Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
hVgcaX2SV8.dll

Overview

General Information

Sample name:hVgcaX2SV8.dll
renamed because original name is a hash value
Original sample name:28d079409d4015dffe55191250e7eed4.dll
Analysis ID:1591526
MD5:28d079409d4015dffe55191250e7eed4
SHA1:57ea441d26af37a11145ca842b26ea81eeca6a72
SHA256:a062d5c2b65fa65dbadbc5e42b4af0e97cfab15f67280cb8b87068236a793ae4
Tags:dllexeWannaCryuser-mentality
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Wannacry ransomware
AI detected suspicious sample
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
May sleep (evasive loops) to hinder dynamic analysis
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Yara signature match

Classification

  • System is w10x64
  • loaddll32.exe (PID: 1272 cmdline: loaddll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 2284 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 768 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 6660 cmdline: rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
        • mssecsvr.exe (PID: 4308 cmdline: C:\WINDOWS\mssecsvr.exe MD5: C52D23EEDF757DFD3703AC774DE1C457)
    • rundll32.exe (PID: 984 cmdline: rundll32.exe C:\Users\user\Desktop\hVgcaX2SV8.dll,PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 6648 cmdline: rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
      • mssecsvr.exe (PID: 3656 cmdline: C:\WINDOWS\mssecsvr.exe MD5: C52D23EEDF757DFD3703AC774DE1C457)
  • mssecsvr.exe (PID: 5536 cmdline: C:\WINDOWS\mssecsvr.exe -m security MD5: C52D23EEDF757DFD3703AC774DE1C457)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
hVgcaX2SV8.dllJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    hVgcaX2SV8.dllWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x353d0:$x3: tasksche.exe
    • 0x353a8:$x8: C:\%s\qeriuwjhrf
    • 0x3014:$s1: C:\%s\%s
    • 0x12098:$s1: C:\%s\%s
    • 0x1b39c:$s1: C:\%s\%s
    • 0x353bc:$s1: C:\%s\%s
    • 0x77a88:$s4: msg/m_portuguese.wnry
    • 0x326f0:$s5: \\192.168.56.20\IPC$
    • 0x1fae5:$s6: \\172.16.99.5\IPC$
    • 0xd195:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
    • 0x78da:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
    • 0x5449:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
    SourceRuleDescriptionAuthorStrings
    00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        00000005.00000000.2104424678.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          00000007.00000000.2123551514.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            00000009.00000000.2133754261.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
              Click to see the 6 entries
              SourceRuleDescriptionAuthorStrings
              7.2.mssecsvr.exe.1d52084.5.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
              • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
              • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
              • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
              7.2.mssecsvr.exe.227b8c8.8.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
              • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
              • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
              • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
              7.2.mssecsvr.exe.228a948.9.raw.unpackJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
                7.2.mssecsvr.exe.228a948.9.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x222ec:$x3: tasksche.exe
                • 0x222c4:$x8: C:\%s\qeriuwjhrf
                • 0x82b8:$s1: C:\%s\%s
                • 0x222d8:$s1: C:\%s\%s
                • 0x649a4:$s4: msg/m_portuguese.wnry
                • 0x1f60c:$s5: \\192.168.56.20\IPC$
                • 0xca01:$s6: \\172.16.99.5\IPC$
                7.2.mssecsvr.exe.228a948.9.raw.unpackWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
                • 0xca4c:$s1: __TREEID__PLACEHOLDER__
                • 0xcae8:$s1: __TREEID__PLACEHOLDER__
                • 0xd354:$s1: __TREEID__PLACEHOLDER__
                • 0xe3b9:$s1: __TREEID__PLACEHOLDER__
                • 0xf420:$s1: __TREEID__PLACEHOLDER__
                • 0x10488:$s1: __TREEID__PLACEHOLDER__
                • 0x114f0:$s1: __TREEID__PLACEHOLDER__
                • 0x12558:$s1: __TREEID__PLACEHOLDER__
                • 0x135c0:$s1: __TREEID__PLACEHOLDER__
                • 0x14628:$s1: __TREEID__PLACEHOLDER__
                • 0x15690:$s1: __TREEID__PLACEHOLDER__
                • 0x166f8:$s1: __TREEID__PLACEHOLDER__
                • 0x17760:$s1: __TREEID__PLACEHOLDER__
                • 0x187c8:$s1: __TREEID__PLACEHOLDER__
                • 0x19830:$s1: __TREEID__PLACEHOLDER__
                • 0x1a898:$s1: __TREEID__PLACEHOLDER__
                • 0x1b900:$s1: __TREEID__PLACEHOLDER__
                • 0x1bb14:$s1: __TREEID__PLACEHOLDER__
                • 0x1bb74:$s1: __TREEID__PLACEHOLDER__
                • 0x1f244:$s1: __TREEID__PLACEHOLDER__
                • 0x1f2c0:$s1: __TREEID__PLACEHOLDER__
                Click to see the 35 entries
                No Sigma rule has matched
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-01-15T02:58:29.253435+010028033043Unknown Traffic192.168.2.549704103.224.212.21580TCP
                2025-01-15T02:58:30.937765+010028033043Unknown Traffic192.168.2.549706103.224.212.21580TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-01-15T02:58:28.485004+010028300181A Network Trojan was detected192.168.2.5542571.1.1.153UDP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: hVgcaX2SV8.dllAvira: detected
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431f5dAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/QAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/1Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431fAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f039Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f0Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294eAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294e47Avira URL Cloud: Label: malware
                Source: C:\WINDOWS\qeriuwjhrf (copy)ReversingLabs: Detection: 80%
                Source: C:\Windows\tasksche.exeReversingLabs: Detection: 80%
                Source: hVgcaX2SV8.dllVirustotal: Detection: 92%Perma Link
                Source: hVgcaX2SV8.dllReversingLabs: Detection: 92%
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.4% probability
                Source: C:\Windows\tasksche.exeJoe Sandbox ML: detected
                Source: hVgcaX2SV8.dllJoe Sandbox ML: detected

                Exploits

                barindex
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: hVgcaX2SV8.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: Binary string: d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb source: hVgcaX2SV8.dll, tasksche.exe.5.dr

                Networking

                barindex
                Source: Network trafficSuricata IDS: 2830018 - Severity 1 - ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup) : 192.168.2.5:54257 -> 1.1.1.1:53
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-29df-89f9-50f10d431f5d HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-30b4-926b-ebcd05294e47 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736906309.2045439
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-3155-9edf-37a78753f039 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=72908bbf-89ad-4006-aba3-e99298a28c4b
                Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.5:49706 -> 103.224.212.215:80
                Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.5:49704 -> 103.224.212.215:80
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.228
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.228
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.228
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.1
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.228
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.1
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.1
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.1
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.1
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.1
                Source: unknownTCP traffic detected without corresponding DNS query: 167.35.109.1
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.51
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.51
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.51
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.1
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.51
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.1
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.1
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.1
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.1
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.1
                Source: unknownTCP traffic detected without corresponding DNS query: 5.92.127.1
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.74
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.74
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.74
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.1
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.1
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.74
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.1
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.1
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.1
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.1
                Source: unknownTCP traffic detected without corresponding DNS query: 161.7.75.1
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.109
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.109
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.109
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.1
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.109
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.1
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.1
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.1
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.1
                Source: unknownTCP traffic detected without corresponding DNS query: 40.92.175.1
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-29df-89f9-50f10d431f5d HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-30b4-926b-ebcd05294e47 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736906309.2045439
                Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-3155-9edf-37a78753f039 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=72908bbf-89ad-4006-aba3-e99298a28c4b
                Source: global trafficDNS traffic detected: DNS query: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: global trafficDNS traffic detected: DNS query: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: mssecsvr.exe, 00000009.00000002.2151839433.0000000000A50000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: mssecsvr.exe, 00000009.00000002.2151839433.0000000000A50000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/1
                Source: mssecsvr.exe, 00000005.00000002.2137869882.0000000000B8E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431f
                Source: mssecsvr.exe, 00000007.00000002.2773536526.0000000000B9B000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2773536526.0000000000BED000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294e
                Source: mssecsvr.exe, 00000009.00000002.2151839433.0000000000A2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f0
                Source: mssecsvr.exe, 00000009.00000002.2151839433.0000000000A50000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Q
                Source: hVgcaX2SV8.dllString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: mssecsvr.exe, 00000005.00000002.2137869882.0000000000BAD000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000005.00000002.2137869882.0000000000B4E000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000005.00000002.2137869882.0000000000BB7000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000005.00000002.2137869882.0000000000B8E000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2773536526.0000000000BE6000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2151839433.00000000009F8000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2151839433.0000000000A2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: mssecsvr.exe, 00000009.00000002.2151839433.00000000009F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Xm
                Source: mssecsvr.exe, 00000005.00000002.2137869882.0000000000B8E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/p
                Source: mssecsvr.exe, 00000007.00000002.2772976788.000000000019D000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJ
                Source: mssecsvr.exe, 00000009.00000002.2151839433.00000000009F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comNm
                Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703

                Spam, unwanted Advertisements and Ransom Demands

                barindex
                Source: Yara matchFile source: hVgcaX2SV8.dll, type: SAMPLE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.228a948.9.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.227b8c8.8.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d52084.5.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d61104.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.22868e8.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d61104.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.228a948.9.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d5d0a4.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000005.00000000.2104424678.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000000.2123551514.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000000.2133754261.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000002.2151167613.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000002.2774027813.0000000001D61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000002.2774278925.000000000228A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 4308, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 5536, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 3656, type: MEMORYSTR

                System Summary

                barindex
                Source: hVgcaX2SV8.dll, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d52084.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.227b8c8.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.228a948.9.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.228a948.9.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.227b8c8.8.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.227b8c8.8.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.1d52084.5.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d52084.5.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.1d61104.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d61104.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.22868e8.6.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d61104.2.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.228a948.9.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d5d0a4.4.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: tasksche.exe.5.drStatic PE information: No import functions for PE file found
                Source: hVgcaX2SV8.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: hVgcaX2SV8.dll, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d52084.5.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.227b8c8.8.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.228a948.9.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.228a948.9.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.227b8c8.8.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.227b8c8.8.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.1d52084.5.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d52084.5.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.1d61104.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d61104.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.22868e8.6.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d61104.2.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.228a948.9.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d5d0a4.4.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: tasksche.exe.5.drStatic PE information: Section: .data ZLIB complexity 1.001953125
                Source: tasksche.exe.5.drStatic PE information: Section: .rsrc ZLIB complexity 1.0007408405172413
                Source: classification engineClassification label: mal100.rans.expl.evad.winDLL@18/2@2/100
                Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,5_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,7_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00407CE0 InternetCloseHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessA,FindResourceA,LoadResource,LockResource,SizeofResource,sprintf,sprintf,sprintf,MoveFileExA,CreateFileA,WriteFile,CloseHandle,CreateProcessA,CloseHandle,CloseHandle,5_2_00407CE0
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,5_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,5_2_00408090
                Source: C:\Windows\mssecsvr.exeCode function: 7_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,7_2_00408090
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2284:120:WilError_03
                Source: hVgcaX2SV8.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\hVgcaX2SV8.dll,PlayGame
                Source: hVgcaX2SV8.dllVirustotal: Detection: 92%
                Source: hVgcaX2SV8.dllReversingLabs: Detection: 92%
                Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll"
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\hVgcaX2SV8.dll,PlayGame
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                Source: unknownProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe -m security
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",PlayGame
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1Jump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\hVgcaX2SV8.dll,PlayGameJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",PlayGameJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1Jump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
                Source: hVgcaX2SV8.dllStatic file information: File size 5267459 > 1048576
                Source: hVgcaX2SV8.dllStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x501000
                Source: Binary string: d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb source: hVgcaX2SV8.dll, tasksche.exe.5.dr

                Persistence and Installation Behavior

                barindex
                Source: C:\Windows\SysWOW64\rundll32.exeExecutable created and started: C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,5_2_00407C40
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exe TID: 5844Thread sleep count: 94 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 5844Thread sleep time: -188000s >= -30000sJump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 3116Thread sleep count: 126 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 3116Thread sleep count: 46 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 5844Thread sleep time: -86400000s >= -30000sJump to behavior
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\loaddll32.exeThread delayed: delay time: 120000Jump to behavior
                Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                Source: mssecsvr.exe, 00000007.00000002.2773536526.0000000000BED000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW"9
                Source: mssecsvr.exe, 00000005.00000002.2137869882.0000000000B78000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000005.00000002.2137869882.0000000000BB7000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2773536526.0000000000BED000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2773536526.0000000000B77000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2151839433.0000000000A1C000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2151839433.0000000000A50000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                Source: mssecsvr.exe, 00000009.00000002.2151839433.0000000000A2D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1Jump to behavior
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                Service Execution
                4
                Windows Service
                4
                Windows Service
                12
                Masquerading
                OS Credential Dumping1
                Network Share Discovery
                Remote ServicesData from Local System2
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/Job1
                DLL Side-Loading
                11
                Process Injection
                21
                Virtualization/Sandbox Evasion
                LSASS Memory11
                Security Software Discovery
                Remote Desktop ProtocolData from Removable Media1
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                11
                Process Injection
                Security Account Manager21
                Virtualization/Sandbox Evasion
                SMB/Windows Admin SharesData from Network Shared Drive2
                Non-Application Layer Protocol
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                Rundll32
                NTDS1
                System Information Discovery
                Distributed Component Object ModelInput Capture3
                Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Software Packing
                LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                DLL Side-Loading
                Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1591526 Sample: hVgcaX2SV8.dll Startdate: 15/01/2025 Architecture: WINDOWS Score: 100 36 www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->36 38 ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->38 40 77026.bodis.com 2->40 48 Suricata IDS alerts for network traffic 2->48 50 Malicious sample detected (through community Yara rule) 2->50 52 Antivirus detection for URL or domain 2->52 54 7 other signatures 2->54 9 loaddll32.exe 1 2->9         started        11 mssecsvr.exe 12 2->11         started        signatures3 process4 dnsIp5 15 rundll32.exe 9->15         started        18 cmd.exe 1 9->18         started        20 conhost.exe 9->20         started        22 rundll32.exe 1 9->22         started        42 192.168.2.100 unknown unknown 11->42 44 192.168.2.102 unknown unknown 11->44 46 98 other IPs or domains 11->46 56 Connects to many different private IPs via SMB (likely to spread or exploit) 11->56 58 Connects to many different private IPs (likely to spread or exploit) 11->58 signatures6 process7 signatures8 60 Drops executables to the windows directory (C:\Windows) and starts them 15->60 24 mssecsvr.exe 13 15->24         started        27 rundll32.exe 18->27         started        process9 file10 32 C:\WINDOWS\qeriuwjhrf (copy), PE32 24->32 dropped 29 mssecsvr.exe 13 27->29         started        process11 file12 34 C:\Windows\tasksche.exe, PE32 29->34 dropped

