Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
NLWfV87ouS.dll

Overview

General Information

Sample name:NLWfV87ouS.dll
renamed because original name is a hash value
Original sample name:23d048d04f55b993301b477b1b8bd7a8.dll
Analysis ID:1591529
MD5:23d048d04f55b993301b477b1b8bd7a8
SHA1:eef0b45632e55705c1cab4bb6da58e882a8ab865
SHA256:d048f0164808c5daab17d4e224bcaa079ac7371f36618e9e6d4eb1b2b65c3953
Tags:dllexeuser-mentality
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Wannacry ransomware
AI detected suspicious sample
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses insecure TLS / SSL version for HTTPS connection
Yara signature match

Classification

  • System is w10x64
  • loaddll32.exe (PID: 2332 cmdline: loaddll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 4088 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 6936 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 6252 cmdline: rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 5640 cmdline: rundll32.exe C:\Users\user\Desktop\NLWfV87ouS.dll,PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
      • mssecsvr.exe (PID: 6656 cmdline: C:\WINDOWS\mssecsvr.exe MD5: 6F25163220B24FB054B144BE9F82C096)
    • rundll32.exe (PID: 1948 cmdline: rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
      • mssecsvr.exe (PID: 6752 cmdline: C:\WINDOWS\mssecsvr.exe MD5: 6F25163220B24FB054B144BE9F82C096)
  • mssecsvr.exe (PID: 5396 cmdline: C:\WINDOWS\mssecsvr.exe -m security MD5: 6F25163220B24FB054B144BE9F82C096)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
NLWfV87ouS.dllJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    NLWfV87ouS.dllWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x353d0:$x3: tasksche.exe
    • 0x353a8:$x8: C:\%s\qeriuwjhrf
    • 0x3014:$s1: C:\%s\%s
    • 0x12098:$s1: C:\%s\%s
    • 0x1b39c:$s1: C:\%s\%s
    • 0x353bc:$s1: C:\%s\%s
    • 0x326f0:$s5: \\192.168.56.20\IPC$
    • 0x1fae5:$s6: \\172.16.99.5\IPC$
    • 0xd195:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
    • 0x78da:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
    • 0x5449:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
    SourceRuleDescriptionAuthorStrings
    C:\Windows\mssecsvr.exeJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      C:\Windows\mssecsvr.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
      • 0x3136c:$x3: tasksche.exe
      • 0x31344:$x8: C:\%s\qeriuwjhrf
      • 0xe034:$s1: C:\%s\%s
      • 0x17338:$s1: C:\%s\%s
      • 0x31358:$s1: C:\%s\%s
      • 0x2e68c:$s5: \\192.168.56.20\IPC$
      • 0x1ba81:$s6: \\172.16.99.5\IPC$
      • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
      • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
      • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
      C:\Windows\mssecsvr.exeWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
      • 0x1bacc:$s1: __TREEID__PLACEHOLDER__
      • 0x1bb68:$s1: __TREEID__PLACEHOLDER__
      • 0x1c3d4:$s1: __TREEID__PLACEHOLDER__
      • 0x1d439:$s1: __TREEID__PLACEHOLDER__
      • 0x1e4a0:$s1: __TREEID__PLACEHOLDER__
      • 0x1f508:$s1: __TREEID__PLACEHOLDER__
      • 0x20570:$s1: __TREEID__PLACEHOLDER__
      • 0x215d8:$s1: __TREEID__PLACEHOLDER__
      • 0x22640:$s1: __TREEID__PLACEHOLDER__
      • 0x236a8:$s1: __TREEID__PLACEHOLDER__
      • 0x24710:$s1: __TREEID__PLACEHOLDER__
      • 0x25778:$s1: __TREEID__PLACEHOLDER__
      • 0x267e0:$s1: __TREEID__PLACEHOLDER__
      • 0x27848:$s1: __TREEID__PLACEHOLDER__
      • 0x288b0:$s1: __TREEID__PLACEHOLDER__
      • 0x29918:$s1: __TREEID__PLACEHOLDER__
      • 0x2a980:$s1: __TREEID__PLACEHOLDER__
      • 0x2ab94:$s1: __TREEID__PLACEHOLDER__
      • 0x2abf4:$s1: __TREEID__PLACEHOLDER__
      • 0x2e2c4:$s1: __TREEID__PLACEHOLDER__
      • 0x2e340:$s1: __TREEID__PLACEHOLDER__
      SourceRuleDescriptionAuthorStrings
      00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        0000000A.00000002.2213069023.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          00000008.00000000.2195861336.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            0000000A.00000000.2199520983.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
              00000006.00000000.2171769143.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
                Click to see the 6 entries
                SourceRuleDescriptionAuthorStrings
                8.2.mssecsvr.exe.23728c8.7.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
                • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
                • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
                8.2.mssecsvr.exe.1e4f084.3.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
                • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
                • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
                8.2.mssecsvr.exe.23728c8.7.unpackJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
                  8.2.mssecsvr.exe.23728c8.7.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                  • 0x3136c:$x3: tasksche.exe
                  • 0x31344:$x8: C:\%s\qeriuwjhrf
                  • 0x17338:$s1: C:\%s\%s
                  • 0x31358:$s1: C:\%s\%s
                  • 0x2e68c:$s5: \\192.168.56.20\IPC$
                  • 0x1ba81:$s6: \\172.16.99.5\IPC$
                  • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
                  • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
                  • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
                  8.2.mssecsvr.exe.23728c8.7.unpackWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
                  • 0x1bacc:$s1: __TREEID__PLACEHOLDER__
                  • 0x1bb68:$s1: __TREEID__PLACEHOLDER__
                  • 0x1c3d4:$s1: __TREEID__PLACEHOLDER__
                  • 0x1d439:$s1: __TREEID__PLACEHOLDER__
                  • 0x1e4a0:$s1: __TREEID__PLACEHOLDER__
                  • 0x1f508:$s1: __TREEID__PLACEHOLDER__
                  • 0x20570:$s1: __TREEID__PLACEHOLDER__
                  • 0x215d8:$s1: __TREEID__PLACEHOLDER__
                  • 0x22640:$s1: __TREEID__PLACEHOLDER__
                  • 0x236a8:$s1: __TREEID__PLACEHOLDER__
                  • 0x24710:$s1: __TREEID__PLACEHOLDER__
                  • 0x25778:$s1: __TREEID__PLACEHOLDER__
                  • 0x267e0:$s1: __TREEID__PLACEHOLDER__
                  • 0x27848:$s1: __TREEID__PLACEHOLDER__
                  • 0x288b0:$s1: __TREEID__PLACEHOLDER__
                  • 0x29918:$s1: __TREEID__PLACEHOLDER__
                  • 0x2a980:$s1: __TREEID__PLACEHOLDER__
                  • 0x2ab94:$s1: __TREEID__PLACEHOLDER__
                  • 0x2abf4:$s1: __TREEID__PLACEHOLDER__
                  • 0x2e2c4:$s1: __TREEID__PLACEHOLDER__
                  • 0x2e340:$s1: __TREEID__PLACEHOLDER__
                  Click to see the 35 entries
                  No Sigma rule has matched
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2025-01-15T02:58:49.093541+010028033043Unknown Traffic192.168.2.649710103.224.212.21580TCP
                  2025-01-15T02:58:50.638385+010028033043Unknown Traffic192.168.2.649713103.224.212.21580TCP
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2025-01-15T02:58:48.174980+010028300181A Network Trojan was detected192.168.2.6566061.1.1.153UDP

