c3a01 HTTP/1.1
                                      Cache-Control: no-cache
                                      Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      Connection: Keep-Alive
                                      Jan 14, 2025 21:06:33.599946022 CET1236INHTTP/1.1 200 OK
                                      date: Tue, 14 Jan 2025 20:06:33 GMT
                                      content-type: text/html; charset=utf-8
                                      content-length: 1262
                                      x-request-id: 8462b0ae-2235-4789-ae47-4c74deb8c66f
                                      cache-control: no-store, max-age=0
                                      accept-ch: sec-ch-prefers-color-scheme
                                      critical-ch: sec-ch-prefers-color-scheme
                                      vary: sec-ch-prefers-color-scheme
                                      x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_ETjHj0Cb2JXaADlLP9SesdWv+DvVMWulGOmN3/bzpJWdAXyfr5BnSoAv21a9xW9nnFBnoBM0fheT+Bd0/0qNzw==
                                      set-cookie: parking_session=8462b0ae-2235-4789-ae47-4c74deb8c66f; expires=Tue, 14 Jan 2025 20:21:33 GMT; path=/
                                      Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 45 54 6a 48 6a 30 43 62 32 4a 58 61 41 44 6c 4c 50 39 53 65 73 64 57 76 2b 44 76 56 4d 57 75 6c 47 4f 6d 4e 33 2f 62 7a 70 4a 57 64 41 58 79 66 72 35 42 6e 53 6f 41 76 32 31 61 39 78 57 39 6e 6e 46 42 6e 6f 42 4d 30 66 68 65 54 2b 42 64 30 2f 30 71 4e 7a 77 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                      Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_ETjHj0Cb2JXaADlLP9SesdWv+DvVMWulGOmN3/bzpJWdAXyfr5BnSoAv21a9xW9nnFBnoBM0fheT+Bd0/0qNzw==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                      Jan 14, 2025 21:06:33.599968910 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                      Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiODQ2MmIwYWUtMjIzNS00Nzg5LWFlNDctNGM3NGRlYjhjNjZmIiwicGFnZV90aW1lIjoxNzM2ODg1MTkzLCJwYWdlX3VybCI6I


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      2192.168.2.949754103.224.212.215807920C:\Windows\mssecsvr.exe
                                      TimestampBytes transferredDirectionData
                                      Jan 14, 2025 21:06:33.830791950 CET100OUTGET / HTTP/1.1
                                      Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      Cache-Control: no-cache
                                      Jan 14, 2025 21:06:34.454596996 CET365INHTTP/1.1 302 Found
                                      date: Tue, 14 Jan 2025 20:06:34 GMT
                                      server: Apache
                                      set-cookie: __tad=1736885194.5933532; expires=Fri, 12-Jan-2035 20:06:34 GMT; Max-Age=315360000
                                      location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-3461-b88e-f77f83c83701
                                      content-length: 2
                                      content-type: text/html; charset=UTF-8
                                      connection: close
                                      Data Raw: 0a 0a
                                      Data Ascii:


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      3192.168.2.949760103.224.212.215807976C:\Windows\mssecsvr.exe
                                      TimestampBytes transferredDirectionData
                                      Jan 14, 2025 21:06:34.584914923 CET134OUTGET / HTTP/1.1
                                      Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      Cache-Control: no-cache
                                      Cookie: __tad=1736885192.5042682
                                      Jan 14, 2025 21:06:35.193245888 CET269INHTTP/1.1 302 Found
                                      date: Tue, 14 Jan 2025 20:06:35 GMT
                                      server: Apache
                                      location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-0706-350f-b72d-c6b0b8e6972f
                                      content-length: 2
                                      content-type: text/html; charset=UTF-8
                                      connection: close
                                      Data Raw: 0a 0a
                                      Data Ascii:


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      4192.168.2.949761199.59.243.228807920C:\Windows\mssecsvr.exe
                                      TimestampBytes transferredDirectionData
                                      Jan 14, 2025 21:06:34.588896036 CET169OUTGET /?subid1=20250115-0706-3461-b88e-f77f83c83701 HTTP/1.1
                                      Cache-Control: no-cache
                                      Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      Connection: Keep-Alive
                                      Jan 14, 2025 21:06:35.044425011 CET1236INHTTP/1.1 200 OK
                                      date: Tue, 14 Jan 2025 20:06:34 GMT
                                      content-type: text/html; charset=utf-8
                                      content-length: 1262
                                      x-request-id: 109a7d1a-7f89-44da-bced-687624b9a5f2
                                      cache-control: no-store, max-age=0
                                      accept-ch: sec-ch-prefers-color-scheme
                                      critical-ch: sec-ch-prefers-color-scheme
                                      vary: sec-ch-prefers-color-scheme
                                      x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_kA5pzlosWM3CYX/Kkvz+zbti6p3UYn1DUjNAjx+pTqy3DnJGX4pJlhklkEFGYhFDvxJOUzstlTN/y/KjcQcQeQ==
                                      set-cookie: parking_session=109a7d1a-7f89-44da-bced-687624b9a5f2; expires=Tue, 14 Jan 2025 20:21:34 GMT; path=/
                                      Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 6b 41 35 70 7a 6c 6f 73 57 4d 33 43 59 58 2f 4b 6b 76 7a 2b 7a 62 74 69 36 70 33 55 59 6e 31 44 55 6a 4e 41 6a 78 2b 70 54 71 79 33 44 6e 4a 47 58 34 70 4a 6c 68 6b 6c 6b 45 46 47 59 68 46 44 76 78 4a 4f 55 7a 73 74 6c 54 4e 2f 79 2f 4b 6a 63 51 63 51 65 51 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                      Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_kA5pzlosWM3CYX/Kkvz+zbti6p3UYn1DUjNAjx+pTqy3DnJGX4pJlhklkEFGYhFDvxJOUzstlTN/y/KjcQcQeQ==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                      Jan 14, 2025 21:06:35.044482946 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                      Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiMTA5YTdkMWEtN2Y4OS00NGRhLWJjZWQtNjg3NjI0YjlhNWYyIiwicGFnZV90aW1lIjoxNzM2ODg1MTk0LCJwYWdlX3VybCI6I


                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                      5192.168.2.949769199.59.243.228807976C:\Windows\mssecsvr.exe
                                      TimestampBytes transferredDirectionData
                                      Jan 14, 2025 21:06:35.204560995 CET231OUTGET /?subid1=20250115-0706-350f-b72d-c6b0b8e6972f HTTP/1.1
                                      Cache-Control: no-cache
                                      Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                      Connection: Keep-Alive
                                      Cookie: parking_session=8462b0ae-2235-4789-ae47-4c74deb8c66f
                                      Jan 14, 2025 21:06:35.670603037 CET1236INHTTP/1.1 200 OK
                                      date: Tue, 14 Jan 2025 20:06:35 GMT
                                      content-type: text/html; charset=utf-8
                                      content-length: 1262
                                      x-request-id: ea20e9e6-834b-4346-b34b-b98ccc9e2158
                                      cache-control: no-store, max-age=0
                                      accept-ch: sec-ch-prefers-color-scheme
                                      critical-ch: sec-ch-prefers-color-scheme
                                      vary: sec-ch-prefers-color-scheme
                                      x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_yOsfiu8vJ2t6isdOlvRtB56LXmjbstkC+dfEuJjnzHFFL0AtEaPwKAgbQQrFuXPng+CPaKakBO3/sePH93auxA==
                                      set-cookie: parking_session=8462b0ae-2235-4789-ae47-4c74deb8c66f; expires=Tue, 14 Jan 2025 20:21:35 GMT
                                      Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 79 4f 73 66 69 75 38 76 4a 32 74 36 69 73 64 4f 6c 76 52 74 42 35 36 4c 58 6d 6a 62 73 74 6b 43 2b 64 66 45 75 4a 6a 6e 7a 48 46 46 4c 30 41 74 45 61 50 77 4b 41 67 62 51 51 72 46 75 58 50 6e 67 2b 43 50 61 4b 61 6b 42 4f 33 2f 73 65 50 48 39 33 61 75 78 41 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                      Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_yOsfiu8vJ2t6isdOlvRtB56LXmjbstkC+dfEuJjnzHFFL0AtEaPwKAgbQQrFuXPng+CPaKakBO3/sePH93auxA==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="preconnect
                                      Jan 14, 2025 21:06:35.670659065 CET688INData Raw: 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65 74 22 20 73 74 79 6c 65
                                      Data Ascii: " href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiODQ2MmIwYWUtMjIzNS00Nzg5LWFlNDctNGM3NGRlYjhjNjZmIiwicGFnZV90aW1lIjoxNzM2ODg1MTk1LCJwYWdlX3VybCI6Imh0dHA6L