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                hVgcaX2SV8.dll93%VirustotalBrowse
                hVgcaX2SV8.dll92%ReversingLabsWin32.Ransomware.WannaCry
                hVgcaX2SV8.dll100%AviraTR/Ransom.Gen
                hVgcaX2SV8.dll100%Joe Sandbox ML
                SourceDetectionScannerLabelLink
                C:\Windows\tasksche.exe100%Joe Sandbox ML
                C:\WINDOWS\qeriuwjhrf (copy)81%ReversingLabsWin32.Trojan.VFlooder
                C:\Windows\tasksche.exe81%ReversingLabsWin32.Trojan.VFlooder
                No Antivirus matches
                No Antivirus matches
                SourceDetectionScannerLabelLink
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comNm0%Avira URL Cloudsafe
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431f5d100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Q100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/1100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431f100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f039100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f0100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294e100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294e47100%Avira URL Cloudmalware
                NameIPActiveMaliciousAntivirus DetectionReputation
                77026.bodis.com
                199.59.243.228
                truefalse
                  high
                  www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                  103.224.212.215
                  truefalse
                    high
                    ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                    unknown
                    unknownfalse
                      high
                      NameMaliciousAntivirus DetectionReputation
                      http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431f5dfalse
                      • Avira URL Cloud: malware
                      unknown
                      http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/false
                        high
                        http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f039false
                        • Avira URL Cloud: malware
                        unknown
                        http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294e47false
                        • Avira URL Cloud: malware
                        unknown
                        NameSourceMaliciousAntivirus DetectionReputation
                        http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comNmmssecsvr.exe, 00000009.00000002.2151839433.00000000009F8000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/mssecsvr.exe, 00000009.00000002.2151839433.0000000000A50000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comhVgcaX2SV8.dllfalse
                            high
                            http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/1mssecsvr.exe, 00000009.00000002.2151839433.0000000000A50000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: malware
                            unknown
                            http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Qmssecsvr.exe, 00000009.00000002.2151839433.0000000000A50000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: malware
                            unknown
                            http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294emssecsvr.exe, 00000007.00000002.2773536526.0000000000B9B000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2773536526.0000000000BED000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: malware
                            unknown
                            http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJmssecsvr.exe, 00000007.00000002.2772976788.000000000019D000.00000004.00000010.00020000.00000000.sdmpfalse
                              high
                              http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Xmmssecsvr.exe, 00000009.00000002.2151839433.00000000009F8000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431fmssecsvr.exe, 00000005.00000002.2137869882.0000000000B8E000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: malware
                                unknown
                                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f0mssecsvr.exe, 00000009.00000002.2151839433.0000000000A2D000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: malware
                                unknown
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/pmssecsvr.exe, 00000005.00000002.2137869882.0000000000B8E000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  30.129.64.110
                                  unknownUnited States
                                  7922COMCAST-7922USfalse
                                  170.151.136.20
                                  unknownUnited States
                                  19115CHARTER-19115-DCUSfalse
                                  122.200.21.252
                                  unknownIndia
                                  38310ICAN-AS-APiCanSolutionsPvtLtdASINfalse
                                  5.92.127.2
                                  unknownItaly
                                  30722VODAFONE-IT-ASNITfalse
                                  5.92.127.1
                                  unknownItaly
                                  30722VODAFONE-IT-ASNITfalse
                                  219.202.225.1
                                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                                  147.140.226.125
                                  unknownUnited States
                                  22644TJUHUSfalse
                                  170.151.136.1
                                  unknownUnited States
                                  19115CHARTER-19115-DCUSfalse
                                  45.33.237.189
                                  unknownUnited States
                                  30848IT-TWT-ASITfalse
                                  38.242.199.232
                                  unknownUnited States
                                  36336NATIXISUSfalse
                                  209.178.43.113
                                  unknownUnited States
                                  7029WINDSTREAMUSfalse
                                  122.101.248.1
                                  unknownKorea Republic of
                                  6619SAMSUNGSDS-AS-KRSamsungSDSIncKRfalse
                                  122.101.248.2
                                  unknownKorea Republic of
                                  6619SAMSUNGSDS-AS-KRSamsungSDSIncKRfalse
                                  167.35.109.2
                                  unknownCanada
                                  2665CDAGOVNCAfalse
                                  167.35.109.1
                                  unknownCanada
                                  2665CDAGOVNCAfalse
                                  219.202.225.135
                                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                                  48.223.148.157
                                  unknownUnited States
                                  2686ATGS-MMD-ASUSfalse
                                  66.43.16.61
                                  unknownUnited States
                                  14233ANCESTRY-INCUSfalse
                                  124.91.26.1
                                  unknownChina
                                  4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                                  IP
                                  192.168.2.148
                                  192.168.2.149
                                  192.168.2.146
                                  192.168.2.147
                                  192.168.2.140
                                  192.168.2.141
                                  192.168.2.144
                                  192.168.2.145
                                  192.168.2.142
                                  192.168.2.143
                                  192.168.2.159
                                  192.168.2.157
                                  192.168.2.158
                                  192.168.2.151
                                  192.168.2.152
                                  192.168.2.150
                                  192.168.2.155
                                  192.168.2.156
                                  192.168.2.153
                                  192.168.2.154
                                  192.168.2.126
                                  192.168.2.247
                                  192.168.2.127
                                  192.168.2.248
                                  192.168.2.124
                                  192.168.2.245
                                  192.168.2.125
                                  192.168.2.246
                                  192.168.2.128
                                  192.168.2.249
                                  192.168.2.129
                                  192.168.2.240
                                  192.168.2.122
                                  192.168.2.243
                                  192.168.2.123
                                  192.168.2.244
                                  192.168.2.120
                                  192.168.2.241
                                  192.168.2.121
                                  192.168.2.242
                                  192.168.2.97
                                  192.168.2.137
                                  192.168.2.96
                                  192.168.2.138
                                  192.168.2.99
                                  192.168.2.135
                                  192.168.2.98
                                  192.168.2.136
                                  192.168.2.139
                                  192.168.2.250
                                  192.168.2.130
                                  192.168.2.251
                                  192.168.2.91
                                  192.168.2.90
                                  192.168.2.93
                                  192.168.2.133
                                  192.168.2.254
                                  192.168.2.92
                                  192.168.2.134
                                  192.168.2.95
                                  192.168.2.131
                                  192.168.2.252
                                  192.168.2.94
                                  192.168.2.132
                                  192.168.2.253
                                  192.168.2.104
                                  192.168.2.225
                                  192.168.2.105
                                  192.168.2.226
                                  192.168.2.102
                                  192.168.2.223
                                  192.168.2.103
                                  192.168.2.224
                                  192.168.2.108
                                  192.168.2.229
                                  192.168.2.109
                                  192.168.2.106
                                  192.168.2.227
                                  192.168.2.107
                                  192.168.2.228
                                  192.168.2.100
                                  Joe Sandbox version:42.0.0 Malachite
                                  Analysis ID:1591526
                                  Start date and time:2025-01-15 02:57:30 +01:00
                                  Joe Sandbox product:CloudBasic
                                  Overall analysis duration:0h 5m 43s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                  Number of analysed new started processes analysed:12
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Sample name:hVgcaX2SV8.dll
                                  renamed because original name is a hash value
                                  Original Sample Name:28d079409d4015dffe55191250e7eed4.dll
                                  Detection:MAL
                                  Classification:mal100.rans.expl.evad.winDLL@18/2@2/100
                                  EGA Information:
                                  • Successful, ratio: 100%
                                  HCA Information:Failed
                                  Cookbook Comments:
                                  • Found application associated with file extension: .dll
                                  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                  • Excluded IPs from analysis (whitelisted): 199.232.210.172, 184.30.131.245, 13.107.246.45, 172.202.163.200
                                  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  TimeTypeDescription
                                  20:58:30API Interceptor1x Sleep call for process: loaddll32.exe modified
                                  20:59:04API Interceptor112x Sleep call for process: mssecsvr.exe modified
                                  No context
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  77026.bodis.comGUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  D3W41IdtQA.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  F1G5BkUV74.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  04Ct9PoJrL.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  sLlAsC4I5r.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  habHh1BC0L.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  19MgUpI9tj.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  ruXU7wj3X9.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  eIZi481eP6.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  m9oUIFauYl.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comGUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  D3W41IdtQA.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  F1G5BkUV74.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  04Ct9PoJrL.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  sLlAsC4I5r.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  habHh1BC0L.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  19MgUpI9tj.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  ruXU7wj3X9.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  eIZi481eP6.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  m9oUIFauYl.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  VODAFONE-IT-ASNITGUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                  • 188.217.194.1
                                  i486.elfGet hashmaliciousUnknownBrowse
                                  • 5.90.249.246
                                  elitebotnet.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 2.46.86.103
                                  6.elfGet hashmaliciousUnknownBrowse
                                  • 31.26.67.104
                                  5.elfGet hashmaliciousUnknownBrowse
                                  • 2.40.217.192
                                  res.sh4.elfGet hashmaliciousUnknownBrowse
                                  • 91.81.135.120
                                  res.ppc.elfGet hashmaliciousUnknownBrowse
                                  • 31.27.46.164
                                  3.elfGet hashmaliciousUnknownBrowse
                                  • 5.95.28.139
                                  6.elfGet hashmaliciousUnknownBrowse
                                  • 83.224.254.117
                                  3.elfGet hashmaliciousUnknownBrowse
                                  • 2.32.151.111
                                  COMCAST-7922US542CxvZnI5.dllGet hashmaliciousVirut, WannacryBrowse
                                  • 26.51.77.154
                                  GUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                  • 30.7.203.119
                                  6fRzgDuqWT.dllGet hashmaliciousWannacryBrowse
                                  • 26.174.0.83
                                  tTbeoLWNhb.dllGet hashmaliciousWannacryBrowse
                                  • 28.124.93.83
                                  F1G5BkUV74.dllGet hashmaliciousWannacryBrowse
                                  • 96.221.78.64
                                  bopY0ot9wf.dllGet hashmaliciousWannacryBrowse
                                  • 73.163.6.192
                                  19MgUpI9tj.dllGet hashmaliciousWannacryBrowse
                                  • 75.65.143.1
                                  YZJG8NuHEP.dllGet hashmaliciousWannacryBrowse
                                  • 29.248.211.36
                                  87c6RORO31.dllGet hashmaliciousWannacryBrowse
                                  • 26.28.204.104
                                  Yx3rRuVx3c.dllGet hashmaliciousWannacryBrowse
                                  • 26.34.166.1
                                  CHARTER-19115-DCUSnshmpsl.elfGet hashmaliciousMiraiBrowse
                                  • 170.151.221.49
                                  nshkarm.elfGet hashmaliciousMiraiBrowse
                                  • 104.138.97.154
                                  loligang.mpsl.elfGet hashmaliciousMiraiBrowse
                                  • 170.151.209.153
                                  sh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 47.3.89.82
                                  amen.arm6.elfGet hashmaliciousMiraiBrowse
                                  • 170.151.208.43
                                  amen.ppc.elfGet hashmaliciousMiraiBrowse
                                  • 170.151.209.155
                                  bin.sh.elfGet hashmaliciousMiraiBrowse
                                  • 170.151.110.228
                                  sh4.elfGet hashmaliciousUnknownBrowse
                                  • 98.8.37.179
                                  kkkarm.elfGet hashmaliciousUnknownBrowse
                                  • 47.3.254.115
                                  la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                  • 170.151.58.165
                                  No context
                                  No context
                                  Process:C:\Windows\mssecsvr.exe
                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):2061938
                                  Entropy (8bit):5.157686687232878
                                  Encrypted:false
                                  SSDEEP:24576:tiIfEqSirYbcMNgef0QeQjG/D8kIqRYsm:X7SPbcBVQej/1jm
                                  MD5:19CB7407A61FF21C0443E2D6BEEB524B
                                  SHA1:6A87D25C84D2864148FE4039EE66DACF35AF1DAC
                                  SHA-256:77F5B72CFD3B90230505F5BECDEFF191EBDF7933FD1669417276606C6625CA41
                                  SHA-512:5E145DED73CF59E03D9B5B141F8E2C310DB7CF8876885ACBE254AC0F92F0692FE2AD75227C7EE135D449AC3C5AE97632C70E8F64E452F34CF4EF06BDD3B84721
                                  Malicious:true
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 81%
                                  Reputation:low
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Windows\mssecsvr.exe
                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):2061938
                                  Entropy (8bit):5.157686687232878
                                  Encrypted:false
                                  SSDEEP:24576:tiIfEqSirYbcMNgef0QeQjG/D8kIqRYsm:X7SPbcBVQej/1jm
                                  MD5:19CB7407A61FF21C0443E2D6BEEB524B
                                  SHA1:6A87D25C84D2864148FE4039EE66DACF35AF1DAC
                                  SHA-256:77F5B72CFD3B90230505F5BECDEFF191EBDF7933FD1669417276606C6625CA41
                                  SHA-512:5E145DED73CF59E03D9B5B141F8E2C310DB7CF8876885ACBE254AC0F92F0692FE2AD75227C7EE135D449AC3C5AE97632C70E8F64E452F34CF4EF06BDD3B84721
                                  Malicious:true
                                  Antivirus:
                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                  • Antivirus: ReversingLabs, Detection: 81%
                                  Reputation:low
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                  File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Entropy (8bit):2.6636042568344824
                                  TrID:
                                  • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                                  • Generic Win/DOS Executable (2004/3) 0.20%
                                  • DOS Executable Generic (2002/1) 0.20%
                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                  File name:hVgcaX2SV8.dll
                                  File size:5'267'459 bytes
                                  MD5:28d079409d4015dffe55191250e7eed4
                                  SHA1:57ea441d26af37a11145ca842b26ea81eeca6a72
                                  SHA256:a062d5c2b65fa65dbadbc5e42b4af0e97cfab15f67280cb8b87068236a793ae4
                                  SHA512:9dfff42553c23ce2aa8d70f4d8b14b4b65427be2cea51f9bbcda1f1ad04db4c987e8252c4a58632111a01b3db64f0e8a4e190306cd42b70fd4e3418333566dcc
                                  SSDEEP:24576:RbLguriIfEqSirYbcMNgef0QeQjG/D8kIqRYs:Rnp7SPbcBVQej/1j
                                  TLSH:4436237234DC80B4D507323494778F26A5BA7C39227AA94FAF904E352F23B92E719753
                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}.r_9...9...9.......=...9...6.....A.:.......8.......8.......:...Rich9...........................PE..L...QW.Y...........!.......
                                  Icon Hash:7ae282899bbab082
                                  Entrypoint:0x100011e9
                                  Entrypoint Section:.text
                                  Digitally signed:false
                                  Imagebase:0x10000000
                                  Subsystem:windows gui
                                  Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                                  DLL Characteristics:
                                  Time Stamp:0x59145751 [Thu May 11 12:21:37 2017 UTC]
                                  TLS Callbacks:
                                  CLR (.Net) Version:
                                  OS Version Major:4
                                  OS Version Minor:0
                                  File Version Major:4
                                  File Version Minor:0
                                  Subsystem Version Major:4
                                  Subsystem Version Minor:0
                                  Import Hash:2e5708ae5fed0403e8117c645fb23e5b
                                  Instruction
                                  push ebp
                                  mov ebp, esp
                                  push ebx
                                  mov ebx, dword ptr [ebp+08h]
                                  push esi
                                  mov esi, dword ptr [ebp+0Ch]
                                  push edi
                                  mov edi, dword ptr [ebp+10h]
                                  test esi, esi
                                  jne 00007F496C60212Bh
                                  cmp dword ptr [10003140h], 00000000h
                                  jmp 00007F496C602148h
                                  cmp esi, 01h
                                  je 00007F496C602127h
                                  cmp esi, 02h
                                  jne 00007F496C602144h
                                  mov eax, dword ptr [10003150h]
                                  test eax, eax
                                  je 00007F496C60212Bh
                                  push edi
                                  push esi
                                  push ebx
                                  call eax
                                  test eax, eax
                                  je 00007F496C60212Eh
                                  push edi
                                  push esi
                                  push ebx
                                  call 00007F496C60203Ah
                                  test eax, eax
                                  jne 00007F496C602126h
                                  xor eax, eax
                                  jmp 00007F496C602170h
                                  push edi
                                  push esi
                                  push ebx
                                  call 00007F496C601EECh
                                  cmp esi, 01h
                                  mov dword ptr [ebp+0Ch], eax
                                  jne 00007F496C60212Eh
                                  test eax, eax
                                  jne 00007F496C602159h
                                  push edi
                                  push eax
                                  push ebx
                                  call 00007F496C602016h
                                  test esi, esi
                                  je 00007F496C602127h
                                  cmp esi, 03h
                                  jne 00007F496C602148h
                                  push edi
                                  push esi
                                  push ebx
                                  call 00007F496C602005h
                                  test eax, eax
                                  jne 00007F496C602125h
                                  and dword ptr [ebp+0Ch], eax
                                  cmp dword ptr [ebp+0Ch], 00000000h
                                  je 00007F496C602133h
                                  mov eax, dword ptr [10003150h]
                                  test eax, eax
                                  je 00007F496C60212Ah
                                  push edi
                                  push esi
                                  push ebx
                                  call eax
                                  mov dword ptr [ebp+0Ch], eax
                                  mov eax, dword ptr [ebp+0Ch]
                                  pop edi
                                  pop esi
                                  pop ebx
                                  pop ebp
                                  retn 000Ch
                                  jmp dword ptr [10002028h]
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  Programming Language:
                                  • [ C ] VS98 (6.0) build 8168
                                  • [C++] VS98 (6.0) build 8168
                                  • [RES] VS98 (6.0) cvtres build 1720
                                  • [LNK] VS98 (6.0) imp/exp build 8168
                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x21900x48.rdata
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x203c0x3c.rdata
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x40000x500060.rsrc
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x5050000x5c.reloc
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0x20000x3c.rdata
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  .text0x10000x28c0x10008de9a2cb31e4c74bd008b871d14bfafcFalse0.13037109375data1.4429971244731552IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                  .rdata0x20000x1d80x10003dd394f95ab218593f2bc8eb65184db4False0.072509765625data0.7346018133622799IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .data0x30000x1540x10009b27c3f254416f775f5a51102ef8fb84False0.016845703125Matlab v4 mat-file (little endian) C:\%s\%s, numeric, rows 0, columns 00.085726967663312IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .rsrc0x40000x5000600x5010001e5db469859bc724a420d0f56fae1d72unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .reloc0x5050000x2ac0x1000620f0b67a91f7f74151bc5be745b7110False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                  W0x40600x500000dataEnglishUnited States0.8359994888305664
                                  DLLImport
                                  KERNEL32.dllCloseHandle, WriteFile, CreateFileA, SizeofResource, LockResource, LoadResource, FindResourceA, CreateProcessA
                                  MSVCRT.dllfree, _initterm, malloc, _adjust_fdiv, sprintf
                                  NameOrdinalAddress
                                  PlayGame10x10001114
                                  Language of compilation systemCountry where language is spokenMap
                                  EnglishUnited States
                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                  2025-01-15T02:58:28.485004+01002830018ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup)1192.168.2.5542571.1.1.153UDP
                                  2025-01-15T02:58:29.253435+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.549704103.224.212.21580TCP
                                  2025-01-15T02:58:30.937765+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.549706103.224.212.21580TCP
                                  TimestampSource PortDest PortSource IPDest IP
                                  Jan 15, 2025 02:58:22.019021988 CET49675443192.168.2.523.1.237.91
                                  Jan 15, 2025 02:58:22.019030094 CET49674443192.168.2.523.1.237.91
                                  Jan 15, 2025 02:58:22.144098997 CET49673443192.168.2.523.1.237.91
                                  Jan 15, 2025 02:58:28.648837090 CET4970480192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:28.653867006 CET8049704103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:28.653979063 CET4970480192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:28.654110909 CET4970480192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:28.658914089 CET8049704103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:29.253204107 CET8049704103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:29.253263950 CET8049704103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:29.253434896 CET4970480192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:29.277323008 CET4970480192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:29.282437086 CET8049704103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:29.606517076 CET4970580192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:29.611392975 CET8049705199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:29.611495972 CET4970580192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:29.611684084 CET4970580192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:29.616511106 CET8049705199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:30.068670988 CET8049705199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:30.068720102 CET8049705199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:30.068907976 CET4970580192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:30.157238007 CET4970580192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:30.157336950 CET4970580192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:30.308207035 CET4970680192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:30.312998056 CET8049706103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:30.313086033 CET4970680192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:30.313309908 CET4970680192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:30.318063021 CET8049706103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:30.937666893 CET8049706103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:30.937730074 CET8049706103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:30.937764883 CET4970680192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:30.937860012 CET4970680192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:30.941605091 CET4970680192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:30.942949057 CET4970780192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:30.946391106 CET8049706103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:30.947797060 CET8049707199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:30.948050976 CET4970780192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:30.948050976 CET4970780192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:30.952860117 CET8049707199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:31.361326933 CET4970880192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:31.366168022 CET8049708103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:31.370366096 CET4970880192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:31.370541096 CET4970880192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:31.375250101 CET8049708103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:31.402571917 CET8049707199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:31.402595997 CET8049707199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:31.402666092 CET4970780192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:31.410676003 CET4970780192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:31.410702944 CET4970780192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:31.529385090 CET49709445192.168.2.5167.35.109.228
                                  Jan 15, 2025 02:58:31.534615040 CET44549709167.35.109.228192.168.2.5
                                  Jan 15, 2025 02:58:31.535057068 CET49709445192.168.2.5167.35.109.228
                                  Jan 15, 2025 02:58:31.536079884 CET49709445192.168.2.5167.35.109.228
                                  Jan 15, 2025 02:58:31.536307096 CET49710445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:31.540884972 CET44549709167.35.109.228192.168.2.5
                                  Jan 15, 2025 02:58:31.540931940 CET49709445192.168.2.5167.35.109.228
                                  Jan 15, 2025 02:58:31.541110039 CET44549710167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:31.541187048 CET49710445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:31.541238070 CET49710445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:31.545754910 CET49711445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:31.546062946 CET44549710167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:31.546129942 CET49710445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:31.550601959 CET44549711167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:31.550662041 CET49711445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:31.550749063 CET49711445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:31.555455923 CET44549711167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:31.628177881 CET49675443192.168.2.523.1.237.91
                                  Jan 15, 2025 02:58:31.628215075 CET49674443192.168.2.523.1.237.91
                                  Jan 15, 2025 02:58:31.753168106 CET49673443192.168.2.523.1.237.91
                                  Jan 15, 2025 02:58:31.964457989 CET8049708103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:31.964544058 CET8049708103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:31.964560032 CET4970880192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:31.964596987 CET4970880192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:31.967323065 CET4970880192.168.2.5103.224.212.215
                                  Jan 15, 2025 02:58:31.968660116 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:31.972165108 CET8049708103.224.212.215192.168.2.5
                                  Jan 15, 2025 02:58:31.973447084 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:31.973526001 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:31.973670959 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:31.978535891 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:32.429480076 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:32.429512978 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 02:58:32.429759026 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:32.437789917 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:32.437813044 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 02:58:33.396446943 CET4434970323.1.237.91192.168.2.5
                                  Jan 15, 2025 02:58:33.398441076 CET49703443192.168.2.523.1.237.91
                                  Jan 15, 2025 02:58:33.540196896 CET49735445192.168.2.55.92.127.51
                                  Jan 15, 2025 02:58:33.545157909 CET445497355.92.127.51192.168.2.5
                                  Jan 15, 2025 02:58:33.545264959 CET49735445192.168.2.55.92.127.51
                                  Jan 15, 2025 02:58:33.545361042 CET49735445192.168.2.55.92.127.51
                                  Jan 15, 2025 02:58:33.545728922 CET49736445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:33.550393105 CET445497355.92.127.51192.168.2.5
                                  Jan 15, 2025 02:58:33.550468922 CET49735445192.168.2.55.92.127.51
                                  Jan 15, 2025 02:58:33.550616980 CET445497365.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:33.550713062 CET49736445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:33.550780058 CET49736445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:33.552186966 CET49737445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:33.555632114 CET445497365.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:33.555704117 CET49736445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:33.556982040 CET445497375.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:33.557060957 CET49737445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:33.557120085 CET49737445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:33.561933041 CET445497375.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:35.573782921 CET49759445192.168.2.5161.7.75.74
                                  Jan 15, 2025 02:58:35.578891993 CET44549759161.7.75.74192.168.2.5
                                  Jan 15, 2025 02:58:35.578984976 CET49759445192.168.2.5161.7.75.74
                                  Jan 15, 2025 02:58:35.580044031 CET49759445192.168.2.5161.7.75.74
                                  Jan 15, 2025 02:58:35.580238104 CET49760445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:35.585249901 CET44549760161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:35.585279942 CET44549759161.7.75.74192.168.2.5
                                  Jan 15, 2025 02:58:35.585314035 CET49760445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:35.585342884 CET49759445192.168.2.5161.7.75.74
                                  Jan 15, 2025 02:58:35.585418940 CET49760445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:35.588762999 CET49761445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:35.590382099 CET44549760161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:35.590449095 CET49760445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:35.593534946 CET44549761161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:35.593625069 CET49761445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:35.593688011 CET49761445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:35.598426104 CET44549761161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:37.585675001 CET49781445192.168.2.540.92.175.109
                                  Jan 15, 2025 02:58:37.590558052 CET4454978140.92.175.109192.168.2.5
                                  Jan 15, 2025 02:58:37.590662003 CET49781445192.168.2.540.92.175.109
                                  Jan 15, 2025 02:58:37.590677977 CET49781445192.168.2.540.92.175.109
                                  Jan 15, 2025 02:58:37.590816021 CET49783445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:37.595629930 CET4454978340.92.175.1192.168.2.5
                                  Jan 15, 2025 02:58:37.595679998 CET4454978140.92.175.109192.168.2.5
                                  Jan 15, 2025 02:58:37.595732927 CET49781445192.168.2.540.92.175.109
                                  Jan 15, 2025 02:58:37.595824957 CET49783445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:37.595865011 CET49783445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:37.598352909 CET49784445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:37.600826979 CET4454978340.92.175.1192.168.2.5
                                  Jan 15, 2025 02:58:37.600891113 CET49783445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:37.603159904 CET4454978440.92.175.1192.168.2.5
                                  Jan 15, 2025 02:58:37.603250027 CET49784445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:37.603291035 CET49784445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:37.608098984 CET4454978440.92.175.1192.168.2.5
                                  Jan 15, 2025 02:58:39.598370075 CET49806445192.168.2.5223.67.238.124
                                  Jan 15, 2025 02:58:39.603358030 CET44549806223.67.238.124192.168.2.5
                                  Jan 15, 2025 02:58:39.603482008 CET49806445192.168.2.5223.67.238.124
                                  Jan 15, 2025 02:58:39.603528023 CET49806445192.168.2.5223.67.238.124
                                  Jan 15, 2025 02:58:39.603763103 CET49807445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:58:39.608531952 CET44549806223.67.238.124192.168.2.5
                                  Jan 15, 2025 02:58:39.608599901 CET49806445192.168.2.5223.67.238.124
                                  Jan 15, 2025 02:58:39.608705044 CET44549807223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:58:39.608784914 CET49807445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:58:39.608865976 CET49807445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:58:39.609831095 CET49808445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:58:39.613805056 CET44549807223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:58:39.613866091 CET49807445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:58:39.614729881 CET44549808223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:58:39.614797115 CET49808445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:58:39.614900112 CET49808445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:58:39.619703054 CET44549808223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:58:41.613859892 CET49838445192.168.2.566.102.158.38
                                  Jan 15, 2025 02:58:41.618644953 CET4454983866.102.158.38192.168.2.5
                                  Jan 15, 2025 02:58:41.618752003 CET49838445192.168.2.566.102.158.38
                                  Jan 15, 2025 02:58:41.618752003 CET49838445192.168.2.566.102.158.38