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: NLWfV87ouS.dllAvira: detected
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2Avira URL Cloud: Label: malware
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2a9Avira URL Cloud: Label: malware
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423bAvira URL Cloud: Label: malware
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/nAvira URL Cloud: Label: malware
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc11Avira URL Cloud: Label: malware
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc110aAvira URL Cloud: Label: malware
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423bb5Avira URL Cloud: Label: malware
                  Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwAvira URL Cloud: Label: malware
                  Source: C:\Windows\mssecsvr.exeAvira: detection malicious, Label: TR/Ransom.Gen
                  Source: C:\WINDOWS\qeriuwjhrf (copy)ReversingLabs: Detection: 86%
                  Source: C:\Windows\mssecsvr.exeReversingLabs: Detection: 100%
                  Source: C:\Windows\tasksche.exeReversingLabs: Detection: 86%
                  Source: NLWfV87ouS.dllVirustotal: Detection: 94%Perma Link
                  Source: NLWfV87ouS.dllReversingLabs: Detection: 92%
                  Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.8% probability
                  Source: C:\Windows\mssecsvr.exeJoe Sandbox ML: detected
                  Source: C:\Windows\tasksche.exeJoe Sandbox ML: detected
                  Source: NLWfV87ouS.dllJoe Sandbox ML: detected

                  Exploits

                  barindex
                  Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                  Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                  Source: NLWfV87ouS.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                  Source: unknownHTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49956 version: TLS 1.0
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49709 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49772 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49992 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50251 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50394 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50630 version: TLS 1.2

                  Networking

                  barindex
                  Source: Network trafficSuricata IDS: 2830018 - Severity 1 - ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup) : 192.168.2.6:56606 -> 1.1.1.1:53
                  Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                  Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-49b3-8be1-4b52c7dcf2a9 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                  Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736906329.4755573
                  Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-50c9-a80a-e88809fc110a HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-50a1-9cf3-708b13423bb5 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=a1a59836-c29b-4307-ae59-a2380c47c41f
                  Source: Joe Sandbox ViewJA3 fingerprint: 1138de370e523e824bbca92d049a3777
                  Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                  Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.6:49713 -> 103.224.212.215:80
                  Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.6:49710 -> 103.224.212.215:80
                  Source: unknownHTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49956 version: TLS 1.0
                  Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                  Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                  Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.0
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.0
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.0
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.0
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 35.203.187.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                  Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                  Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.198
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.198
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.198
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.198
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 161.113.71.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.204
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.204
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.204
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.204
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 185.104.232.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.159
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.159
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.159
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.159
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.1
                  Source: unknownTCP traffic detected without corresponding DNS query: 46.91.122.1
                  Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                  Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-49b3-8be1-4b52c7dcf2a9 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                  Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736906329.4755573
                  Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-50c9-a80a-e88809fc110a HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /?subid1=20250115-1258-50a1-9cf3-708b13423bb5 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=a1a59836-c29b-4307-ae59-a2380c47c41f
                  Source: global trafficDNS traffic detected: DNS query: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                  Source: global trafficDNS traffic detected: DNS query: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrw
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2
                  Source: mssecsvr.exe, 0000000A.00000002.2213559856.0000000000A1E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423b
                  Source: mssecsvr.exe, 00000008.00000002.2849180029.0000000000AEA000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000003.2208462022.0000000000B0C000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000AF2000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000B0C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc11
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/n
                  Source: mssecsvr.exe.4.drString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000003.2208462022.0000000000AFE000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000AF2000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000AC8000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 0000000A.00000002.2213559856.0000000000A2D000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 0000000A.00000002.2213559856.00000000009E8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                  Source: mssecsvr.exe, 0000000A.00000002.2213559856.0000000000A2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/7
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/:s~A
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/us
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/~
                  Source: mssecsvr.exe, 0000000A.00000002.2213559856.00000000009E8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com2$6.5
                  Source: mssecsvr.exe, 00000008.00000002.2848722808.000000000019D000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJ
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comYs
                  Source: mssecsvr.exe, 00000008.00000002.2849180029.0000000000AC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.commmEn
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50251
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50394
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 50394 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50630
                  Source: unknownNetwork traffic detected: HTTP traffic on port 50630 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49956 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49992 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49956
                  Source: unknownNetwork traffic detected: HTTP traffic on port 50251 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49709 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49772 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49992 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50251 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50394 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50630 version: TLS 1.2

                  Spam, unwanted Advertisements and Ransom Demands

                  barindex
                  Source: Yara matchFile source: NLWfV87ouS.dll, type: SAMPLE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.23728c8.7.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.1e5e104.2.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.1e4f084.3.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.2381948.8.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.1e5e104.2.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.1e5a0a4.5.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.237d8e8.6.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.mssecsvr.exe.2381948.8.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000A.00000002.2213069023.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000008.00000000.2195861336.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000A.00000000.2199520983.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000006.00000000.2171769143.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000006.00000002.2209019561.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000008.00000002.2849584166.0000000001E5E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000008.00000002.2849831934.0000000002381000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 6656, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 5396, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 6752, type: MEMORYSTR
                  Source: Yara matchFile source: C:\Windows\mssecsvr.exe, type: DROPPED

                  System Summary

                  barindex
                  Source: NLWfV87ouS.dll, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.23728c8.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.1e4f084.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.23728c8.7.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.23728c8.7.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 8.2.mssecsvr.exe.1e5e104.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.1e5e104.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 8.2.mssecsvr.exe.1e4f084.3.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.1e4f084.3.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 8.2.mssecsvr.exe.2381948.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.2381948.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 8.2.mssecsvr.exe.1e5e104.2.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: 8.2.mssecsvr.exe.1e5a0a4.5.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.237d8e8.6.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: 8.2.mssecsvr.exe.2381948.8.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: C:\Windows\mssecsvr.exe, type: DROPPEDMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                  Source: C:\Windows\mssecsvr.exe, type: DROPPEDMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                  Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\WINDOWS\mssecsvr.exeJump to behavior
                  Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                  Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                  Source: mssecsvr.exe.4.drStatic PE information: Resource name: R type: PE32 executable (GUI) Intel 80386, for MS Windows
                  Source: tasksche.exe.6.drStatic PE information: No import functions for PE file found
                  Source: NLWfV87ouS.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                  Source: NLWfV87ouS.dll, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.23728c8.7.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.1e4f084.3.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.23728c8.7.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.23728c8.7.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 8.2.mssecsvr.exe.1e5e104.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.1e5e104.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 8.2.mssecsvr.exe.1e4f084.3.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.1e4f084.3.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 6.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 8.2.mssecsvr.exe.2381948.8.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.2381948.8.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 6.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 10.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 8.2.mssecsvr.exe.1e5e104.2.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 10.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: 8.2.mssecsvr.exe.1e5a0a4.5.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.237d8e8.6.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: 8.2.mssecsvr.exe.2381948.8.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: C:\Windows\mssecsvr.exe, type: DROPPEDMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                  Source: C:\Windows\mssecsvr.exe, type: DROPPEDMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                  Source: tasksche.exe.6.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                  Source: tasksche.exe.6.drStatic PE information: Section: .rdata ZLIB complexity 1.0007621951219512
                  Source: tasksche.exe.6.drStatic PE information: Section: .data ZLIB complexity 1.001953125
                  Source: tasksche.exe.6.drStatic PE information: Section: .rsrc ZLIB complexity 1.0007408405172413
                  Source: classification engineClassification label: mal100.rans.expl.evad.winDLL@18/3@2/100
                  Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                  Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,8_2_00407C40
                  Source: C:\Windows\mssecsvr.exeCode function: 6_2_00407CE0 InternetCloseHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessA,FindResourceA,LoadResource,LockResource,SizeofResource,sprintf,sprintf,sprintf,MoveFileExA,CreateFileA,WriteFile,CloseHandle,CreateProcessA,CloseHandle,CloseHandle,6_2_00407CE0
                  Source: C:\Windows\mssecsvr.exeCode function: 6_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                  Source: C:\Windows\mssecsvr.exeCode function: 6_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,6_2_00408090
                  Source: C:\Windows\mssecsvr.exeCode function: 8_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,8_2_00408090
                  Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4088:120:WilError_03
                  Source: NLWfV87ouS.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                  Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\NLWfV87ouS.dll,PlayGame
                  Source: NLWfV87ouS.dllVirustotal: Detection: 94%
                  Source: NLWfV87ouS.dllReversingLabs: Detection: 92%
                  Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll"
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\NLWfV87ouS.dll,PlayGame
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1
                  Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                  Source: unknownProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe -m security
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",PlayGame
                  Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1Jump to behavior
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\NLWfV87ouS.dll,PlayGameJump to behavior
                  Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",PlayGameJump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1Jump to behavior
                  Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                  Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                  Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Windows\System32\loaddll32.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: rsaenh.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: cryptbase.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                  Source: C:\Windows\mssecsvr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
                  Source: NLWfV87ouS.dllStatic file information: File size 5267459 > 1048576
                  Source: NLWfV87ouS.dllStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x501000
                  Source: tasksche.exe.6.drStatic PE information: section name: .text entropy: 7.543576774509125