                                      Click to jump to process

                                      Click to jump to process

                                      Click to dive into process behavior distribution

                                      Click to jump to process

                                      Target ID:0
                                      Start time:15:06:30
                                      Start date:14/01/2025
                                      Path:C:\Windows\System32\loaddll32.exe
                                      Wow64 process (32bit):true
                                      Commandline:loaddll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll"
                                      Imagebase:0xd50000
                                      File size:126'464 bytes
                                      MD5 hash:51E6071F9CBA48E79F10C84515AAE618
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:1
                                      Start time:15:06:30
                                      Start date:14/01/2025
                                      Path:C:\Windows\System32\conhost.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                      Imagebase:0x7ff70f010000
                                      File size:862'208 bytes
                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:2
                                      Start time:15:06:30
                                      Start date:14/01/2025
                                      Path:C:\Windows\SysWOW64\cmd.exe
                                      Wow64 process (32bit):true
                                      Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1
                                      Imagebase:0xc50000
                                      File size:236'544 bytes
                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:3
                                      Start time:15:06:30
                                      Start date:14/01/2025
                                      Path:C:\Windows\SysWOW64\rundll32.exe
                                      Wow64 process (32bit):true
                                      Commandline:rundll32.exe C:\Users\user\Desktop\sUlHfYQxNw.dll,PlayGame
                                      Imagebase:0xa80000
                                      File size:61'440 bytes
                                      MD5 hash:889B99C52A60DD49227C5E485A016679
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:4
                                      Start time:15:06:30
                                      Start date:14/01/2025
                                      Path:C:\Windows\SysWOW64\rundll32.exe
                                      Wow64 process (32bit):true
                                      Commandline:rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",#1
                                      Imagebase:0xa80000
                                      File size:61'440 bytes
                                      MD5 hash:889B99C52A60DD49227C5E485A016679
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:6
                                      Start time:15:06:30
                                      Start date:14/01/2025
                                      Path:C:\Windows\mssecsvr.exe
                                      Wow64 process (32bit):true
                                      Commandline:C:\WINDOWS\mssecsvr.exe
                                      Imagebase:0x400000
                                      File size:3'723'264 bytes
                                      MD5 hash:B01DB44786F461C9415813F968A7664A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Yara matches:
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000006.00000000.1356648127.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                      Reputation:low
                                      Has exited:true

                                      Target ID:8
                                      Start time:15:06:33
                                      Start date:14/01/2025
                                      Path:C:\Windows\mssecsvr.exe
                                      Wow64 process (32bit):true
                                      Commandline:C:\WINDOWS\mssecsvr.exe -m security
                                      Imagebase:0x400000
                                      File size:3'723'264 bytes
                                      MD5 hash:B01DB44786F461C9415813F968A7664A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Yara matches:
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmp, Author: Joe Security
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2032119796.00000000024E9000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2031833962.0000000001FB8000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000000.1379865895.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                      Reputation:low
                                      Has exited:true

                                      Target ID:9
                                      Start time:15:06:33
                                      Start date:14/01/2025
                                      Path:C:\Windows\SysWOW64\rundll32.exe
                                      Wow64 process (32bit):true
                                      Commandline:rundll32.exe "C:\Users\user\Desktop\sUlHfYQxNw.dll",PlayGame
                                      Imagebase:0xa80000
                                      File size:61'440 bytes
                                      MD5 hash:889B99C52A60DD49227C5E485A016679
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high
                                      Has exited:true

                                      Target ID:10
                                      Start time:15:06:33
                                      Start date:14/01/2025
                                      Path:C:\Windows\mssecsvr.exe
                                      Wow64 process (32bit):true
                                      Commandline:C:\WINDOWS\mssecsvr.exe
                                      Imagebase:0x400000
                                      File size:3'723'264 bytes
                                      MD5 hash:B01DB44786F461C9415813F968A7664A
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Yara matches:
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 0000000A.00000000.1385339292.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                      • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 0000000A.00000002.1400701115.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                      Reputation:low
                                      Has exited:true