                                  Jan 15, 2025 02:58:41.618916035 CET49839445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:41.623663902 CET4454983966.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:41.623728991 CET49839445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:41.623735905 CET4454983866.102.158.38192.168.2.5
                                  Jan 15, 2025 02:58:41.623795033 CET49838445192.168.2.566.102.158.38
                                  Jan 15, 2025 02:58:41.623867989 CET49839445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:41.624923944 CET49840445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:41.628680944 CET4454983966.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:41.628803015 CET49839445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:41.630242109 CET4454984066.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:41.630315065 CET49840445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:41.630341053 CET49840445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:41.637433052 CET4454984066.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:43.288295031 CET4454984066.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:43.288387060 CET49840445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:43.288434982 CET49840445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:43.288538933 CET49840445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:43.293759108 CET4454984066.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:43.293773890 CET4454984066.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:43.628730059 CET49877445192.168.2.5136.61.41.150
                                  Jan 15, 2025 02:58:43.633697033 CET44549877136.61.41.150192.168.2.5
                                  Jan 15, 2025 02:58:43.633779049 CET49877445192.168.2.5136.61.41.150
                                  Jan 15, 2025 02:58:43.633867979 CET49877445192.168.2.5136.61.41.150
                                  Jan 15, 2025 02:58:43.634042978 CET49878445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:58:43.638765097 CET44549877136.61.41.150192.168.2.5
                                  Jan 15, 2025 02:58:43.638794899 CET44549878136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:58:43.638874054 CET49877445192.168.2.5136.61.41.150
                                  Jan 15, 2025 02:58:43.638875008 CET49878445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:58:43.638952017 CET49878445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:58:43.639462948 CET49879445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:58:43.643846989 CET44549878136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:58:43.643922091 CET49878445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:58:43.644228935 CET44549879136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:58:43.644289017 CET49879445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:58:43.644519091 CET49879445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:58:43.649260044 CET44549879136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:58:45.644371033 CET49914445192.168.2.5122.101.248.12
                                  Jan 15, 2025 02:58:45.649785995 CET44549914122.101.248.12192.168.2.5
                                  Jan 15, 2025 02:58:45.649876118 CET49914445192.168.2.5122.101.248.12
                                  Jan 15, 2025 02:58:45.649899006 CET49914445192.168.2.5122.101.248.12
                                  Jan 15, 2025 02:58:45.650043964 CET49915445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:58:45.656443119 CET44549915122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:58:45.656502962 CET44549914122.101.248.12192.168.2.5
                                  Jan 15, 2025 02:58:45.656538963 CET49915445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:58:45.656579018 CET49914445192.168.2.5122.101.248.12
                                  Jan 15, 2025 02:58:45.656688929 CET49915445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:58:45.657020092 CET49916445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:58:45.661591053 CET44549915122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:58:45.661657095 CET49915445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:58:45.661896944 CET44549916122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:58:45.661958933 CET49916445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:58:45.661993027 CET49916445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:58:45.667736053 CET44549916122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:58:46.300494909 CET49925445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:46.332814932 CET4454992566.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:46.332947016 CET49925445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:46.333086967 CET49925445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:46.340704918 CET4454992566.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:47.660022020 CET49949445192.168.2.566.43.16.61
                                  Jan 15, 2025 02:58:47.664927959 CET4454994966.43.16.61192.168.2.5
                                  Jan 15, 2025 02:58:47.665052891 CET49949445192.168.2.566.43.16.61
                                  Jan 15, 2025 02:58:47.665100098 CET49949445192.168.2.566.43.16.61
                                  Jan 15, 2025 02:58:47.665255070 CET49951445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:58:47.669984102 CET4454994966.43.16.61192.168.2.5
                                  Jan 15, 2025 02:58:47.670093060 CET49949445192.168.2.566.43.16.61
                                  Jan 15, 2025 02:58:47.670098066 CET4454995166.43.16.1192.168.2.5
                                  Jan 15, 2025 02:58:47.670171022 CET49951445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:58:47.670303106 CET49951445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:58:47.671329021 CET49952445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:58:47.675199986 CET4454995166.43.16.1192.168.2.5
                                  Jan 15, 2025 02:58:47.675271034 CET49951445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:58:47.676239014 CET4454995266.43.16.1192.168.2.5
                                  Jan 15, 2025 02:58:47.676340103 CET49952445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:58:47.676438093 CET49952445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:58:47.681324005 CET4454995266.43.16.1192.168.2.5
                                  Jan 15, 2025 02:58:48.000591040 CET4454992566.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:48.000690937 CET49925445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:48.000802040 CET49925445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:48.000873089 CET49925445192.168.2.566.102.158.1
                                  Jan 15, 2025 02:58:48.006731987 CET4454992566.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:48.006761074 CET4454992566.102.158.1192.168.2.5
                                  Jan 15, 2025 02:58:48.066070080 CET49959445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:58:48.070972919 CET4454995966.102.158.2192.168.2.5
                                  Jan 15, 2025 02:58:48.071101904 CET49959445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:58:48.071183920 CET49959445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:58:48.071618080 CET49960445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:58:48.076229095 CET4454995966.102.158.2192.168.2.5
                                  Jan 15, 2025 02:58:48.076311111 CET49959445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:58:48.076502085 CET4454996066.102.158.2192.168.2.5
                                  Jan 15, 2025 02:58:48.076948881 CET49960445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:58:48.076948881 CET49960445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:58:48.081814051 CET4454996066.102.158.2192.168.2.5
                                  Jan 15, 2025 02:58:49.682751894 CET49988445192.168.2.5197.168.4.72
                                  Jan 15, 2025 02:58:49.687602997 CET44549988197.168.4.72192.168.2.5
                                  Jan 15, 2025 02:58:49.687680006 CET49988445192.168.2.5197.168.4.72
                                  Jan 15, 2025 02:58:49.687709093 CET49988445192.168.2.5197.168.4.72
                                  Jan 15, 2025 02:58:49.687844992 CET49990445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:58:49.692660093 CET44549990197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:58:49.692672014 CET44549988197.168.4.72192.168.2.5
                                  Jan 15, 2025 02:58:49.692739964 CET49990445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:58:49.692769051 CET49988445192.168.2.5197.168.4.72
                                  Jan 15, 2025 02:58:49.692879915 CET49990445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:58:49.693190098 CET49991445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:58:49.697731018 CET44549990197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:58:49.697782993 CET49990445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:58:49.697993040 CET44549991197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:58:49.698147058 CET49991445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:58:49.698147058 CET49991445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:58:49.702936888 CET44549991197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:58:51.691091061 CET50022445192.168.2.538.242.199.232
                                  Jan 15, 2025 02:58:51.695919991 CET4455002238.242.199.232192.168.2.5
                                  Jan 15, 2025 02:58:51.696002007 CET50022445192.168.2.538.242.199.232
                                  Jan 15, 2025 02:58:51.696014881 CET50022445192.168.2.538.242.199.232
                                  Jan 15, 2025 02:58:51.696099043 CET50023445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:58:51.700889111 CET4455002338.242.199.1192.168.2.5
                                  Jan 15, 2025 02:58:51.700927973 CET4455002238.242.199.232192.168.2.5
                                  Jan 15, 2025 02:58:51.701103926 CET50022445192.168.2.538.242.199.232
                                  Jan 15, 2025 02:58:51.701198101 CET50023445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:58:51.701376915 CET50024445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:58:51.706187963 CET4455002338.242.199.1192.168.2.5
                                  Jan 15, 2025 02:58:51.706199884 CET4455002438.242.199.1192.168.2.5
                                  Jan 15, 2025 02:58:51.706252098 CET50023445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:58:51.706285000 CET50024445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:58:51.706312895 CET50024445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:58:51.711148977 CET4455002438.242.199.1192.168.2.5
                                  Jan 15, 2025 02:58:52.929212093 CET44549711167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:52.929296017 CET49711445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:52.929349899 CET49711445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:52.929406881 CET49711445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:52.934118986 CET44549711167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:52.934130907 CET44549711167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:53.707093000 CET50057445192.168.2.534.28.85.153
                                  Jan 15, 2025 02:58:53.711977005 CET4455005734.28.85.153192.168.2.5
                                  Jan 15, 2025 02:58:53.712161064 CET50057445192.168.2.534.28.85.153
                                  Jan 15, 2025 02:58:53.712342978 CET50057445192.168.2.534.28.85.153
                                  Jan 15, 2025 02:58:53.712579966 CET50058445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:58:53.717370987 CET4455005834.28.85.1192.168.2.5
                                  Jan 15, 2025 02:58:53.717386961 CET4455005734.28.85.153192.168.2.5
                                  Jan 15, 2025 02:58:53.717478037 CET50057445192.168.2.534.28.85.153
                                  Jan 15, 2025 02:58:53.717494011 CET50058445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:58:53.717545033 CET50058445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:58:53.717895031 CET50059445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:58:53.722460985 CET4455005834.28.85.1192.168.2.5
                                  Jan 15, 2025 02:58:53.722548008 CET50058445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:58:53.722678900 CET4455005934.28.85.1192.168.2.5
                                  Jan 15, 2025 02:58:53.722738981 CET50059445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:58:53.722770929 CET50059445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:58:53.727488995 CET4455005934.28.85.1192.168.2.5
                                  Jan 15, 2025 02:58:54.946738005 CET445497375.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:54.946903944 CET49737445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:54.946970940 CET49737445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:54.947043896 CET49737445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:54.951796055 CET445497375.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:54.951827049 CET445497375.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:55.722512960 CET50091445192.168.2.5117.2.101.56
                                  Jan 15, 2025 02:58:55.727375984 CET44550091117.2.101.56192.168.2.5
                                  Jan 15, 2025 02:58:55.727471113 CET50091445192.168.2.5117.2.101.56
                                  Jan 15, 2025 02:58:55.727505922 CET50091445192.168.2.5117.2.101.56
                                  Jan 15, 2025 02:58:55.727699995 CET50093445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:58:55.732561111 CET44550093117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:58:55.732574940 CET44550091117.2.101.56192.168.2.5
                                  Jan 15, 2025 02:58:55.732681990 CET50093445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:58:55.732681990 CET50091445192.168.2.5117.2.101.56
                                  Jan 15, 2025 02:58:55.733163118 CET50094445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:58:55.737627029 CET44550093117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:58:55.737711906 CET50093445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:58:55.738003016 CET44550094117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:58:55.738071918 CET50094445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:58:55.738116026 CET50094445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:58:55.742883921 CET44550094117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:58:55.941154957 CET50100445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:55.946099997 CET44550100167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:55.946331978 CET50100445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:55.946358919 CET50100445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:58:55.951116085 CET44550100167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:58:56.958698988 CET44549761161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:56.958854914 CET49761445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:56.958919048 CET49761445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:56.958992958 CET49761445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:56.963850975 CET44549761161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:56.963872910 CET44549761161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:57.738341093 CET50109445192.168.2.548.111.230.181
                                  Jan 15, 2025 02:58:57.743119001 CET4455010948.111.230.181192.168.2.5
                                  Jan 15, 2025 02:58:57.743246078 CET50109445192.168.2.548.111.230.181
                                  Jan 15, 2025 02:58:57.743385077 CET50109445192.168.2.548.111.230.181
                                  Jan 15, 2025 02:58:57.743762016 CET50110445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:58:57.748264074 CET4455010948.111.230.181192.168.2.5
                                  Jan 15, 2025 02:58:57.748357058 CET50109445192.168.2.548.111.230.181
                                  Jan 15, 2025 02:58:57.748589993 CET4455011048.111.230.1192.168.2.5
                                  Jan 15, 2025 02:58:57.748670101 CET50110445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:58:57.748748064 CET50110445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:58:57.749165058 CET50111445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:58:57.753535986 CET4455011048.111.230.1192.168.2.5
                                  Jan 15, 2025 02:58:57.753699064 CET50110445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:58:57.754009008 CET4455011148.111.230.1192.168.2.5
                                  Jan 15, 2025 02:58:57.754080057 CET50111445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:58:57.754121065 CET50111445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:58:57.758881092 CET4455011148.111.230.1192.168.2.5
                                  Jan 15, 2025 02:58:57.956892967 CET50113445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:57.961776972 CET445501135.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:57.961860895 CET50113445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:57.961957932 CET50113445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:58:57.966743946 CET445501135.92.127.1192.168.2.5
                                  Jan 15, 2025 02:58:59.009268999 CET4454978440.92.175.1192.168.2.5
                                  Jan 15, 2025 02:58:59.012890100 CET49784445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:59.012936115 CET49784445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:59.013011932 CET49784445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:58:59.017764091 CET4454978440.92.175.1192.168.2.5
                                  Jan 15, 2025 02:58:59.017837048 CET4454978440.92.175.1192.168.2.5
                                  Jan 15, 2025 02:58:59.753937960 CET50123445192.168.2.575.199.66.17
                                  Jan 15, 2025 02:58:59.758758068 CET4455012375.199.66.17192.168.2.5
                                  Jan 15, 2025 02:58:59.758843899 CET50123445192.168.2.575.199.66.17
                                  Jan 15, 2025 02:58:59.758910894 CET50123445192.168.2.575.199.66.17
                                  Jan 15, 2025 02:58:59.759174109 CET50124445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:58:59.763885021 CET4455012375.199.66.17192.168.2.5
                                  Jan 15, 2025 02:58:59.763951063 CET50123445192.168.2.575.199.66.17
                                  Jan 15, 2025 02:58:59.764002085 CET4455012475.199.66.1192.168.2.5
                                  Jan 15, 2025 02:58:59.764081955 CET50124445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:58:59.764132977 CET50124445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:58:59.764559031 CET50125445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:58:59.769094944 CET4455012475.199.66.1192.168.2.5
                                  Jan 15, 2025 02:58:59.769167900 CET50124445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:58:59.769376040 CET4455012575.199.66.1192.168.2.5
                                  Jan 15, 2025 02:58:59.769448996 CET50125445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:58:59.769463062 CET50125445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:58:59.774296999 CET4455012575.199.66.1192.168.2.5
                                  Jan 15, 2025 02:58:59.972235918 CET50127445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:59.976990938 CET44550127161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:58:59.977086067 CET50127445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:59.977142096 CET50127445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:58:59.981895924 CET44550127161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:59:00.972453117 CET44549808223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:00.974370956 CET49808445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:00.974426985 CET49808445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:00.974499941 CET49808445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:00.979422092 CET44549808223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:00.979433060 CET44549808223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:01.803594112 CET50136445192.168.2.576.182.197.189
                                  Jan 15, 2025 02:59:01.808383942 CET4455013676.182.197.189192.168.2.5
                                  Jan 15, 2025 02:59:01.808481932 CET50136445192.168.2.576.182.197.189
                                  Jan 15, 2025 02:59:01.810055017 CET50136445192.168.2.576.182.197.189
                                  Jan 15, 2025 02:59:01.810252905 CET50137445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:01.814934015 CET4455013676.182.197.189192.168.2.5
                                  Jan 15, 2025 02:59:01.815006971 CET50136445192.168.2.576.182.197.189
                                  Jan 15, 2025 02:59:01.815077066 CET4455013776.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:01.815140009 CET50137445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:01.815529108 CET50137445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:01.815927029 CET50138445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:01.820370913 CET4455013776.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:01.820449114 CET50137445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:01.820791006 CET4455013876.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:01.820853949 CET50138445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:01.823900938 CET50138445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:01.828722000 CET4455013876.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:02.041228056 CET50141445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:59:02.046152115 CET4455014140.92.175.1192.168.2.5
                                  Jan 15, 2025 02:59:02.046277046 CET50141445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:59:02.062638998 CET50141445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:59:02.067451000 CET4455014140.92.175.1192.168.2.5
                                  Jan 15, 2025 02:59:03.785015106 CET50151445192.168.2.530.129.64.110
                                  Jan 15, 2025 02:59:03.789851904 CET4455015130.129.64.110192.168.2.5
                                  Jan 15, 2025 02:59:03.790481091 CET50151445192.168.2.530.129.64.110
                                  Jan 15, 2025 02:59:03.790510893 CET50151445192.168.2.530.129.64.110
                                  Jan 15, 2025 02:59:03.790700912 CET50152445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:03.795569897 CET4455015130.129.64.110192.168.2.5
                                  Jan 15, 2025 02:59:03.795584917 CET4455015230.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:03.795676947 CET50151445192.168.2.530.129.64.110
                                  Jan 15, 2025 02:59:03.795743942 CET50152445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:03.795881987 CET50152445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:03.796184063 CET50153445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:03.800769091 CET4455015230.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:03.801076889 CET4455015330.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:03.801192999 CET50153445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:03.801213980 CET50152445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:03.801268101 CET50153445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:03.806044102 CET4455015330.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:03.987834930 CET50155445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:03.992738962 CET44550155223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:03.992830038 CET50155445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:03.992888927 CET50155445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:03.997652054 CET44550155223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:04.988100052 CET44549879136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:04.988223076 CET49879445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:04.988289118 CET49879445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:04.988346100 CET49879445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:04.993040085 CET44549879136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:04.993177891 CET44549879136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:05.800668955 CET50164445192.168.2.5124.91.26.128
                                  Jan 15, 2025 02:59:05.805706024 CET44550164124.91.26.128192.168.2.5
                                  Jan 15, 2025 02:59:05.805819988 CET50164445192.168.2.5124.91.26.128
                                  Jan 15, 2025 02:59:05.805819988 CET50164445192.168.2.5124.91.26.128
                                  Jan 15, 2025 02:59:05.805973053 CET50165445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:05.810792923 CET44550165124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:05.810806036 CET44550164124.91.26.128192.168.2.5
                                  Jan 15, 2025 02:59:05.810851097 CET50165445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:05.810960054 CET50164445192.168.2.5124.91.26.128
                                  Jan 15, 2025 02:59:05.810964108 CET50165445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:05.814168930 CET50166445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:05.815768003 CET44550165124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:05.815874100 CET50165445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:05.819055080 CET44550166124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:05.819125891 CET50166445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:05.820954084 CET50166445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:05.825788975 CET44550166124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:07.019622087 CET44549916122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:07.019700050 CET49916445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:07.019753933 CET49916445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:07.019792080 CET49916445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:07.024616957 CET44549916122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:07.024646044 CET44549916122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:07.675585032 CET50178445192.168.2.5197.84.254.223
                                  Jan 15, 2025 02:59:07.680434942 CET44550178197.84.254.223192.168.2.5
                                  Jan 15, 2025 02:59:07.680531025 CET50178445192.168.2.5197.84.254.223
                                  Jan 15, 2025 02:59:07.680557013 CET50178445192.168.2.5197.84.254.223
                                  Jan 15, 2025 02:59:07.680679083 CET50179445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:07.685566902 CET44550178197.84.254.223192.168.2.5
                                  Jan 15, 2025 02:59:07.685584068 CET44550179197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:07.685630083 CET50178445192.168.2.5197.84.254.223
                                  Jan 15, 2025 02:59:07.685662985 CET50179445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:07.685740948 CET50179445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:07.686067104 CET50180445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:07.690632105 CET44550179197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:07.690700054 CET50179445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:07.690910101 CET44550180197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:07.690985918 CET50180445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:07.691055059 CET50180445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:07.695928097 CET44550180197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:08.003551960 CET50182445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:08.009644985 CET44550182136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:08.009887934 CET50182445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:08.009887934 CET50182445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:08.014710903 CET44550182136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:09.052521944 CET4454995266.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:09.052601099 CET49952445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:09.052633047 CET49952445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:09.052668095 CET49952445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:09.057421923 CET4454995266.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:09.057434082 CET4454995266.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:09.425848961 CET50191445192.168.2.579.125.115.104
                                  Jan 15, 2025 02:59:09.430674076 CET4455019179.125.115.104192.168.2.5
                                  Jan 15, 2025 02:59:09.430758953 CET50191445192.168.2.579.125.115.104
                                  Jan 15, 2025 02:59:09.430815935 CET50191445192.168.2.579.125.115.104
                                  Jan 15, 2025 02:59:09.431010008 CET50192445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:09.435684919 CET4455019179.125.115.104192.168.2.5
                                  Jan 15, 2025 02:59:09.435750008 CET50191445192.168.2.579.125.115.104
                                  Jan 15, 2025 02:59:09.435817003 CET4455019279.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:09.435883999 CET50192445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:09.435977936 CET50192445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:09.436306000 CET50193445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:09.440778017 CET4455019279.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:09.440830946 CET50192445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:09.441106081 CET4455019379.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:09.441163063 CET50193445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:09.441198111 CET50193445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:09.445947886 CET4455019379.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:09.459031105 CET4454996066.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:09.459115028 CET49960445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:09.459150076 CET49960445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:09.459187984 CET49960445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:09.463870049 CET4454996066.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:09.463891029 CET4454996066.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:10.034914017 CET50198445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:10.039930105 CET44550198122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:10.040698051 CET50198445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:10.040736914 CET50198445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:10.045759916 CET44550198122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:11.066689014 CET50203445192.168.2.545.33.237.189
                                  Jan 15, 2025 02:59:11.269731045 CET44549991197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:59:11.271933079 CET49991445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:11.272032976 CET49991445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:11.272058964 CET49991445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:11.274719000 CET4455020345.33.237.189192.168.2.5
                                  Jan 15, 2025 02:59:11.274995089 CET50203445192.168.2.545.33.237.189
                                  Jan 15, 2025 02:59:11.277857065 CET44549991197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:59:11.277861118 CET44549991197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:59:11.299959898 CET50203445192.168.2.545.33.237.189
                                  Jan 15, 2025 02:59:11.300215006 CET50204445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:11.307174921 CET4455020345.33.237.189192.168.2.5
                                  Jan 15, 2025 02:59:11.307246923 CET50203445192.168.2.545.33.237.189
                                  Jan 15, 2025 02:59:11.307559013 CET4455020445.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:11.307629108 CET50204445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:11.307737112 CET50204445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:11.308123112 CET50206445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:11.312643051 CET4455020445.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:11.312954903 CET4455020645.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:11.313019991 CET50204445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:11.313050985 CET50206445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:11.314743996 CET50206445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:11.319576025 CET4455020645.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:12.066071987 CET50210445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:12.071933031 CET4455021066.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:12.072037935 CET50210445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:12.072091103 CET50210445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:12.079560995 CET4455021066.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:12.472146034 CET50214445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:12.476973057 CET4455021466.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:12.477138996 CET50214445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:12.477159977 CET50214445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:12.481986046 CET4455021466.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:12.597856045 CET50216445192.168.2.5147.140.226.125
                                  Jan 15, 2025 02:59:12.603166103 CET44550216147.140.226.125192.168.2.5
                                  Jan 15, 2025 02:59:12.606405020 CET50216445192.168.2.5147.140.226.125
                                  Jan 15, 2025 02:59:12.606441975 CET50216445192.168.2.5147.140.226.125
                                  Jan 15, 2025 02:59:12.606614113 CET50217445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:12.611392975 CET44550217147.140.226.1192.168.2.5
                                  Jan 15, 2025 02:59:12.611407995 CET44550216147.140.226.125192.168.2.5
                                  Jan 15, 2025 02:59:12.611474991 CET50216445192.168.2.5147.140.226.125
                                  Jan 15, 2025 02:59:12.611489058 CET50217445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:12.611565113 CET50217445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:12.611809015 CET50218445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:12.616597891 CET44550218147.140.226.1192.168.2.5
                                  Jan 15, 2025 02:59:12.618381977 CET44550217147.140.226.1192.168.2.5
                                  Jan 15, 2025 02:59:12.618401051 CET50218445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:12.618434906 CET50217445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:12.618449926 CET50218445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:12.623191118 CET44550218147.140.226.1192.168.2.5
                                  Jan 15, 2025 02:59:13.065460920 CET4455020645.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:13.065888882 CET50206445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:13.065980911 CET50206445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:13.065980911 CET50206445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:13.070777893 CET4455020645.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:13.070786953 CET4455020645.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:13.082223892 CET4455002438.242.199.1192.168.2.5
                                  Jan 15, 2025 02:59:13.082422018 CET50024445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:59:13.082492113 CET50024445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:59:13.082492113 CET50024445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:59:13.087385893 CET4455002438.242.199.1192.168.2.5
                                  Jan 15, 2025 02:59:13.087398052 CET4455002438.242.199.1192.168.2.5
                                  Jan 15, 2025 02:59:14.019648075 CET50228445192.168.2.5150.215.1.80
                                  Jan 15, 2025 02:59:14.024460077 CET44550228150.215.1.80192.168.2.5
                                  Jan 15, 2025 02:59:14.024580002 CET50228445192.168.2.5150.215.1.80
                                  Jan 15, 2025 02:59:14.024617910 CET50228445192.168.2.5150.215.1.80
                                  Jan 15, 2025 02:59:14.024805069 CET50229445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:14.029607058 CET44550228150.215.1.80192.168.2.5
                                  Jan 15, 2025 02:59:14.029675961 CET50228445192.168.2.5150.215.1.80
                                  Jan 15, 2025 02:59:14.029732943 CET44550229150.215.1.1192.168.2.5
                                  Jan 15, 2025 02:59:14.029799938 CET50229445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:14.029887915 CET50229445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:14.030203104 CET50230445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:14.035952091 CET44550229150.215.1.1192.168.2.5
                                  Jan 15, 2025 02:59:14.035981894 CET44550230150.215.1.1192.168.2.5
                                  Jan 15, 2025 02:59:14.036066055 CET50229445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:14.036135912 CET50230445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:14.036333084 CET50230445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:14.041266918 CET44550230150.215.1.1192.168.2.5
                                  Jan 15, 2025 02:59:14.284686089 CET50233445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:14.289549112 CET44550233197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:59:14.289652109 CET50233445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:14.289689064 CET50233445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:14.294924974 CET44550233197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:59:15.103344917 CET4455005934.28.85.1192.168.2.5
                                  Jan 15, 2025 02:59:15.103506088 CET50059445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:59:15.103506088 CET50059445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:59:15.103602886 CET50059445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:59:15.108302116 CET4455005934.28.85.1192.168.2.5
                                  Jan 15, 2025 02:59:15.108347893 CET4455005934.28.85.1192.168.2.5
                                  Jan 15, 2025 02:59:15.347649097 CET50240445192.168.2.529.183.147.247
                                  Jan 15, 2025 02:59:15.352502108 CET4455024029.183.147.247192.168.2.5
                                  Jan 15, 2025 02:59:15.352585077 CET50240445192.168.2.529.183.147.247
                                  Jan 15, 2025 02:59:15.352616072 CET50240445192.168.2.529.183.147.247
                                  Jan 15, 2025 02:59:15.352750063 CET50241445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:15.357657909 CET4455024129.183.147.1192.168.2.5
                                  Jan 15, 2025 02:59:15.357758045 CET50241445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:15.357758045 CET50241445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:15.358098984 CET50242445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:15.358134985 CET4455024029.183.147.247192.168.2.5
                                  Jan 15, 2025 02:59:15.358194113 CET50240445192.168.2.529.183.147.247
                                  Jan 15, 2025 02:59:15.362685919 CET4455024129.183.147.1192.168.2.5
                                  Jan 15, 2025 02:59:15.362741947 CET50241445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:15.363056898 CET4455024229.183.147.1192.168.2.5
                                  Jan 15, 2025 02:59:15.363125086 CET50242445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:15.363172054 CET50242445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:15.367938995 CET4455024229.183.147.1192.168.2.5
                                  Jan 15, 2025 02:59:16.081984043 CET50248445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:16.086878061 CET4455024845.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:16.087033987 CET50248445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:16.087033987 CET50248445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:16.092302084 CET4455024845.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:16.097573042 CET50249445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:59:16.102560997 CET4455024938.242.199.1192.168.2.5
                                  Jan 15, 2025 02:59:16.102647066 CET50249445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:59:16.102698088 CET50249445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:59:16.107661009 CET4455024938.242.199.1192.168.2.5
                                  Jan 15, 2025 02:59:16.582773924 CET50254445192.168.2.5140.58.80.103
                                  Jan 15, 2025 02:59:16.587594986 CET44550254140.58.80.103192.168.2.5
                                  Jan 15, 2025 02:59:16.587718964 CET50254445192.168.2.5140.58.80.103
                                  Jan 15, 2025 02:59:16.587718964 CET50254445192.168.2.5140.58.80.103
                                  Jan 15, 2025 02:59:16.587960005 CET50255445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:16.592736959 CET44550255140.58.80.1192.168.2.5
                                  Jan 15, 2025 02:59:16.592746973 CET44550254140.58.80.103192.168.2.5
                                  Jan 15, 2025 02:59:16.592808962 CET50255445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:16.592845917 CET50254445192.168.2.5140.58.80.103
                                  Jan 15, 2025 02:59:16.593012094 CET50255445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:16.594798088 CET50256445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:16.597815037 CET44550255140.58.80.1192.168.2.5
                                  Jan 15, 2025 02:59:16.597883940 CET50255445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:16.599863052 CET44550256140.58.80.1192.168.2.5