                  Persistence and Installation Behavior

                  barindex
                  Source: C:\Windows\SysWOW64\rundll32.exeExecutable created and started: C:\WINDOWS\mssecsvr.exeJump to behavior
                  Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                  Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                  Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\mssecsvr.exeJump to dropped file
                  Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                  Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                  Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\mssecsvr.exeJump to dropped file
                  Source: C:\Windows\mssecsvr.exeCode function: 6_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                  Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                  Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                  Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\Windows\tasksche.exeJump to dropped file
                  Source: C:\Windows\mssecsvr.exe TID: 6440Thread sleep count: 93 > 30Jump to behavior
                  Source: C:\Windows\mssecsvr.exe TID: 6440Thread sleep time: -186000s >= -30000sJump to behavior
                  Source: C:\Windows\mssecsvr.exe TID: 6416Thread sleep count: 128 > 30Jump to behavior
                  Source: C:\Windows\mssecsvr.exe TID: 6416Thread sleep count: 40 > 30Jump to behavior
                  Source: C:\Windows\mssecsvr.exe TID: 6440Thread sleep time: -86400000s >= -30000sJump to behavior
                  Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                  Source: C:\Windows\System32\loaddll32.exeThread delayed: delay time: 120000Jump to behavior
                  Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWp
                  Source: mssecsvr.exe, 00000006.00000002.2209504571.0000000000BDE000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000003.2208462022.0000000000B0C000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000AC8000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000B0C000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 0000000A.00000002.2213559856.0000000000A3D000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 0000000A.00000002.2213559856.00000000009E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                  Source: mssecsvr.exe, 0000000A.00000002.2213559856.0000000000A3D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW*_]-
                  Source: mssecsvr.exe, 00000008.00000003.2208462022.0000000000B0C000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000B0C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWD
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1Jump to behavior
                  ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                  Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                  Service Execution
                  4
                  Windows Service
                  4
                  Windows Service
                  12
                  Masquerading
                  OS Credential Dumping1
                  Network Share Discovery
                  Remote ServicesData from Local System2
                  Encrypted Channel
                  Exfiltration Over Other Network MediumAbuse Accessibility Features
                  CredentialsDomainsDefault AccountsScheduled Task/Job1
                  DLL Side-Loading
                  11
                  Process Injection
                  21
                  Virtualization/Sandbox Evasion
                  LSASS Memory11
                  Security Software Discovery
                  Remote Desktop ProtocolData from Removable Media1
                  Ingress Tool Transfer
                  Exfiltration Over BluetoothNetwork Denial of Service
                  Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                  DLL Side-Loading
                  11
                  Process Injection
                  Security Account Manager21
                  Virtualization/Sandbox Evasion
                  SMB/Windows Admin SharesData from Network Shared Drive2
                  Non-Application Layer Protocol
                  Automated ExfiltrationData Encrypted for Impact
                  Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                  Obfuscated Files or Information
                  NTDS1
                  System Information Discovery
                  Distributed Component Object ModelInput Capture3
                  Application Layer Protocol
                  Traffic DuplicationData Destruction
                  Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                  Rundll32
                  LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                  Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
                  Software Packing
                  Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                  DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                  DLL Side-Loading
                  DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                  Hide Legend

                  Legend:

                  • Process
                  • Signature
                  • Created File
                  • DNS/IP Info
                  • Is Dropped
                  • Is Windows Process
                  • Number of created Registry Values
                  • Number of created Files
                  • Visual Basic
                  • Delphi
                  • Java
                  • .Net C# or VB.NET
                  • C, C++ or other language
                  • Is malicious
                  • Internet
                  behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1591529 Sample: NLWfV87ouS.dll Startdate: 15/01/2025 Architecture: WINDOWS Score: 100 37 www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->37 39 ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->39 41 77026.bodis.com 2->41 51 Suricata IDS alerts for network traffic 2->51 53 Malicious sample detected (through community Yara rule) 2->53 55 Antivirus detection for URL or domain 2->55 57 7 other signatures 2->57 8 loaddll32.exe 1 2->8         started        10 mssecsvr.exe 12 2->10         started        signatures3 process4 dnsIp5 14 rundll32.exe 8->14         started        16 rundll32.exe 8->16         started        19 cmd.exe 1 8->19         started        21 conhost.exe 8->21         started        43 192.168.2.100 unknown unknown 10->43 45 192.168.2.101 unknown unknown 10->45 47 98 other IPs or domains 10->47 65 Connects to many different private IPs via SMB (likely to spread or exploit) 10->65 67 Connects to many different private IPs (likely to spread or exploit) 10->67 signatures6 process7 signatures8 23 mssecsvr.exe 13 14->23         started        49 Drops executables to the windows directory (C:\Windows) and starts them 16->49 27 mssecsvr.exe 13 16->27         started        29 rundll32.exe 1 19->29         started        process9 file10 31 C:\Windows\tasksche.exe, PE32 23->31 dropped 59 Antivirus detection for dropped file 23->59 61 Multi AV Scanner detection for dropped file 23->61 63 Machine Learning detection for dropped file 23->63 33 C:\WINDOWS\qeriuwjhrf (copy), PE32 27->33 dropped 35 C:\Windows\mssecsvr.exe, PE32 29->35 dropped signatures11