                                      Reset < >

                                        Execution Graph

                                        Execution Coverage:71.7%
                                        Dynamic/Decrypted Code Coverage:0%
                                        Signature Coverage:63.2%
                                        Total number of Nodes:38
                                        Total number of Limit Nodes:9
                                        execution_graph 63 409a16 __set_app_type __p__fmode __p__commode 64 409a85 63->64 65 409a99 64->65 66 409a8d __setusermatherr 64->66 75 409b8c _controlfp 65->75 66->65 68 409a9e _initterm __getmainargs _initterm 69 409af2 GetStartupInfoA 68->69 71 409b26 GetModuleHandleA 69->71 76 408140 InternetOpenA InternetOpenUrlA 71->76 75->68 77 4081a7 InternetCloseHandle InternetCloseHandle 76->77 80 408090 GetModuleFileNameA __p___argc 77->80 79 4081b2 exit _XcptFilter 81 4080b0 80->81 82 4080b9 OpenSCManagerA 80->82 91 407f20 81->91 83 408101 StartServiceCtrlDispatcherA 82->83 84 4080cf OpenServiceA 82->84 83->79 86 4080fc CloseServiceHandle 84->86 87 4080ee 84->87 86->83 96 407fa0 ChangeServiceConfig2A 87->96 90 4080f6 CloseServiceHandle 90->86 108 407c40 sprintf OpenSCManagerA 91->108 93 407f25 97 407ce0 GetModuleHandleW 93->97 96->90 98 407d01 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 97->98 99 407f08 97->99 98->99 100 407d49 98->100 99->79 100->99 101 407d69 FindResourceA 100->101 101->99 102 407d84 LoadResource 101->102 102->99 103 407d94 LockResource 102->103 103->99 104 407da7 SizeofResource 103->104 104->99 105 407db9 sprintf sprintf MoveFileExA CreateFileA 104->105 105->99 106 407e54 WriteFile CloseHandle CreateProcessA 105->106 106->99 107 407ef2 CloseHandle CloseHandle 106->107 107->99 109 407c74 CreateServiceA 108->109 110 407cca 108->110 111 407cbb CloseServiceHandle 109->111 112 407cad StartServiceA CloseServiceHandle 109->112 110->93 111->93 112->111

                                        Callgraph

                                        Control-flow Graph

                                        APIs
                                        • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F9B0EF0,?,00000000), ref: 00407CEF
                                        • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                        • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                        • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                        • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                        • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                        • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                        • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                        • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                        • sprintf.MSVCRT ref: 00407E01
                                        • sprintf.MSVCRT ref: 00407E18
                                        • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                        • CreateFileA.KERNELBASE(?,40000000,00000000,00000000,00000002,00000004,00000000), ref: 00407E43
                                        • WriteFile.KERNELBASE(00000000,?,00000000,?,00000000), ref: 00407E61
                                        • CloseHandle.KERNELBASE(00000000), ref: 00407E68
                                        • CreateProcessA.KERNELBASE ref: 00407EE8
                                        • CloseHandle.KERNEL32(00000000), ref: 00407EF7
                                        • CloseHandle.KERNEL32(08000000), ref: 00407F02
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000006.00000002.1395421706.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000006.00000002.1395401133.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395444466.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395512402.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: AddressHandleProcResource$CloseFile$Createsprintf$FindLoadLockModuleMoveProcessSizeofWrite
                                        • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                        • API String ID: 4281112323-1507730452
                                        • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                        • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                        • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                        • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                        Control-flow Graph

                                        APIs
                                        Memory Dump Source
                                        • Source File: 00000006.00000002.1395421706.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000006.00000002.1395401133.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395444466.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395512402.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                        • String ID:
                                        • API String ID: 801014965-0
                                        • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                        • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                        • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                        • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59

                                        Control-flow Graph

                                        APIs
                                        • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                        • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                        • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                        • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                          • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                          • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                        Strings
                                        • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                        Memory Dump Source
                                        • Source File: 00000006.00000002.1395421706.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000006.00000002.1395401133.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395444466.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395512402.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                        • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        • API String ID: 774561529-2614457033
                                        • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                        • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                        • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                        • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                        Control-flow Graph

                                        APIs
                                        • sprintf.MSVCRT ref: 00407C56
                                        • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                        • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F9B0EF0,00000000), ref: 00407C9B
                                        • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                        • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                        • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000006.00000002.1395421706.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000006.00000002.1395401133.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395444466.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395512402.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                        • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                        • API String ID: 3340711343-2450984573
                                        • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                        • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                        • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                        • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                        Control-flow Graph