                                  Jan 15, 2025 02:59:16.599940062 CET50256445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:16.599977970 CET50256445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:16.604824066 CET44550256140.58.80.1192.168.2.5
                                  Jan 15, 2025 02:59:17.082205057 CET44550094117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:59:17.082335949 CET50094445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:59:17.082473993 CET50094445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:59:17.082530022 CET50094445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:59:17.088541031 CET44550094117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:59:17.088571072 CET44550094117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:59:17.301559925 CET44550100167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:59:17.301641941 CET50100445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:59:17.301717997 CET50100445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:59:17.301743984 CET50100445192.168.2.5167.35.109.1
                                  Jan 15, 2025 02:59:17.306505919 CET44550100167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:59:17.306521893 CET44550100167.35.109.1192.168.2.5
                                  Jan 15, 2025 02:59:17.363219023 CET50262445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:17.368216038 CET44550262167.35.109.2192.168.2.5
                                  Jan 15, 2025 02:59:17.368339062 CET50262445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:17.368426085 CET50262445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:17.369096994 CET50263445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:17.373281956 CET44550262167.35.109.2192.168.2.5
                                  Jan 15, 2025 02:59:17.373347998 CET50262445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:17.374011040 CET44550263167.35.109.2192.168.2.5
                                  Jan 15, 2025 02:59:17.374084949 CET50263445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:17.374217987 CET50263445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:17.379028082 CET44550263167.35.109.2192.168.2.5
                                  Jan 15, 2025 02:59:17.738291025 CET50265445192.168.2.5111.209.240.246
                                  Jan 15, 2025 02:59:17.743386030 CET44550265111.209.240.246192.168.2.5
                                  Jan 15, 2025 02:59:17.743597984 CET50265445192.168.2.5111.209.240.246
                                  Jan 15, 2025 02:59:17.743643999 CET50265445192.168.2.5111.209.240.246
                                  Jan 15, 2025 02:59:17.743789911 CET50266445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:17.748636007 CET44550265111.209.240.246192.168.2.5
                                  Jan 15, 2025 02:59:17.748650074 CET44550266111.209.240.1192.168.2.5
                                  Jan 15, 2025 02:59:17.748702049 CET50265445192.168.2.5111.209.240.246
                                  Jan 15, 2025 02:59:17.748727083 CET50266445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:17.748859882 CET50266445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:17.749294996 CET50267445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:17.754740953 CET44550267111.209.240.1192.168.2.5
                                  Jan 15, 2025 02:59:17.754928112 CET44550266111.209.240.1192.168.2.5
                                  Jan 15, 2025 02:59:17.755013943 CET50266445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:17.755033016 CET50267445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:17.755033016 CET50267445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:17.760040998 CET44550267111.209.240.1192.168.2.5
                                  Jan 15, 2025 02:59:17.835213900 CET4455024845.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:17.835336924 CET50248445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:17.835336924 CET50248445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:17.835381031 CET50248445192.168.2.545.33.237.1
                                  Jan 15, 2025 02:59:17.841217041 CET4455024845.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:17.841387033 CET4455024845.33.237.1192.168.2.5
                                  Jan 15, 2025 02:59:17.894140959 CET50268445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:17.898955107 CET4455026845.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:17.899075031 CET50268445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:17.899158955 CET50268445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:17.899503946 CET50269445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:17.904366016 CET4455026845.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:17.904438019 CET50268445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:17.904522896 CET4455026945.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:17.904577017 CET50269445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:17.904617071 CET50269445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:17.909651995 CET4455026945.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:18.112935066 CET50274445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:59:18.117822886 CET4455027434.28.85.1192.168.2.5
                                  Jan 15, 2025 02:59:18.117973089 CET50274445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:59:18.117973089 CET50274445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:59:18.122937918 CET4455027434.28.85.1192.168.2.5
                                  Jan 15, 2025 02:59:18.816509008 CET50281445192.168.2.5219.14.212.211
                                  Jan 15, 2025 02:59:18.821415901 CET44550281219.14.212.211192.168.2.5
                                  Jan 15, 2025 02:59:18.821583986 CET50281445192.168.2.5219.14.212.211
                                  Jan 15, 2025 02:59:18.821583986 CET50281445192.168.2.5219.14.212.211
                                  Jan 15, 2025 02:59:18.821743011 CET50282445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:18.826458931 CET44550281219.14.212.211192.168.2.5
                                  Jan 15, 2025 02:59:18.826494932 CET44550282219.14.212.1192.168.2.5
                                  Jan 15, 2025 02:59:18.826541901 CET50281445192.168.2.5219.14.212.211
                                  Jan 15, 2025 02:59:18.826567888 CET50282445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:18.826683998 CET50282445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:18.827065945 CET50283445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:18.831470013 CET44550282219.14.212.1192.168.2.5
                                  Jan 15, 2025 02:59:18.831523895 CET50282445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:18.831860065 CET44550283219.14.212.1192.168.2.5
                                  Jan 15, 2025 02:59:18.831916094 CET50283445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:18.831953049 CET50283445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:18.836709023 CET44550283219.14.212.1192.168.2.5
                                  Jan 15, 2025 02:59:19.099870920 CET4455011148.111.230.1192.168.2.5
                                  Jan 15, 2025 02:59:19.099950075 CET50111445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:59:19.100042105 CET50111445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:59:19.100079060 CET50111445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:59:19.104851961 CET4455011148.111.230.1192.168.2.5
                                  Jan 15, 2025 02:59:19.104865074 CET4455011148.111.230.1192.168.2.5
                                  Jan 15, 2025 02:59:19.316484928 CET445501135.92.127.1192.168.2.5
                                  Jan 15, 2025 02:59:19.316570997 CET50113445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:59:19.316643000 CET50113445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:59:19.316699028 CET50113445192.168.2.55.92.127.1
                                  Jan 15, 2025 02:59:19.322556973 CET445501135.92.127.1192.168.2.5
                                  Jan 15, 2025 02:59:19.322609901 CET445501135.92.127.1192.168.2.5
                                  Jan 15, 2025 02:59:19.378947973 CET50285445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:19.383815050 CET445502855.92.127.2192.168.2.5
                                  Jan 15, 2025 02:59:19.383886099 CET50285445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:19.383928061 CET50285445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:19.384360075 CET50286445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:19.388876915 CET445502855.92.127.2192.168.2.5
                                  Jan 15, 2025 02:59:19.388946056 CET50285445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:19.389247894 CET445502865.92.127.2192.168.2.5
                                  Jan 15, 2025 02:59:19.389311075 CET50286445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:19.389348030 CET50286445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:19.394103050 CET445502865.92.127.2192.168.2.5
                                  Jan 15, 2025 02:59:19.618165970 CET4455026945.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:19.618248940 CET50269445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:19.618304968 CET50269445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:19.618331909 CET50269445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:19.623029947 CET4455026945.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:19.623075008 CET4455026945.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:19.831896067 CET50292445192.168.2.5170.151.136.20
                                  Jan 15, 2025 02:59:19.837913036 CET44550292170.151.136.20192.168.2.5
                                  Jan 15, 2025 02:59:19.838006020 CET50292445192.168.2.5170.151.136.20
                                  Jan 15, 2025 02:59:19.838054895 CET50292445192.168.2.5170.151.136.20
                                  Jan 15, 2025 02:59:19.838217974 CET50293445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:19.843297958 CET44550293170.151.136.1192.168.2.5
                                  Jan 15, 2025 02:59:19.843369961 CET50293445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:19.843388081 CET50293445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:19.843405962 CET44550292170.151.136.20192.168.2.5
                                  Jan 15, 2025 02:59:19.843858957 CET50294445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:19.843883038 CET50292445192.168.2.5170.151.136.20
                                  Jan 15, 2025 02:59:19.848315954 CET44550293170.151.136.1192.168.2.5
                                  Jan 15, 2025 02:59:19.848326921 CET44550293170.151.136.1192.168.2.5
                                  Jan 15, 2025 02:59:19.848376989 CET50293445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:19.848648071 CET44550294170.151.136.1192.168.2.5
                                  Jan 15, 2025 02:59:19.848711967 CET50294445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:19.848753929 CET50294445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:19.853549957 CET44550294170.151.136.1192.168.2.5
                                  Jan 15, 2025 02:59:20.097399950 CET50295445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:59:20.102314949 CET44550295117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:59:20.102442980 CET50295445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:59:20.102511883 CET50295445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:59:20.107283115 CET44550295117.2.101.1192.168.2.5
                                  Jan 15, 2025 02:59:20.769567013 CET50301445192.168.2.5219.202.225.135
                                  Jan 15, 2025 02:59:20.774451971 CET44550301219.202.225.135192.168.2.5
                                  Jan 15, 2025 02:59:20.778422117 CET50301445192.168.2.5219.202.225.135
                                  Jan 15, 2025 02:59:20.778497934 CET50301445192.168.2.5219.202.225.135
                                  Jan 15, 2025 02:59:20.778678894 CET50302445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:20.783421993 CET44550301219.202.225.135192.168.2.5
                                  Jan 15, 2025 02:59:20.783493996 CET44550302219.202.225.1192.168.2.5
                                  Jan 15, 2025 02:59:20.783559084 CET50301445192.168.2.5219.202.225.135
                                  Jan 15, 2025 02:59:20.783591986 CET50302445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:20.783665895 CET50302445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:20.783931971 CET50303445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:20.788593054 CET44550302219.202.225.1192.168.2.5
                                  Jan 15, 2025 02:59:20.788723946 CET44550303219.202.225.1192.168.2.5
                                  Jan 15, 2025 02:59:20.788794994 CET50302445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:20.788816929 CET50303445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:20.788861036 CET50303445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:20.793603897 CET44550303219.202.225.1192.168.2.5
                                  Jan 15, 2025 02:59:21.175993919 CET4455012575.199.66.1192.168.2.5
                                  Jan 15, 2025 02:59:21.176208973 CET50125445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:59:21.176208973 CET50125445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:59:21.176208973 CET50125445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:59:21.181181908 CET4455012575.199.66.1192.168.2.5
                                  Jan 15, 2025 02:59:21.181199074 CET4455012575.199.66.1192.168.2.5
                                  Jan 15, 2025 02:59:21.317580938 CET44550127161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:59:21.317650080 CET50127445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:59:21.317771912 CET50127445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:59:21.317845106 CET50127445192.168.2.5161.7.75.1
                                  Jan 15, 2025 02:59:21.322516918 CET44550127161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:59:21.322594881 CET44550127161.7.75.1192.168.2.5
                                  Jan 15, 2025 02:59:21.378901958 CET50309445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:21.383739948 CET44550309161.7.75.2192.168.2.5
                                  Jan 15, 2025 02:59:21.383832932 CET50309445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:21.383876085 CET50309445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:21.384335995 CET50310445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:21.388762951 CET44550309161.7.75.2192.168.2.5
                                  Jan 15, 2025 02:59:21.388835907 CET50309445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:21.389137983 CET44550310161.7.75.2192.168.2.5
                                  Jan 15, 2025 02:59:21.389208078 CET50310445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:21.389266968 CET50310445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:21.394023895 CET44550310161.7.75.2192.168.2.5
                                  Jan 15, 2025 02:59:21.644644976 CET50311445192.168.2.5122.200.21.252
                                  Jan 15, 2025 02:59:21.649418116 CET44550311122.200.21.252192.168.2.5
                                  Jan 15, 2025 02:59:21.649524927 CET50311445192.168.2.5122.200.21.252
                                  Jan 15, 2025 02:59:21.656454086 CET50311445192.168.2.5122.200.21.252
                                  Jan 15, 2025 02:59:21.656692982 CET50312445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:21.661323071 CET44550311122.200.21.252192.168.2.5
                                  Jan 15, 2025 02:59:21.661397934 CET50311445192.168.2.5122.200.21.252
                                  Jan 15, 2025 02:59:21.661478043 CET44550312122.200.21.1192.168.2.5
                                  Jan 15, 2025 02:59:21.661537886 CET50312445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:21.661578894 CET50312445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:21.661962032 CET50313445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:21.666476011 CET44550312122.200.21.1192.168.2.5
                                  Jan 15, 2025 02:59:21.666529894 CET50312445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:21.666810036 CET44550313122.200.21.1192.168.2.5
                                  Jan 15, 2025 02:59:21.666862011 CET50313445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:21.666898966 CET50313445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:21.671731949 CET44550313122.200.21.1192.168.2.5
                                  Jan 15, 2025 02:59:22.113684893 CET50319445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:59:22.118532896 CET4455031948.111.230.1192.168.2.5
                                  Jan 15, 2025 02:59:22.118623018 CET50319445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:59:22.118664980 CET50319445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:59:22.123440981 CET4455031948.111.230.1192.168.2.5
                                  Jan 15, 2025 02:59:22.472610950 CET50320445192.168.2.5209.178.43.113
                                  Jan 15, 2025 02:59:22.477463961 CET44550320209.178.43.113192.168.2.5
                                  Jan 15, 2025 02:59:22.477544069 CET50320445192.168.2.5209.178.43.113
                                  Jan 15, 2025 02:59:22.477576971 CET50320445192.168.2.5209.178.43.113
                                  Jan 15, 2025 02:59:22.477869034 CET50321445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:22.482650995 CET44550321209.178.43.1192.168.2.5
                                  Jan 15, 2025 02:59:22.482701063 CET44550320209.178.43.113192.168.2.5
                                  Jan 15, 2025 02:59:22.482716084 CET50321445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:22.482728958 CET50321445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:22.482758045 CET50320445192.168.2.5209.178.43.113
                                  Jan 15, 2025 02:59:22.483038902 CET50322445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:22.487601042 CET44550321209.178.43.1192.168.2.5
                                  Jan 15, 2025 02:59:22.487673998 CET50321445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:22.487798929 CET44550322209.178.43.1192.168.2.5
                                  Jan 15, 2025 02:59:22.487862110 CET50322445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:22.488096952 CET50322445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:22.492897987 CET44550322209.178.43.1192.168.2.5
                                  Jan 15, 2025 02:59:22.628511906 CET50327445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:22.633389950 CET4455032745.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:22.633481026 CET50327445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:22.633496046 CET50327445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:22.638279915 CET4455032745.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:23.175971031 CET4455013876.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:23.176045895 CET50138445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:23.176096916 CET50138445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:23.176141977 CET50138445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:23.181091070 CET4455013876.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:23.181220055 CET4455013876.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:23.238389969 CET50329445192.168.2.548.223.148.157
                                  Jan 15, 2025 02:59:23.243196964 CET4455032948.223.148.157192.168.2.5
                                  Jan 15, 2025 02:59:23.243295908 CET50329445192.168.2.548.223.148.157
                                  Jan 15, 2025 02:59:23.243328094 CET50329445192.168.2.548.223.148.157
                                  Jan 15, 2025 02:59:23.243534088 CET50330445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:23.248226881 CET4455032948.223.148.157192.168.2.5
                                  Jan 15, 2025 02:59:23.248274088 CET4455033048.223.148.1192.168.2.5
                                  Jan 15, 2025 02:59:23.248310089 CET50329445192.168.2.548.223.148.157
                                  Jan 15, 2025 02:59:23.248368979 CET50330445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:23.248461008 CET50330445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:23.248801947 CET50331445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:23.253304005 CET4455033048.223.148.1192.168.2.5
                                  Jan 15, 2025 02:59:23.253376007 CET50330445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:23.253664970 CET4455033148.223.148.1192.168.2.5
                                  Jan 15, 2025 02:59:23.253725052 CET50331445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:23.253752947 CET50331445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:23.258522034 CET4455033148.223.148.1192.168.2.5
                                  Jan 15, 2025 02:59:23.425493956 CET4455014140.92.175.1192.168.2.5
                                  Jan 15, 2025 02:59:23.425632954 CET50141445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:59:23.425755024 CET50141445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:59:23.425837994 CET50141445192.168.2.540.92.175.1
                                  Jan 15, 2025 02:59:23.430540085 CET4455014140.92.175.1192.168.2.5
                                  Jan 15, 2025 02:59:23.430617094 CET4455014140.92.175.1192.168.2.5
                                  Jan 15, 2025 02:59:23.488249063 CET50336445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:23.493215084 CET4455033640.92.175.2192.168.2.5
                                  Jan 15, 2025 02:59:23.493297100 CET50336445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:23.493356943 CET50336445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:23.493748903 CET50337445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:23.498833895 CET4455033740.92.175.2192.168.2.5
                                  Jan 15, 2025 02:59:23.498904943 CET50337445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:23.498934031 CET50337445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:23.499797106 CET4455033640.92.175.2192.168.2.5
                                  Jan 15, 2025 02:59:23.499852896 CET50336445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:23.503770113 CET4455033740.92.175.2192.168.2.5
                                  Jan 15, 2025 02:59:24.191215992 CET50344445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:59:24.196052074 CET4455034475.199.66.1192.168.2.5
                                  Jan 15, 2025 02:59:24.196172953 CET50344445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:59:24.196208954 CET50344445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:59:24.200958014 CET4455034475.199.66.1192.168.2.5
                                  Jan 15, 2025 02:59:24.436860085 CET4455032745.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:24.436930895 CET50327445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:24.436966896 CET50327445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:24.437004089 CET50327445192.168.2.545.33.237.2
                                  Jan 15, 2025 02:59:24.441838026 CET4455032745.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:24.441849947 CET4455032745.33.237.2192.168.2.5
                                  Jan 15, 2025 02:59:24.488065004 CET50345445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:24.492973089 CET4455034545.33.237.3192.168.2.5
                                  Jan 15, 2025 02:59:24.493065119 CET50345445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:24.493149996 CET50345445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:24.493609905 CET50346445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:24.498431921 CET4455034645.33.237.3192.168.2.5
                                  Jan 15, 2025 02:59:24.498516083 CET50346445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:24.498840094 CET50346445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:24.500304937 CET4455034545.33.237.3192.168.2.5
                                  Jan 15, 2025 02:59:24.500535965 CET4455034545.33.237.3192.168.2.5
                                  Jan 15, 2025 02:59:24.500586987 CET50345445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:24.503671885 CET4455034645.33.237.3192.168.2.5
                                  Jan 15, 2025 02:59:25.179893970 CET4455015330.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:25.179966927 CET50153445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:25.180000067 CET50153445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:25.180047989 CET50153445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:25.184767962 CET4455015330.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:25.184783936 CET4455015330.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:25.365478992 CET44550155223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:25.365576029 CET50155445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:25.365631104 CET50155445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:25.365698099 CET50155445192.168.2.5223.67.238.1
                                  Jan 15, 2025 02:59:25.370424986 CET44550155223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:25.370446920 CET44550155223.67.238.1192.168.2.5
                                  Jan 15, 2025 02:59:25.425687075 CET50356445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:25.430608988 CET44550356223.67.238.2192.168.2.5
                                  Jan 15, 2025 02:59:25.430716991 CET50356445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:25.430759907 CET50356445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:25.431152105 CET50357445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:25.435643911 CET44550356223.67.238.2192.168.2.5
                                  Jan 15, 2025 02:59:25.435705900 CET50356445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:25.435945988 CET44550357223.67.238.2192.168.2.5
                                  Jan 15, 2025 02:59:25.436005116 CET50357445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:25.436049938 CET50357445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:25.440821886 CET44550357223.67.238.2192.168.2.5
                                  Jan 15, 2025 02:59:26.191360950 CET50366445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:26.196211100 CET4455036676.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:26.196372986 CET50366445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:26.196372986 CET50366445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:26.201176882 CET4455036676.182.197.1192.168.2.5
                                  Jan 15, 2025 02:59:27.208117008 CET44550166124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:27.208234072 CET50166445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:27.208266973 CET50166445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:27.208319902 CET50166445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:27.213078976 CET44550166124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:27.213087082 CET44550166124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:28.197130919 CET50389445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:28.202290058 CET4455038930.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:28.202531099 CET50389445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:28.203269005 CET50389445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:28.208137035 CET4455038930.129.64.1192.168.2.5
                                  Jan 15, 2025 02:59:29.053234100 CET44550180197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:29.053308964 CET50180445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:29.053350925 CET50180445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:29.053401947 CET50180445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:29.058264017 CET44550180197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:29.058294058 CET44550180197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:29.363970995 CET44550182136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:29.364126921 CET50182445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:29.364191055 CET50182445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:29.364238024 CET50182445192.168.2.5136.61.41.1
                                  Jan 15, 2025 02:59:29.370157003 CET44550182136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:29.370191097 CET44550182136.61.41.1192.168.2.5
                                  Jan 15, 2025 02:59:29.425622940 CET50401445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:29.430572987 CET44550401136.61.41.2192.168.2.5
                                  Jan 15, 2025 02:59:29.430696011 CET50401445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:29.430743933 CET50401445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:29.431083918 CET50403445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:29.435724020 CET44550401136.61.41.2192.168.2.5
                                  Jan 15, 2025 02:59:29.435810089 CET50401445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:29.435945034 CET44550403136.61.41.2192.168.2.5
                                  Jan 15, 2025 02:59:29.436014891 CET50403445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:29.436078072 CET50403445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:29.440910101 CET44550403136.61.41.2192.168.2.5
                                  Jan 15, 2025 02:59:30.222296000 CET50415445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:30.227384090 CET44550415124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:30.230465889 CET50415445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:30.230556011 CET50415445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:30.236421108 CET44550415124.91.26.1192.168.2.5
                                  Jan 15, 2025 02:59:30.834233999 CET4455019379.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:30.834346056 CET50193445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:30.834414005 CET50193445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:30.834471941 CET50193445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:30.839320898 CET4455019379.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:30.839335918 CET4455019379.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:31.431802034 CET44550198122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:31.431943893 CET50198445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:31.431977987 CET50198445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:31.432022095 CET50198445192.168.2.5122.101.248.1
                                  Jan 15, 2025 02:59:31.436755896 CET44550198122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:31.436765909 CET44550198122.101.248.1192.168.2.5
                                  Jan 15, 2025 02:59:31.488114119 CET50438445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:31.492935896 CET44550438122.101.248.2192.168.2.5
                                  Jan 15, 2025 02:59:31.493036032 CET50438445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:31.493094921 CET50438445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:31.493525982 CET50439445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:31.498373032 CET44550439122.101.248.2192.168.2.5
                                  Jan 15, 2025 02:59:31.498507023 CET50439445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:31.498581886 CET50439445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:31.500341892 CET44550438122.101.248.2192.168.2.5
                                  Jan 15, 2025 02:59:31.500375986 CET44550438122.101.248.2192.168.2.5
                                  Jan 15, 2025 02:59:31.500432014 CET50438445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:31.503431082 CET44550439122.101.248.2192.168.2.5
                                  Jan 15, 2025 02:59:32.066030025 CET50452445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:32.072978020 CET44550452197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:32.073124886 CET50452445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:32.073167086 CET50452445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:32.077995062 CET44550452197.84.254.1192.168.2.5
                                  Jan 15, 2025 02:59:33.457611084 CET4455021066.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:33.457706928 CET50210445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:33.457757950 CET50210445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:33.457794905 CET50210445192.168.2.566.43.16.1
                                  Jan 15, 2025 02:59:33.462697029 CET4455021066.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:33.462749958 CET4455021066.43.16.1192.168.2.5
                                  Jan 15, 2025 02:59:33.519418955 CET50495445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:33.524414062 CET4455049566.43.16.2192.168.2.5
                                  Jan 15, 2025 02:59:33.524545908 CET50495445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:33.524604082 CET50495445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:33.524899960 CET50497445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:33.530237913 CET4455049766.43.16.2192.168.2.5
                                  Jan 15, 2025 02:59:33.530307055 CET50497445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:33.530363083 CET50497445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:33.530385971 CET4455049566.43.16.2192.168.2.5
                                  Jan 15, 2025 02:59:33.530494928 CET50495445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:33.535114050 CET4455049766.43.16.2192.168.2.5
                                  Jan 15, 2025 02:59:33.838351965 CET4455021466.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:33.838474989 CET50214445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:33.838531017 CET50214445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:33.838582039 CET50214445192.168.2.566.102.158.2
                                  Jan 15, 2025 02:59:33.843358994 CET4455021466.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:33.843374968 CET4455021466.102.158.2192.168.2.5
                                  Jan 15, 2025 02:59:33.847203016 CET50512445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:33.852058887 CET4455051279.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:33.852134943 CET50512445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:33.852159977 CET50512445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:33.856888056 CET4455051279.125.115.1192.168.2.5
                                  Jan 15, 2025 02:59:33.894315004 CET50515445192.168.2.566.102.158.3
                                  Jan 15, 2025 02:59:33.899238110 CET4455051566.102.158.3192.168.2.5
                                  Jan 15, 2025 02:59:33.899346113 CET50515445192.168.2.566.102.158.3
                                  Jan 15, 2025 02:59:33.899347067 CET50515445192.168.2.566.102.158.3
                                  Jan 15, 2025 02:59:33.899804115 CET50516445192.168.2.566.102.158.3
                                  Jan 15, 2025 02:59:33.904316902 CET4455051566.102.158.3192.168.2.5
                                  Jan 15, 2025 02:59:33.904328108 CET4455051566.102.158.3192.168.2.5
                                  Jan 15, 2025 02:59:33.904392958 CET50515445192.168.2.566.102.158.3
                                  Jan 15, 2025 02:59:33.904668093 CET4455051666.102.158.3192.168.2.5
                                  Jan 15, 2025 02:59:33.904728889 CET50516445192.168.2.566.102.158.3
                                  Jan 15, 2025 02:59:33.904747963 CET50516445192.168.2.566.102.158.3
                                  Jan 15, 2025 02:59:33.909476995 CET4455051666.102.158.3192.168.2.5
                                  Jan 15, 2025 02:59:34.008553028 CET44550218147.140.226.1192.168.2.5
                                  Jan 15, 2025 02:59:34.008650064 CET50218445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:34.008712053 CET50218445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:34.008769989 CET50218445192.168.2.5147.140.226.1
                                  Jan 15, 2025 02:59:34.013485909 CET44550218147.140.226.1192.168.2.5
                                  Jan 15, 2025 02:59:34.013540030 CET44550218147.140.226.1192.168.2.5
                                  Jan 15, 2025 02:59:35.428261995 CET44550230150.215.1.1192.168.2.5
                                  Jan 15, 2025 02:59:35.428332090 CET50230445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:35.664565086 CET44550233197.168.4.1192.168.2.5
                                  Jan 15, 2025 02:59:35.664647102 CET50233445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:36.200167894 CET50242445192.168.2.529.183.147.1
                                  Jan 15, 2025 02:59:36.200227976 CET50357445192.168.2.5223.67.238.2
                                  Jan 15, 2025 02:59:36.200227976 CET50337445192.168.2.540.92.175.2
                                  Jan 15, 2025 02:59:36.200267076 CET50310445192.168.2.5161.7.75.2
                                  Jan 15, 2025 02:59:36.200274944 CET50249445192.168.2.538.242.199.1
                                  Jan 15, 2025 02:59:36.200301886 CET50346445192.168.2.545.33.237.3
                                  Jan 15, 2025 02:59:36.200321913 CET50233445192.168.2.5197.168.4.1
                                  Jan 15, 2025 02:59:36.200381041 CET50230445192.168.2.5150.215.1.1
                                  Jan 15, 2025 02:59:36.200422049 CET50512445192.168.2.579.125.115.1
                                  Jan 15, 2025 02:59:36.200498104 CET50286445192.168.2.55.92.127.2
                                  Jan 15, 2025 02:59:36.200515032 CET50263445192.168.2.5167.35.109.2
                                  Jan 15, 2025 02:59:36.200557947 CET50439445192.168.2.5122.101.248.2
                                  Jan 15, 2025 02:59:36.200582981 CET50256445192.168.2.5140.58.80.1
                                  Jan 15, 2025 02:59:36.200597048 CET50267445192.168.2.5111.209.240.1
                                  Jan 15, 2025 02:59:36.200635910 CET50274445192.168.2.534.28.85.1
                                  Jan 15, 2025 02:59:36.200723886 CET50283445192.168.2.5219.14.212.1
                                  Jan 15, 2025 02:59:36.200762987 CET50294445192.168.2.5170.151.136.1
                                  Jan 15, 2025 02:59:36.200778008 CET50295445192.168.2.5117.2.101.1
                                  Jan 15, 2025 02:59:36.200793982 CET50303445192.168.2.5219.202.225.1
                                  Jan 15, 2025 02:59:36.200848103 CET50319445192.168.2.548.111.230.1
                                  Jan 15, 2025 02:59:36.200870991 CET50313445192.168.2.5122.200.21.1
                                  Jan 15, 2025 02:59:36.200870991 CET50322445192.168.2.5209.178.43.1
                                  Jan 15, 2025 02:59:36.200902939 CET50331445192.168.2.548.223.148.1
                                  Jan 15, 2025 02:59:36.200934887 CET50344445192.168.2.575.199.66.1
                                  Jan 15, 2025 02:59:36.200958967 CET50366445192.168.2.576.182.197.1
                                  Jan 15, 2025 02:59:36.200993061 CET50389445192.168.2.530.129.64.1
                                  Jan 15, 2025 02:59:36.201013088 CET50403445192.168.2.5136.61.41.2
                                  Jan 15, 2025 02:59:36.201040983 CET50415445192.168.2.5124.91.26.1
                                  Jan 15, 2025 02:59:36.201085091 CET50452445192.168.2.5197.84.254.1
                                  Jan 15, 2025 02:59:36.201220989 CET50497445192.168.2.566.43.16.2
                                  Jan 15, 2025 02:59:36.201311111 CET50516445192.168.2.566.102.158.3
                                  TimestampSource PortDest PortSource IPDest IP
                                  Jan 15, 2025 02:58:28.485003948 CET5425753192.168.2.51.1.1.1
                                  Jan 15, 2025 02:58:28.639758110 CET53542571.1.1.1192.168.2.5
                                  Jan 15, 2025 02:58:29.279057026 CET6177153192.168.2.51.1.1.1
                                  Jan 15, 2025 02:58:29.605180025 CET53617711.1.1.1192.168.2.5
                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                  Jan 15, 2025 02:58:28.485003948 CET192.168.2.51.1.1.10x2ab3Standard query (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                  Jan 15, 2025 02:58:29.279057026 CET192.168.2.51.1.1.10x7ad0Standard query (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                  Jan 15, 2025 02:58:28.639758110 CET1.1.1.1192.168.2.50x2ab3No error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com103.224.212.215A (IP address)IN (0x0001)false
                                  Jan 15, 2025 02:58:29.605180025 CET1.1.1.1192.168.2.50x7ad0No error (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com77026.bodis.comCNAME (Canonical name)IN (0x0001)false
                                  Jan 15, 2025 02:58:29.605180025 CET1.1.1.1192.168.2.50x7ad0No error (0)77026.bodis.com199.59.243.228A (IP address)IN (0x0001)false
                                  • www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  • ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  0192.168.2.549704103.224.212.215804308C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 02:58:28.654110909 CET100OUTGET / HTTP/1.1
                                  Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Cache-Control: no-cache
                                  Jan 15, 2025 02:58:29.253204107 CET365INHTTP/1.1 302 Found
                                  date: Wed, 15 Jan 2025 01:58:29 GMT
                                  server: Apache
                                  set-cookie: __tad=1736906309.2045439; expires=Sat, 13-Jan-2035 01:58:29 GMT; Max-Age=315360000
                                  location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-29df-89f9-50f10d431f5d
                                  content-length: 2
                                  content-type: text/html; charset=UTF-8
                                  connection: close
                                  Data Raw: 0a 0a
                                  Data Ascii:


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  1192.168.2.549705199.59.243.228804308C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 02:58:29.611684084 CET169OUTGET /?subid1=20250115-1258-29df-89f9-50f10d431f5d HTTP/1.1
                                  Cache-Control: no-cache
                                  Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Connection: Keep-Alive
                                  Jan 15, 2025 02:58:30.068670988 CET1236INHTTP/1.1 200 OK
                                  date: Wed, 15 Jan 2025 01:58:29 GMT
                                  content-type: text/html; charset=utf-8
                                  content-length: 1262
                                  x-request-id: 72908bbf-89ad-4006-aba3-e99298a28c4b
                                  cache-control: no-store, max-age=0
                                  accept-ch: sec-ch-prefers-color-scheme
                                  critical-ch: sec-ch-prefers-color-scheme
                                  vary: sec-ch-prefers-color-scheme
                                  x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_XtbfwpOoZhTE/fCp6GRexeoVH/NTaqH+k/DeJ0yEGSCrtv5szMIDYgxxyPc2/GPPYfCpc7SkViWOg3o1RIS4WA==
                                  set-cookie: parking_session=72908bbf-89ad-4006-aba3-e99298a28c4b; expires=Wed, 15 Jan 2025 02:13:30 GMT; path=/
                                  Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 58 74 62 66 77 70 4f 6f 5a 68 54 45 2f 66 43 70 36 47 52 65 78 65 6f 56 48 2f 4e 54 61 71 48 2b 6b 2f 44 65 4a 30 79 45 47 53 43 72 74 76 35 73 7a 4d 49 44 59 67 78 78 79 50 63 32 2f 47 50 50 59 66 43 70 63 37 53 6b 56 69 57 4f 67 33 6f 31 52 49 53 34 57 41 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                  Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_XtbfwpOoZhTE/fCp6GRexeoVH/NTaqH+k/DeJ0yEGSCrtv5szMIDYgxxyPc2/GPPYfCpc7SkViWOg3o1RIS4WA==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                  Jan 15, 2025 02:58:30.068720102 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                  Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiNzI5MDhiYmYtODlhZC00MDA2LWFiYTMtZTk5Mjk4YTI4YzRiIiwicGFnZV90aW1lIjoxNzM2OTA2MzEwLCJwYWdlX3VybCI6I