                  This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                  windows-stand
                  SourceDetectionScannerLabelLink
                  NLWfV87ouS.dll94%VirustotalBrowse
                  NLWfV87ouS.dll92%ReversingLabsWin32.Ransomware.WannaCry
                  NLWfV87ouS.dll100%AviraTR/AD.DPulsarShellcode.gohtr
                  NLWfV87ouS.dll100%Joe Sandbox ML
                  SourceDetectionScannerLabelLink
                  C:\Windows\mssecsvr.exe100%AviraTR/Ransom.Gen
                  C:\Windows\mssecsvr.exe100%Joe Sandbox ML
                  C:\Windows\tasksche.exe100%Joe Sandbox ML
                  C:\WINDOWS\qeriuwjhrf (copy)86%ReversingLabsByteCode-MSIL.Ransomware.WannaCry
                  C:\Windows\mssecsvr.exe100%ReversingLabsWin32.Ransomware.WannaCry
                  C:\Windows\tasksche.exe86%ReversingLabsByteCode-MSIL.Ransomware.WannaCry
                  No Antivirus matches
                  No Antivirus matches
                  SourceDetectionScannerLabelLink
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2100%Avira URL Cloudmalware
                  http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comYs0%Avira URL Cloudsafe
                  http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.commmEn0%Avira URL Cloudsafe
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2a9100%Avira URL Cloudmalware
                  http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com2$6.50%Avira URL Cloudsafe
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423b100%Avira URL Cloudmalware
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/n100%Avira URL Cloudmalware
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc11100%Avira URL Cloudmalware
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc110a100%Avira URL Cloudmalware
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423bb5100%Avira URL Cloudmalware
                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrw100%Avira URL Cloudmalware
                  NameIPActiveMaliciousAntivirus DetectionReputation
                  77026.bodis.com
                  199.59.243.228
                  truefalse
                    high
                    www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                    103.224.212.215
                    truefalse
                      high
                      ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                      unknown
                      unknownfalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/false
                          high
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2a9false
                          • Avira URL Cloud: malware
                          unknown
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423bb5false
                          • Avira URL Cloud: malware
                          unknown
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc110afalse
                          • Avira URL Cloud: malware
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc11mssecsvr.exe, 00000008.00000002.2849180029.0000000000AEA000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000003.2208462022.0000000000B0C000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000AF2000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000008.00000002.2849180029.0000000000B0C000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: malware
                          unknown
                          http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/:s~Amssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com2$6.5mssecsvr.exe, 0000000A.00000002.2213559856.00000000009E8000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comYsmssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.commssecsvr.exe.4.drfalse
                                high
                                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: malware
                                unknown
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/~mssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/usmssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423bmssecsvr.exe, 0000000A.00000002.2213559856.0000000000A1E000.00000004.00000020.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: malware
                                    unknown
                                    http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.commmEnmssecsvr.exe, 00000008.00000002.2849180029.0000000000AC8000.00000004.00000020.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/nmssecsvr.exe, 00000006.00000002.2209504571.0000000000BC2000.00000004.00000020.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: malware
                                    unknown
                                    http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJmssecsvr.exe, 00000008.00000002.2848722808.000000000019D000.00000004.00000010.00020000.00000000.sdmpfalse
                                      high
                                      http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/7mssecsvr.exe, 0000000A.00000002.2213559856.0000000000A2D000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwmssecsvr.exe, 00000006.00000002.2209504571.0000000000B7E000.00000004.00000020.00020000.00000000.sdmpfalse
                                        • Avira URL Cloud: malware
                                        unknown
                                        • No. of IPs < 25%
                                        • 25% < No. of IPs < 50%
                                        • 50% < No. of IPs < 75%
                                        • 75% < No. of IPs
                                        IPDomainCountryFlagASNASN NameMalicious
                                        159.140.202.246
                                        unknownUnited States
                                        17264CERNER-COMUSfalse
                                        115.165.57.1
                                        unknownJapan9365ITSCOMitscommunicationsIncJPfalse
                                        148.225.116.104
                                        unknownMexico
                                        4493UniversidaddeSonoraMXfalse
                                        49.55.159.1
                                        unknownChina
                                        4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                                        46.91.122.159
                                        unknownGermany
                                        3320DTAGInternetserviceprovideroperationsDEfalse
                                        148.225.116.1
                                        unknownMexico
                                        4493UniversidaddeSonoraMXfalse
                                        155.184.140.2
                                        unknownUnited States
                                        37532ZAMRENZMfalse
                                        155.184.140.1
                                        unknownUnited States
                                        37532ZAMRENZMfalse
                                        72.167.90.1
                                        unknownUnited States
                                        26496AS-26496-GO-DADDY-COM-LLCUSfalse
                                        23.170.165.153
                                        unknownReserved
                                        393582KHP-DLA-ASN-01USfalse
                                        175.101.165.1
                                        unknownIndia
                                        17754EXCELL-ASExcellmediaINfalse
                                        159.199.82.1
                                        unknownUnited States
                                        11363FUJITSU-USAUSfalse
                                        65.242.217.35
                                        unknownUnited States
                                        33476AS33476-TRADE-12USfalse
                                        65.242.217.1
                                        unknownUnited States
                                        33476AS33476-TRADE-12USfalse
                                        23.170.165.1
                                        unknownReserved
                                        393582KHP-DLA-ASN-01USfalse
                                        161.113.71.198
                                        unknownUnited States
                                        26381HSBC-COMUSfalse
                                        31.108.191.1
                                        unknownUnited Kingdom
                                        12576EELtdGBfalse
                                        IP
                                        192.168.2.148
                                        192.168.2.149
                                        192.168.2.146
                                        192.168.2.147
                                        192.168.2.140
                                        192.168.2.141
                                        192.168.2.144
                                        192.168.2.145
                                        192.168.2.142
                                        192.168.2.143
                                        192.168.2.159
                                        192.168.2.157
                                        192.168.2.158
                                        192.168.2.151
                                        192.168.2.152
                                        192.168.2.150
                                        192.168.2.155
                                        192.168.2.156
                                        192.168.2.153
                                        192.168.2.154
                                        192.168.2.126
                                        192.168.2.247
                                        192.168.2.127
                                        192.168.2.248
                                        192.168.2.124
                                        192.168.2.245
                                        192.168.2.125
                                        192.168.2.246
                                        192.168.2.128
                                        192.168.2.249
                                        192.168.2.129
                                        192.168.2.240
                                        192.168.2.122
                                        192.168.2.243
                                        192.168.2.123
                                        192.168.2.244
                                        192.168.2.120
                                        192.168.2.241
                                        192.168.2.121
                                        192.168.2.242
                                        192.168.2.97
                                        192.168.2.137
                                        192.168.2.96
                                        192.168.2.138
                                        192.168.2.99
                                        192.168.2.135
                                        192.168.2.98
                                        192.168.2.136