                                        APIs
                                        • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                        • __p___argc.MSVCRT ref: 004080A5
                                        • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                        • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F9B0EF0,00000000,?,004081B2), ref: 004080DC
                                        • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                        • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                        • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000006.00000002.1395421706.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000006.00000002.1395401133.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395444466.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395464825.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395512402.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000006.00000002.1395600709.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                        • String ID: mssecsvc2.1
                                        • API String ID: 4274534310-2839763450
                                        • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                        • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                        • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                        • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                        Execution Graph

                                        Execution Coverage:34.8%
                                        Dynamic/Decrypted Code Coverage:0%
                                        Signature Coverage:0%
                                        Total number of Nodes:36
                                        Total number of Limit Nodes:2

                                        Callgraph

                                        Control-flow Graph

                                        APIs
                                        • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                        • __p___argc.MSVCRT ref: 004080A5
                                        • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                        • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F9B0EF0,00000000,?,004081B2), ref: 004080DC
                                        • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                        • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                        • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000008.00000002.2030939215.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000008.00000002.2030923800.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030956785.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031022901.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031038558.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                        • String ID: mssecsvc2.1
                                        • API String ID: 4274534310-2839763450
                                        • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                        • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                        • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                        • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                        Control-flow Graph

                                        APIs
                                        • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                        • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                        • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                        • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                          • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                          • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                        Strings
                                        • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                        Memory Dump Source
                                        • Source File: 00000008.00000002.2030939215.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000008.00000002.2030923800.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030956785.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031022901.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031038558.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                        • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        • API String ID: 774561529-2614457033
                                        • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                        • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                        • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                        • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                        Control-flow Graph

                                        APIs
                                        • sprintf.MSVCRT ref: 00407C56
                                        • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                        • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F9B0EF0,00000000), ref: 00407C9B
                                        • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                        • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                        • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000008.00000002.2030939215.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000008.00000002.2030923800.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030956785.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031022901.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031038558.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                        • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                        • API String ID: 3340711343-2450984573
                                        • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                        • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                        • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                        • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                        Control-flow Graph

                                        • Executed
                                        • Not Executed
                                        control_flow_graph 15 407ce0-407cfb GetModuleHandleW 16 407d01-407d43 GetProcAddress * 4 15->16 17 407f08-407f14 15->17 16->17 18 407d49-407d4f 16->18 18->17 19 407d55-407d5b 18->19 19->17 20 407d61-407d63 19->20 20->17 21 407d69-407d7e FindResourceA 20->21 21->17 22 407d84-407d8e LoadResource 21->22 22->17 23 407d94-407da1 LockResource 22->23 23->17 24 407da7-407db3 SizeofResource 23->24 24->17 25 407db9-407e4e sprintf * 2 MoveFileExA 24->25 25->17 27 407e54-407ef0 25->27 27->17 31 407ef2-407f01 27->31 31->17
                                        APIs
                                        • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F9B0EF0,?,00000000), ref: 00407CEF
                                        • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                        • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                        • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                        • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                        • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                        • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                        • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                        • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                        • sprintf.MSVCRT ref: 00407E01
                                        • sprintf.MSVCRT ref: 00407E18
                                        • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                        Strings
                                        Memory Dump Source
                                        • Source File: 00000008.00000002.2030939215.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000008.00000002.2030923800.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030956785.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031022901.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031038558.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: AddressProcResource$sprintf$FileFindHandleLoadLockModuleMoveSizeof
                                        • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                        • API String ID: 4072214828-1507730452
                                        • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                        • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                        • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                        • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                        Control-flow Graph

                                        APIs
                                        Memory Dump Source
                                        • Source File: 00000008.00000002.2030939215.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                        • Associated: 00000008.00000002.2030923800.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030956785.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2030971446.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031007037.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031022901.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031038558.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000733000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.0000000000775000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        • Associated: 00000008.00000002.2031130627.00000000007D0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                        Joe Sandbox IDA Plugin
                                        • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                        Yara matches
                                        Similarity
                                        • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                        • String ID:
                                        • API String ID: 801014965-0
                                        • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                        • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                        • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                        • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59