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  2192.168.2.549706103.224.212.215805536C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 02:58:30.313309908 CET100OUTGET / HTTP/1.1
                                  Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Cache-Control: no-cache
                                  Jan 15, 2025 02:58:30.937666893 CET365INHTTP/1.1 302 Found
                                  date: Wed, 15 Jan 2025 01:58:30 GMT
                                  server: Apache
                                  set-cookie: __tad=1736906310.4444240; expires=Sat, 13-Jan-2035 01:58:30 GMT; Max-Age=315360000
                                  location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-30b4-926b-ebcd05294e47
                                  content-length: 2
                                  content-type: text/html; charset=UTF-8
                                  connection: close
                                  Data Raw: 0a 0a
                                  Data Ascii:


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  3192.168.2.549707199.59.243.228805536C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 02:58:30.948050976 CET169OUTGET /?subid1=20250115-1258-30b4-926b-ebcd05294e47 HTTP/1.1
                                  Cache-Control: no-cache
                                  Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Connection: Keep-Alive
                                  Jan 15, 2025 02:58:31.402571917 CET1236INHTTP/1.1 200 OK
                                  date: Wed, 15 Jan 2025 01:58:30 GMT
                                  content-type: text/html; charset=utf-8
                                  content-length: 1262
                                  x-request-id: 84ffacce-068e-45e5-9070-c271a9c0ace6
                                  cache-control: no-store, max-age=0
                                  accept-ch: sec-ch-prefers-color-scheme
                                  critical-ch: sec-ch-prefers-color-scheme
                                  vary: sec-ch-prefers-color-scheme
                                  x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_aM0v1/JWjjTj66a4UIbMSZcKBJeh//sGeF0cuDMZQ+CxjNkRhGS+yXpc1Dni2mb0a+FVC6bgoKYPZ8g7WqUROg==
                                  set-cookie: parking_session=84ffacce-068e-45e5-9070-c271a9c0ace6; expires=Wed, 15 Jan 2025 02:13:31 GMT; path=/
                                  Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 61 4d 30 76 31 2f 4a 57 6a 6a 54 6a 36 36 61 34 55 49 62 4d 53 5a 63 4b 42 4a 65 68 2f 2f 73 47 65 46 30 63 75 44 4d 5a 51 2b 43 78 6a 4e 6b 52 68 47 53 2b 79 58 70 63 31 44 6e 69 32 6d 62 30 61 2b 46 56 43 36 62 67 6f 4b 59 50 5a 38 67 37 57 71 55 52 4f 67 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                  Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_aM0v1/JWjjTj66a4UIbMSZcKBJeh//sGeF0cuDMZQ+CxjNkRhGS+yXpc1Dni2mb0a+FVC6bgoKYPZ8g7WqUROg==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                  Jan 15, 2025 02:58:31.402595997 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                  Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiODRmZmFjY2UtMDY4ZS00NWU1LTkwNzAtYzI3MWE5YzBhY2U2IiwicGFnZV90aW1lIjoxNzM2OTA2MzExLCJwYWdlX3VybCI6I