                                        192.168.2.139
                                        192.168.2.250
                                        192.168.2.130
                                        192.168.2.251
                                        192.168.2.91
                                        192.168.2.90
                                        192.168.2.93
                                        192.168.2.133
                                        192.168.2.254
                                        192.168.2.92
                                        192.168.2.134
                                        192.168.2.95
                                        192.168.2.131
                                        192.168.2.252
                                        192.168.2.94
                                        192.168.2.132
                                        192.168.2.253
                                        192.168.2.104
                                        192.168.2.225
                                        192.168.2.105
                                        192.168.2.226
                                        192.168.2.102
                                        192.168.2.223
                                        192.168.2.103
                                        192.168.2.224
                                        192.168.2.108
                                        192.168.2.229
                                        192.168.2.109
                                        192.168.2.106
                                        192.168.2.227
                                        192.168.2.107
                                        192.168.2.228
                                        192.168.2.100
                                        192.168.2.221
                                        192.168.2.101
                                        Joe Sandbox version:42.0.0 Malachite
                                        Analysis ID:1591529
                                        Start date and time:2025-01-15 02:57:50 +01:00
                                        Joe Sandbox product:CloudBasic
                                        Overall analysis duration:0h 5m 34s
                                        Hypervisor based Inspection enabled:false
                                        Report type:full
                                        Cookbook file name:default.jbs
                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                        Number of analysed new started processes analysed:15
                                        Number of new started drivers analysed:0
                                        Number of existing processes analysed:0
                                        Number of existing drivers analysed:0
                                        Number of injected processes analysed:0
                                        Technologies:
                                        • HCA enabled
                                        • EGA enabled
                                        • AMSI enabled
                                        Analysis Mode:default
                                        Analysis stop reason:Timeout
                                        Sample name:NLWfV87ouS.dll
                                        renamed because original name is a hash value
                                        Original Sample Name:23d048d04f55b993301b477b1b8bd7a8.dll
                                        Detection:MAL
                                        Classification:mal100.rans.expl.evad.winDLL@18/3@2/100
                                        EGA Information:
                                        • Successful, ratio: 100%
                                        HCA Information:Failed
                                        Cookbook Comments:
                                        • Found application associated with file extension: .dll
                                        • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                        • Excluded IPs from analysis (whitelisted): 184.30.131.245, 199.232.214.172, 2.22.50.144, 13.107.246.45, 4.175.87.197
                                        • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                        • Not all processes where analyzed, report is missing behavior information
                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                        TimeTypeDescription
                                        20:58:49API Interceptor1x Sleep call for process: loaddll32.exe modified
                                        20:59:24API Interceptor112x Sleep call for process: mssecsvr.exe modified
                                        No context
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        77026.bodis.comGUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        D3W41IdtQA.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        F1G5BkUV74.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        04Ct9PoJrL.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        sLlAsC4I5r.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        habHh1BC0L.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        19MgUpI9tj.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        ruXU7wj3X9.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        eIZi481eP6.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        m9oUIFauYl.dllGet hashmaliciousWannacryBrowse
                                        • 199.59.243.228
                                        www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comGUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        D3W41IdtQA.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        F1G5BkUV74.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        04Ct9PoJrL.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        sLlAsC4I5r.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        habHh1BC0L.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        19MgUpI9tj.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        ruXU7wj3X9.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        eIZi481eP6.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        m9oUIFauYl.dllGet hashmaliciousWannacryBrowse
                                        • 103.224.212.215
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        CERNER-COMUSm68k.elfGet hashmaliciousMirai, MoobotBrowse
                                        • 159.140.225.100
                                        arm6.elfGet hashmaliciousUnknownBrowse
                                        • 159.140.225.122
                                        jew.ppc.elfGet hashmaliciousUnknownBrowse
                                        • 159.140.225.170
                                        loligang.arm.elfGet hashmaliciousMiraiBrowse
                                        • 159.140.225.103
                                        la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                                        • 159.140.225.168
                                        bot.mips.elfGet hashmaliciousMirai, MoobotBrowse
                                        • 159.140.225.105
                                        huhu.mpsl.elfGet hashmaliciousMiraiBrowse
                                        • 159.140.225.168
                                        j1tsFOM5hC.elfGet hashmaliciousMiraiBrowse
                                        • 159.140.225.139
                                        3NlKDxmZwm.elfGet hashmaliciousUnknownBrowse
                                        • 159.140.225.119
                                        wEWJ2qbZx1.elfGet hashmaliciousMiraiBrowse
                                        • 159.140.225.127
                                        ITSCOMitscommunicationsIncJPmips.elfGet hashmaliciousUnknownBrowse
                                        • 163.58.82.152
                                        3.elfGet hashmaliciousUnknownBrowse
                                        • 218.45.207.247
                                        db0fa4b8db0333367e9bda3ab68b8042.m68k.elfGet hashmaliciousMirai, GafgytBrowse
                                        • 219.110.149.136
                                        armv5l.elfGet hashmaliciousUnknownBrowse
                                        • 163.58.70.45
                                        sh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                        • 219.110.36.94
                                        loligang.mips.elfGet hashmaliciousMiraiBrowse
                                        • 163.58.21.82
                                        x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                        • 116.0.231.239
                                        sh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                        • 163.58.166.109
                                        meerkat.arm.elfGet hashmaliciousMiraiBrowse
                                        • 219.110.102.103
                                        arm.elfGet hashmaliciousUnknownBrowse
                                        • 175.177.255.87
                                        UniversidaddeSonoraMXx86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                        • 148.225.64.87
                                        arm7.elfGet hashmaliciousUnknownBrowse
                                        • 148.225.52.71
                                        hiss.arm7.elfGet hashmaliciousUnknownBrowse
                                        • 148.225.64.61
                                        byte.arm5.elfGet hashmaliciousOkiruBrowse
                                        • 148.225.40.98
                                        hoho.arm7.elfGet hashmaliciousMiraiBrowse
                                        • 148.225.52.88
                                        8427xbk3Zt.elfGet hashmaliciousUnknownBrowse
                                        • 148.225.108.254
                                        byKLI4nzv2.elfGet hashmaliciousMiraiBrowse
                                        • 148.225.40.71
                                        ODggSYsZP2.elfGet hashmaliciousUnknownBrowse
                                        • 148.225.64.76
                                        x44pCciC79.elfGet hashmaliciousMiraiBrowse
                                        • 148.225.108.243
                                        K3k8Tqy0DP.elfGet hashmaliciousMiraiBrowse
                                        • 148.225.88.82
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        1138de370e523e824bbca92d049a3777330tqxXVzm.dllGet hashmaliciousWannacryBrowse
                                        • 173.222.162.64
                                        https://asalto-bart.eu/o/dcvGet hashmaliciousUnknownBrowse
                                        • 173.222.162.64
                                        https://teiegram-mg.org/Get hashmaliciousUnknownBrowse
                                        • 173.222.162.64
                                        https://sreamconmymnltty.com/scerty/bliun/bolopGet hashmaliciousUnknownBrowse