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  4192.168.2.549708103.224.212.215803656C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 02:58:31.370541096 CET134OUTGET / HTTP/1.1
                                  Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Cache-Control: no-cache
                                  Cookie: __tad=1736906309.2045439
                                  Jan 15, 2025 02:58:31.964457989 CET269INHTTP/1.1 302 Found
                                  date: Wed, 15 Jan 2025 01:58:31 GMT
                                  server: Apache
                                  location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-3155-9edf-37a78753f039
                                  content-length: 2
                                  content-type: text/html; charset=UTF-8
                                  connection: close
                                  Data Raw: 0a 0a
                                  Data Ascii:


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  5192.168.2.549721199.59.243.228803656C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 02:58:31.973670959 CET231OUTGET /?subid1=20250115-1258-3155-9edf-37a78753f039 HTTP/1.1
                                  Cache-Control: no-cache
                                  Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Connection: Keep-Alive
                                  Cookie: parking_session=72908bbf-89ad-4006-aba3-e99298a28c4b
                                  Jan 15, 2025 02:58:32.429480076 CET1236INHTTP/1.1 200 OK
                                  date: Wed, 15 Jan 2025 01:58:32 GMT
                                  content-type: text/html; charset=utf-8
                                  content-length: 1262
                                  x-request-id: 858c5a60-122f-4119-92d8-af914e5465bf
                                  cache-control: no-store, max-age=0
                                  accept-ch: sec-ch-prefers-color-scheme
                                  critical-ch: sec-ch-prefers-color-scheme
                                  vary: sec-ch-prefers-color-scheme
                                  x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_r4tF+4rl5t9VcDldenzTNTL77wc/md1QUosQdbDDtb/EYSR3yknH/VrxpZQGMuHBEKXQozoJdLekP7UDvi0wPQ==
                                  set-cookie: parking_session=72908bbf-89ad-4006-aba3-e99298a28c4b; expires=Wed, 15 Jan 2025 02:13:32 GMT
                                  Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 72 34 74 46 2b 34 72 6c 35 74 39 56 63 44 6c 64 65 6e 7a 54 4e 54 4c 37 37 77 63 2f 6d 64 31 51 55 6f 73 51 64 62 44 44 74 62 2f 45 59 53 52 33 79 6b 6e 48 2f 56 72 78 70 5a 51 47 4d 75 48 42 45 4b 58 51 6f 7a 6f 4a 64 4c 65 6b 50 37 55 44 76 69 30 77 50 51 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                  Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_r4tF+4rl5t9VcDldenzTNTL77wc/md1QUosQdbDDtb/EYSR3yknH/VrxpZQGMuHBEKXQozoJdLekP7UDvi0wPQ==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="preconnect
                                  Jan 15, 2025 02:58:32.429512978 CET688INData Raw: 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65 74 22 20 73 74 79 6c 65
                                  Data Ascii: " href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiNzI5MDhiYmYtODlhZC00MDA2LWFiYTMtZTk5Mjk4YTI4YzRiIiwicGFnZV90aW1lIjoxNzM2OTA2MzEyLCJwYWdlX3VybCI6Imh0dHA6L


                                  Click to jump to process

                                  Click to jump to process

                                  Click to dive into process behavior distribution

                                  Click to jump to process

                                  Target ID:0
                                  Start time:20:58:27
                                  Start date:14/01/2025
                                  Path:C:\Windows\System32\loaddll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:loaddll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll"
                                  Imagebase:0x220000
                                  File size:126'464 bytes
                                  MD5 hash:51E6071F9CBA48E79F10C84515AAE618
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:1
                                  Start time:20:58:27
                                  Start date:14/01/2025
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6d64d0000
                                  File size:862'208 bytes
                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:2
                                  Start time:20:58:27
                                  Start date:14/01/2025
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1
                                  Imagebase:0x790000
                                  File size:236'544 bytes
                                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:3
                                  Start time:20:58:27
                                  Start date:14/01/2025
                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:rundll32.exe C:\Users\user\Desktop\hVgcaX2SV8.dll,PlayGame
                                  Imagebase:0x5f0000
                                  File size:61'440 bytes
                                  MD5 hash:889B99C52A60DD49227C5E485A016679
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:4
                                  Start time:20:58:27
                                  Start date:14/01/2025
                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",#1
                                  Imagebase:0x5f0000
                                  File size:61'440 bytes
                                  MD5 hash:889B99C52A60DD49227C5E485A016679
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:5
                                  Start time:20:58:27
                                  Start date:14/01/2025
                                  Path:C:\Windows\mssecsvr.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\WINDOWS\mssecsvr.exe
                                  Imagebase:0x400000
                                  File size:2'281'472 bytes
                                  MD5 hash:C52D23EEDF757DFD3703AC774DE1C457
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000005.00000000.2104424678.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  Reputation:low
                                  Has exited:true

                                  Target ID:7
                                  Start time:20:58:29
                                  Start date:14/01/2025
                                  Path:C:\Windows\mssecsvr.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\WINDOWS\mssecsvr.exe -m security
                                  Imagebase:0x400000
                                  File size:2'281'472 bytes
                                  MD5 hash:C52D23EEDF757DFD3703AC774DE1C457
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000000.2123551514.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000002.2774027813.0000000001D61000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000002.2774278925.000000000228A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                  Reputation:low
                                  Has exited:true

                                  Target ID:8
                                  Start time:20:58:30
                                  Start date:14/01/2025
                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:rundll32.exe "C:\Users\user\Desktop\hVgcaX2SV8.dll",PlayGame
                                  Imagebase:0x5f0000
                                  File size:61'440 bytes
                                  MD5 hash:889B99C52A60DD49227C5E485A016679
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:9
                                  Start time:20:58:30
                                  Start date:14/01/2025
                                  Path:C:\Windows\mssecsvr.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\WINDOWS\mssecsvr.exe
                                  Imagebase:0x400000
                                  File size:2'281'472 bytes
                                  MD5 hash:C52D23EEDF757DFD3703AC774DE1C457
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000009.00000000.2133754261.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000009.00000002.2151167613.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  Reputation:low
                                  Has exited:true

                                  Reset < >

                                    Execution Graph

                                    Execution Coverage:71.7%
                                    Dynamic/Decrypted Code Coverage:0%
                                    Signature Coverage:63.2%
                                    Total number of Nodes:38
                                    Total number of Limit Nodes:9
                                    execution_graph 63 409a16 __set_app_type __p__fmode __p__commode 64 409a85 63->64 65 409a99 64->65 66 409a8d __setusermatherr 64->66 75 409b8c _controlfp 65->75 66->65 68 409a9e _initterm __getmainargs _initterm 69 409af2 GetStartupInfoA 68->69 71 409b26 GetModuleHandleA 69->71 76 408140 InternetOpenA InternetOpenUrlA 71->76 75->68 77 4081a7 InternetCloseHandle InternetCloseHandle 76->77 80 408090 GetModuleFileNameA __p___argc 77->80 79 4081b2 exit _XcptFilter 81 4080b0 80->81 82 4080b9 OpenSCManagerA 80->82 91 407f20 81->91 83 408101 StartServiceCtrlDispatcherA 82->83 84 4080cf OpenServiceA 82->84 83->79 86 4080fc CloseServiceHandle 84->86 87 4080ee 84->87 86->83 96 407fa0 ChangeServiceConfig2A 87->96 90 4080f6 CloseServiceHandle 90->86 108 407c40 sprintf OpenSCManagerA 91->108 93 407f25 97 407ce0 GetModuleHandleW 93->97 96->90 98 407d01 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 97->98 99 407f08 97->99 98->99 100 407d49 98->100 99->79 100->99 101 407d69 FindResourceA 100->101 101->99 102 407d84 LoadResource 101->102 102->99 103 407d94 LockResource 102->103 103->99 104 407da7 SizeofResource 103->104 104->99 105 407db9 sprintf sprintf MoveFileExA CreateFileA 104->105 105->99 106 407e54 WriteFile CloseHandle CreateProcessA 105->106 106->99 107 407ef2 CloseHandle CloseHandle 106->107 107->99 109 407c74 CreateServiceA 108->109 110 407cca 108->110 111 407cbb CloseServiceHandle 109->111 112 407cad StartServiceA CloseServiceHandle 109->112 110->93 111->93 112->111

                                    Callgraph

                                    Control-flow Graph

                                    APIs
                                    • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F370EF0,?,00000000), ref: 00407CEF
                                    • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                    • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                    • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                    • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                    • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                    • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                    • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                    • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                    • sprintf.MSVCRT ref: 00407E01
                                    • sprintf.MSVCRT ref: 00407E18
                                    • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                    • CreateFileA.KERNELBASE(?,40000000,00000000,00000000,00000002,00000004,00000000), ref: 00407E43
                                    • WriteFile.KERNELBASE(00000000,?,00000000,?,00000000), ref: 00407E61
                                    • CloseHandle.KERNELBASE(00000000), ref: 00407E68
                                    • CreateProcessA.KERNELBASE ref: 00407EE8
                                    • CloseHandle.KERNEL32(00000000), ref: 00407EF7
                                    • CloseHandle.KERNEL32(08000000), ref: 00407F02
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2137096385.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2137073139.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137130398.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137217492.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AddressHandleProcResource$CloseFile$Createsprintf$FindLoadLockModuleMoveProcessSizeofWrite
                                    • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                    • API String ID: 4281112323-1507730452
                                    • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                    • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                    Control-flow Graph

                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2137096385.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2137073139.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137130398.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137217492.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                    • String ID:
                                    • API String ID: 801014965-0
                                    • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                    • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59

                                    Control-flow Graph

                                    APIs
                                    • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                    • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                    • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                    • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                      • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                      • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                    Strings
                                    • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2137096385.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2137073139.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137130398.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137217492.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                    • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                    • API String ID: 774561529-2614457033
                                    • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                    • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                    Control-flow Graph

                                    APIs
                                    • sprintf.MSVCRT ref: 00407C56
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                    • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F370EF0,00000000), ref: 00407C9B
                                    • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2137096385.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2137073139.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137130398.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137217492.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                    • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                    • API String ID: 3340711343-2450984573
                                    • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                    • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                    Control-flow Graph

                                    APIs
                                    • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                    • __p___argc.MSVCRT ref: 004080A5
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                    • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F370EF0,00000000,?,004081B2), ref: 004080DC
                                    • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                    • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                    • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2137096385.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2137073139.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137130398.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137159664.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137217492.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2137318896.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                    • String ID: mssecsvc2.1
                                    • API String ID: 4274534310-2839763450
                                    • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                    • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                    Execution Graph

                                    Execution Coverage:34.8%
                                    Dynamic/Decrypted Code Coverage:0%
                                    Signature Coverage:0%
                                    Total number of Nodes:36
                                    Total number of Limit Nodes:2

                                    Callgraph

                                    Control-flow Graph

                                    APIs
                                    • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                    • __p___argc.MSVCRT ref: 004080A5
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                    • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F370EF0,00000000,?,004081B2), ref: 004080DC
                                    • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                    • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                    • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2773030409.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2773014131.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773049586.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773130667.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773149345.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                    • String ID: mssecsvc2.1
                                    • API String ID: 4274534310-2839763450
                                    • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                    • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                    Control-flow Graph

                                    APIs
                                    • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                    • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                    • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                    • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                      • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                      • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                    Strings
                                    • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2773030409.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2773014131.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773049586.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773130667.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773149345.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                    • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                    • API String ID: 774561529-2614457033
                                    • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                    • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                    Control-flow Graph

                                    APIs
                                    • sprintf.MSVCRT ref: 00407C56
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                    • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F370EF0,00000000), ref: 00407C9B
                                    • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2773030409.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2773014131.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773049586.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773130667.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773149345.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                    • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                    • API String ID: 3340711343-2450984573
                                    • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                    • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 15 407ce0-407cfb GetModuleHandleW 16 407d01-407d43 GetProcAddress * 4 15->16 17 407f08-407f14 15->17 16->17 18 407d49-407d4f 16->18 18->17 19 407d55-407d5b 18->19 19->17 20 407d61-407d63 19->20 20->17 21 407d69-407d7e FindResourceA 20->21 21->17 22 407d84-407d8e LoadResource 21->22 22->17 23 407d94-407da1 LockResource 22->23 23->17 24 407da7-407db3 SizeofResource 23->24 24->17 25 407db9-407e4e sprintf * 2 MoveFileExA 24->25 25->17 27 407e54-407ef0 25->27 27->17 31 407ef2-407f01 27->31 31->17
                                    APIs
                                    • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F370EF0,?,00000000), ref: 00407CEF
                                    • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                    • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                    • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                    • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                    • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                    • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                    • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                    • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                    • sprintf.MSVCRT ref: 00407E01
                                    • sprintf.MSVCRT ref: 00407E18
                                    • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2773030409.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2773014131.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773049586.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773130667.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773149345.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AddressProcResource$sprintf$FileFindHandleLoadLockModuleMoveSizeof
                                    • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                    • API String ID: 4072214828-1507730452
                                    • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                    • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                    Control-flow Graph

                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2773030409.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2773014131.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773049586.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773066141.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773108997.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773130667.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773149345.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2773238979.00000000008FD000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                    • String ID:
                                    • API String ID: 801014965-0
                                    • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                    • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59