                                        • 173.222.162.64
                                        https://reviewpolicysocialreach.vercel.app/help&z/Get hashmaliciousHTMLPhisherBrowse
                                        • 173.222.162.64
                                        https://teiegtrm.cc/EN/Get hashmaliciousTelegram PhisherBrowse
                                        • 173.222.162.64
                                        https://cdn.trytraffics.com/rdr/YWE9MzU1NTgxMDE3JnNlaT0zMDE4NjQ3NyZ0az1JaVpNVjJSRDNza0FlTER2TTdvRyZ0PTUmYz05MGFzODc2ZmQ4OWFzNWZnOGEwOXM=Get hashmaliciousUnknownBrowse
                                        • 173.222.162.64
                                        https://teiegroj.cc/ZH/Get hashmaliciousTelegram PhisherBrowse
                                        • 173.222.162.64
                                        http://onlineausde.andhrauniversity.edu.in/studentLogin/Payments/Get hashmaliciousUnknownBrowse
                                        • 173.222.162.64
                                        https://nnsnsupport.weebly.com/Get hashmaliciousHTMLPhisherBrowse
                                        • 173.222.162.64
                                        3b5074b1b5d032e5620f69f9f700ff0e542CxvZnI5.dllGet hashmaliciousVirut, WannacryBrowse
                                        • 40.113.110.67
                                        https://cc68b94d-d9d0-4a03-bf37-d58a3335e1ce.p.reviewstudio.com/-/en/b/?_encoding=UTF8&_encoding=UTF8&node=3024314031&bbn=16435051&pd_rd_w=VSdHJ&content-id=amzn1.sym.01fcb23a-92a2-4260-b9bf-7c78abf408da&pf_rd_p=01fcb23a-92a2-4260-b9bf-7c78abf408da&pf_rd_r=E0WD16QK99B55VAWSKBQ&pd_rd_wg=EU3Lj&pd_rd_r=fd3510c2-a6e6-4f59-a468-c59aac80bfa9&ref_=pd_hp_d_btf_unkGet hashmaliciousUnknownBrowse
                                        • 40.113.110.67
                                        https://ziyahid.github.io/netflix-cloneGet hashmaliciousHTMLPhisherBrowse
                                        • 40.113.110.67
                                        http://pub-35a1d927529e4c9684409537cf8ff63f.r2.dev/docu/e_protocol.htmlGet hashmaliciousHTMLPhisherBrowse
                                        • 40.113.110.67
                                        http://emeklilereozeldir.org/Get hashmaliciousUnknownBrowse
                                        • 40.113.110.67
                                        http://industrious-tomato-ngvkcs.mystrikingly.com/Get hashmaliciousUnknownBrowse
                                        • 40.113.110.67
                                        http://telegroom-nzj.icu/Get hashmaliciousTelegram PhisherBrowse
                                        • 40.113.110.67
                                        https://cdn.trytraffics.com/rdr/YWE9MzUyODAwODkxJnNlaT0zMDQ3NDU3NCZ0az1JR0doTXJGNXNpVnJBYzZkWlBUWSZ0PTUmYz05MGFzODc2ZmQ4OWFzNWZnOGEwOXM=Get hashmaliciousUnknownBrowse
                                        • 40.113.110.67
                                        https://sreamconmymnltty.com/scerty/bliun/bolopGet hashmaliciousUnknownBrowse
                                        • 40.113.110.67
                                        https://yolocdh.weebly.com/Get hashmaliciousHTMLPhisherBrowse
                                        • 40.113.110.67
                                        No context
                                        Process:C:\Windows\mssecsvr.exe
                                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):2061938
                                        Entropy (8bit):7.962002774072566
                                        Encrypted:false
                                        SSDEEP:49152:uMSDbcBVQej/1INRx+DX1HkQo6SAARdhn7:uDoBhz1aRxqk36SAEdh7
                                        MD5:ABA8C6BAE8872F73A473AE3B18F186A4
                                        SHA1:9567DAB5A9E98B1623E0A12ABA3E5788EB32360F
                                        SHA-256:13AEAA8228839201C3BF6632AA7696E549773DE4824DCA3FEBE43FE1D20EF477
                                        SHA-512:F4F6B60997C771D5829DE2E007F2A894A936DF855C100A7D27AF7195DFD9E4C4634E62BFA24103A2CE771EC6ECCF27D19399A1D5552FA9CC02813D5C84E7EEA1
                                        Malicious:true
                                        Antivirus:
                                        • Antivirus: ReversingLabs, Detection: 86%
                                        Reputation:low
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Windows\SysWOW64\rundll32.exe
                                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):2281472
                                        Entropy (8bit):7.87524444106292
                                        Encrypted:false
                                        SSDEEP:49152:QnAMSDbcBVQej/1INRx+DX1HkQo6SAARdhnF:QADoBhz1aRxqk36SAEdhF
                                        MD5:6F25163220B24FB054B144BE9F82C096
                                        SHA1:F49190281384EC665B88C5917CF30E5E1652D27E
                                        SHA-256:3ED3703E2513698E1615793DFFC02D7844A345C03EE37C867ECD7289EFDEC509
                                        SHA-512:00C8489B5F3DC28A43531D0D10663B07AF07FEA06E2CD5927EB1E36D2A54F8B8DC297FF4EA788AF1F798F959306982DE7E77BA87883A6E41E99E337DC2FF7DFF
                                        Malicious:true
                                        Yara Hits:
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Windows\mssecsvr.exe, Author: Joe Security
                                        • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvr.exe, Author: Florian Roth (with the help of binar.ly)
                                        • Rule: WannaCry_Ransomware_Gen, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvr.exe, Author: Florian Roth (based on rule by US CERT)
                                        Antivirus:
                                        • Antivirus: Avira, Detection: 100%
                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                        • Antivirus: ReversingLabs, Detection: 100%
                                        Reputation:low
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......U<S..]=..]=..]=.jA1..]=.A3..]=.~B7..]=.~B6..]=.~B9..]=..R`..]=..]<.J]=.'{6..]=..[;..]=.Rich.]=.........................PE..L.....L......................"...................@...........................P......................................................1..z...........................................................................................................text.............................. ..`.rdata..............................@..@.data....H0......p..................@....rsrc.........1...... ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Windows\mssecsvr.exe
                                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):2061938
                                        Entropy (8bit):7.962002774072566
                                        Encrypted:false
                                        SSDEEP:49152:uMSDbcBVQej/1INRx+DX1HkQo6SAARdhn7:uDoBhz1aRxqk36SAEdh7
                                        MD5:ABA8C6BAE8872F73A473AE3B18F186A4
                                        SHA1:9567DAB5A9E98B1623E0A12ABA3E5788EB32360F
                                        SHA-256:13AEAA8228839201C3BF6632AA7696E549773DE4824DCA3FEBE43FE1D20EF477
                                        SHA-512:F4F6B60997C771D5829DE2E007F2A894A936DF855C100A7D27AF7195DFD9E4C4634E62BFA24103A2CE771EC6ECCF27D19399A1D5552FA9CC02813D5C84E7EEA1
                                        Malicious:true
                                        Antivirus:
                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                        • Antivirus: ReversingLabs, Detection: 86%
                                        Reputation:low
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                        File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                        Entropy (8bit):4.270211266710343
                                        TrID:
                                        • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                                        • Generic Win/DOS Executable (2004/3) 0.20%
                                        • DOS Executable Generic (2002/1) 0.20%
                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                        File name:NLWfV87ouS.dll
                                        File size:5'267'459 bytes
                                        MD5:23d048d04f55b993301b477b1b8bd7a8
                                        SHA1:eef0b45632e55705c1cab4bb6da58e882a8ab865
                                        SHA256:d048f0164808c5daab17d4e224bcaa079ac7371f36618e9e6d4eb1b2b65c3953
                                        SHA512:91404577668856cf80d0a566884bbfef9606be70108b4b31932c46feb329b6b7df1be09a96d1d19fae8ed6cae4fe6b9349831b37b129ee14aa97222bd7cec635
                                        SSDEEP:49152:RnAMSDbcBVQej/1INRx+DX1HkQo6SAARdhn:1ADoBhz1aRxqk36SAEdh
                                        TLSH:ED36124272FC0178F2B37B70D9BA4661ABB77C652A7ED50E5780055E0CF2E80EA61763
                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}.r_9...9...9.......=...9...6.....A.:.......8.......8.......:...Rich9...........................PE..L...QW.Y...........!.......
                                        Icon Hash:7ae282899bbab082
                                        Entrypoint:0x100011e9
                                        Entrypoint Section:.text
                                        Digitally signed:false
                                        Imagebase:0x10000000
                                        Subsystem:windows gui
                                        Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                                        DLL Characteristics:
                                        Time Stamp:0x59145751 [Thu May 11 12:21:37 2017 UTC]
                                        TLS Callbacks:
                                        CLR (.Net) Version:
                                        OS Version Major:4
                                        OS Version Minor:0
                                        File Version Major:4
                                        File Version Minor:0
                                        Subsystem Version Major:4
                                        Subsystem Version Minor:0
                                        Import Hash:2e5708ae5fed0403e8117c645fb23e5b
                                        Instruction
                                        push ebp
                                        mov ebp, esp
                                        push ebx
                                        mov ebx, dword ptr [ebp+08h]
                                        push esi
                                        mov esi, dword ptr [ebp+0Ch]
                                        push edi
                                        mov edi, dword ptr [ebp+10h]
                                        test esi, esi
                                        jne 00007F25191E1C1Bh
                                        cmp dword ptr [10003140h], 00000000h
                                        jmp 00007F25191E1C38h
                                        cmp esi, 01h
                                        je 00007F25191E1C17h
                                        cmp esi, 02h
                                        jne 00007F25191E1C34h
                                        mov eax, dword ptr [10003150h]
                                        test eax, eax
                                        je 00007F25191E1C1Bh
                                        push edi
                                        push esi
                                        push ebx
                                        call eax
                                        test eax, eax
                                        je 00007F25191E1C1Eh
                                        push edi
                                        push esi
                                        push ebx
                                        call 00007F25191E1B2Ah
                                        test eax, eax
                                        jne 00007F25191E1C16h
                                        xor eax, eax
                                        jmp 00007F25191E1C60h
                                        push edi
                                        push esi
                                        push ebx
                                        call 00007F25191E19DCh
                                        cmp esi, 01h
                                        mov dword ptr [ebp+0Ch], eax
                                        jne 00007F25191E1C1Eh
                                        test eax, eax
                                        jne 00007F25191E1C49h
                                        push edi
                                        push eax
                                        push ebx
                                        call 00007F25191E1B06h
                                        test esi, esi
                                        je 00007F25191E1C17h
                                        cmp esi, 03h
                                        jne 00007F25191E1C38h
                                        push edi
                                        push esi
                                        push ebx
                                        call 00007F25191E1AF5h
                                        test eax, eax
                                        jne 00007F25191E1C15h
                                        and dword ptr [ebp+0Ch], eax
                                        cmp dword ptr [ebp+0Ch], 00000000h
                                        je 00007F25191E1C23h
                                        mov eax, dword ptr [10003150h]
                                        test eax, eax
                                        je 00007F25191E1C1Ah
                                        push edi
                                        push esi
                                        push ebx
                                        call eax
                                        mov dword ptr [ebp+0Ch], eax
                                        mov eax, dword ptr [ebp+0Ch]
                                        pop edi
                                        pop esi
                                        pop ebx
                                        pop ebp
                                        retn 000Ch
                                        jmp dword ptr [10002028h]
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        add byte ptr [eax], al
                                        Programming Language:
                                        • [ C ] VS98 (6.0) build 8168
                                        • [C++] VS98 (6.0) build 8168
                                        • [RES] VS98 (6.0) cvtres build 1720
                                        • [LNK] VS98 (6.0) imp/exp build 8168
                                        NameVirtual AddressVirtual Size Is in Section
                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x21900x48.rdata
                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x203c0x3c.rdata
                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x40000x500060.rsrc
                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x5050000x5c.reloc
                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_IAT0x20000x3c.rdata
                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                        .text0x10000x28c0x10008de9a2cb31e4c74bd008b871d14bfafcFalse0.13037109375data1.4429971244731552IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                        .rdata0x20000x1d80x10003dd394f95ab218593f2bc8eb65184db4False0.072509765625data0.7346018133622799IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        .data0x30000x1540x10009b27c3f254416f775f5a51102ef8fb84False0.016845703125Matlab v4 mat-file (little endian) C:\%s\%s, numeric, rows 0, columns 00.085726967663312IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                        .rsrc0x40000x5000600x5010004ca8d8a2ecc4acf499b6a5c3bdc3869dunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        .reloc0x5050000x2ac0x1000620f0b67a91f7f74151bc5be745b7110False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                        NameRVASizeTypeLanguageCountryZLIB Complexity
                                        W0x40600x500000dataEnglishUnited States0.8742046356201172
                                        DLLImport
                                        KERNEL32.dllCloseHandle, WriteFile, CreateFileA, SizeofResource, LockResource, LoadResource, FindResourceA, CreateProcessA
                                        MSVCRT.dllfree, _initterm, malloc, _adjust_fdiv, sprintf
                                        NameOrdinalAddress
                                        PlayGame10x10001114
                                        Language of compilation systemCountry where language is spokenMap
                                        EnglishUnited States
                                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                        2025-01-15T02:58:48.174980+01002830018ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup)1192.168.2.6566061.1.1.153UDP
                                        2025-01-15T02:58:49.093541+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.649710103.224.212.21580TCP
                                        2025-01-15T02:58:50.638385+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.649713103.224.212.21580TCP
                                        TimestampSource PortDest PortSource IPDest IP
                                        Jan 15, 2025 02:58:42.135881901 CET49674443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:58:42.135890961 CET49673443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:58:42.464065075 CET49672443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:58:45.887983084 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:45.888055086 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:45.888319969 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:45.889339924 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:45.889364958 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.690416098 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.690917015 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:46.696274042 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:46.696305037 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.696588993 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.698754072 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:46.698754072 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:46.698754072 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:46.698786974 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.743336916 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.869976997 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.870161057 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:46.870233059 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:46.870872021 CET49709443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:46.870889902 CET4434970940.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:48.486773014 CET4971080192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:48.491657019 CET8049710103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:48.491746902 CET4971080192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:48.492455006 CET4971080192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:48.497163057 CET8049710103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:49.093451977 CET8049710103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:49.093540907 CET4971080192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:49.093667030 CET8049710103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:49.093714952 CET4971080192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:49.227395058 CET4971080192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:49.232403040 CET8049710103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:49.422569990 CET4971280192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:49.427385092 CET8049712199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:49.427531958 CET4971280192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:49.429986954 CET4971280192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:49.434729099 CET8049712199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:49.895385027 CET8049712199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:49.895474911 CET4971280192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:49.895508051 CET8049712199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:49.895550013 CET4971280192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:49.901768923 CET4971280192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:49.901768923 CET4971280192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:50.025569916 CET4971380192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.030575991 CET8049713103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:50.030663013 CET4971380192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.030791044 CET4971380192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.035598040 CET8049713103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:50.438128948 CET4971480192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.443069935 CET8049714103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:50.443156004 CET4971480192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.443291903 CET4971480192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.448426008 CET8049714103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:50.638276100 CET8049713103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:50.638314009 CET8049713103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:50.638385057 CET4971380192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.638407946 CET4971380192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.641323090 CET4971380192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:50.642657995 CET4972080192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:50.646110058 CET8049713103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:50.647568941 CET8049720199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:50.647650957 CET4972080192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:50.647815943 CET4972080192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:50.652637959 CET8049720199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:51.042836905 CET8049714103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:51.042926073 CET8049714103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:51.043061972 CET4971480192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:51.043061972 CET4971480192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:51.046044111 CET4971480192.168.2.6103.224.212.215
                                        Jan 15, 2025 02:58:51.047698021 CET4972180192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.050805092 CET8049714103.224.212.215192.168.2.6
                                        Jan 15, 2025 02:58:51.052594900 CET8049721199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:51.052685022 CET4972180192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.052824020 CET4972180192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.057642937 CET8049721199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:51.136511087 CET8049720199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:51.136528969 CET8049720199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:51.136665106 CET4972080192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.143143892 CET4972080192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.143182039 CET4972080192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.207154989 CET49722445192.168.2.635.203.187.0
                                        Jan 15, 2025 02:58:51.212150097 CET4454972235.203.187.0192.168.2.6
                                        Jan 15, 2025 02:58:51.212259054 CET49722445192.168.2.635.203.187.0
                                        Jan 15, 2025 02:58:51.212970018 CET49722445192.168.2.635.203.187.0
                                        Jan 15, 2025 02:58:51.213175058 CET49723445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:58:51.217822075 CET4454972235.203.187.0192.168.2.6
                                        Jan 15, 2025 02:58:51.217892885 CET49722445192.168.2.635.203.187.0
                                        Jan 15, 2025 02:58:51.217976093 CET4454972335.203.187.1192.168.2.6
                                        Jan 15, 2025 02:58:51.218059063 CET49723445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:58:51.218136072 CET49723445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:58:51.223052979 CET4454972335.203.187.1192.168.2.6
                                        Jan 15, 2025 02:58:51.223120928 CET49723445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:58:51.227346897 CET49724445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:58:51.232176065 CET4454972435.203.187.1192.168.2.6
                                        Jan 15, 2025 02:58:51.232255936 CET49724445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:58:51.232285023 CET49724445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:58:51.237056017 CET4454972435.203.187.1192.168.2.6
                                        Jan 15, 2025 02:58:51.518809080 CET8049721199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:51.518829107 CET8049721199.59.243.228192.168.2.6
                                        Jan 15, 2025 02:58:51.518915892 CET4972180192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.551153898 CET4972180192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.551270008 CET4972180192.168.2.6199.59.243.228
                                        Jan 15, 2025 02:58:51.745202065 CET49674443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:58:51.745206118 CET49673443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:58:52.073328972 CET49672443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:58:53.184592009 CET49762445192.168.2.6161.113.71.198
                                        Jan 15, 2025 02:58:53.189513922 CET44549762161.113.71.198192.168.2.6
                                        Jan 15, 2025 02:58:53.189601898 CET49762445192.168.2.6161.113.71.198
                                        Jan 15, 2025 02:58:53.189640999 CET49762445192.168.2.6161.113.71.198
                                        Jan 15, 2025 02:58:53.189886093 CET49763445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:58:53.194684982 CET44549762161.113.71.198192.168.2.6
                                        Jan 15, 2025 02:58:53.194739103 CET44549763161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:58:53.194749117 CET49762445192.168.2.6161.113.71.198
                                        Jan 15, 2025 02:58:53.194860935 CET49763445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:58:53.194916010 CET49763445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:58:53.196075916 CET49764445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:58:53.199821949 CET44549763161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:58:53.199934006 CET49763445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:58:53.200959921 CET44549764161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:58:53.201031923 CET49764445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:58:53.201081038 CET49764445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:58:53.206322908 CET44549764161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:58:53.738161087 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:53.738218069 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:53.738636971 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:53.739279985 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:53.739298105 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:53.752070904 CET44349706173.222.162.64192.168.2.6
                                        Jan 15, 2025 02:58:53.752563000 CET49706443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:58:54.516700029 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:54.516787052 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:54.519067049 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:54.519089937 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:54.519433975 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:54.521651983 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:54.521724939 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:54.521754980 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:54.521985054 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:54.563339949 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:54.692280054 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:54.692369938 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:54.692496061 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:54.693262100 CET49772443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:58:54.693294048 CET4434977240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:58:55.200000048 CET49798445192.168.2.6185.104.232.204
                                        Jan 15, 2025 02:58:55.204788923 CET44549798185.104.232.204192.168.2.6
                                        Jan 15, 2025 02:58:55.204858065 CET49798445192.168.2.6185.104.232.204
                                        Jan 15, 2025 02:58:55.204961061 CET49798445192.168.2.6185.104.232.204
                                        Jan 15, 2025 02:58:55.205219984 CET49799445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:58:55.209877968 CET44549798185.104.232.204192.168.2.6
                                        Jan 15, 2025 02:58:55.209943056 CET49798445192.168.2.6185.104.232.204
                                        Jan 15, 2025 02:58:55.209995985 CET44549799185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:58:55.210057020 CET49799445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:58:55.210185051 CET49799445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:58:55.211690903 CET49800445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:58:55.215028048 CET44549799185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:58:55.215076923 CET49799445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:58:55.216512918 CET44549800185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:58:55.216576099 CET49800445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:58:55.216638088 CET49800445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:58:55.221425056 CET44549800185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:58:57.217803001 CET49834445192.168.2.646.91.122.159
                                        Jan 15, 2025 02:58:57.222732067 CET4454983446.91.122.159192.168.2.6
                                        Jan 15, 2025 02:58:57.222824097 CET49834445192.168.2.646.91.122.159
                                        Jan 15, 2025 02:58:57.222908020 CET49834445192.168.2.646.91.122.159
                                        Jan 15, 2025 02:58:57.223150969 CET49835445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:58:57.227863073 CET4454983446.91.122.159192.168.2.6
                                        Jan 15, 2025 02:58:57.227938890 CET4454983546.91.122.1192.168.2.6
                                        Jan 15, 2025 02:58:57.227938890 CET49834445192.168.2.646.91.122.159
                                        Jan 15, 2025 02:58:57.228023052 CET49835445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:58:57.228132963 CET49835445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:58:57.230849981 CET49836445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:58:57.232928991 CET4454983546.91.122.1192.168.2.6
                                        Jan 15, 2025 02:58:57.232991934 CET49835445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:58:57.235671043 CET4454983646.91.122.1192.168.2.6
                                        Jan 15, 2025 02:58:57.235788107 CET49836445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:58:57.235846996 CET49836445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:58:57.240596056 CET4454983646.91.122.1192.168.2.6
                                        Jan 15, 2025 02:58:59.231079102 CET49867445192.168.2.6101.167.235.244
                                        Jan 15, 2025 02:58:59.235903025 CET44549867101.167.235.244192.168.2.6
                                        Jan 15, 2025 02:58:59.236093044 CET49867445192.168.2.6101.167.235.244
                                        Jan 15, 2025 02:58:59.236141920 CET49867445192.168.2.6101.167.235.244
                                        Jan 15, 2025 02:58:59.236351967 CET49869445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:58:59.241027117 CET44549867101.167.235.244192.168.2.6
                                        Jan 15, 2025 02:58:59.241094112 CET49867445192.168.2.6101.167.235.244
                                        Jan 15, 2025 02:58:59.241169930 CET44549869101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:58:59.241255045 CET49869445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:58:59.241281986 CET49869445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:58:59.242405891 CET49870445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:58:59.246155024 CET44549869101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:58:59.246211052 CET49869445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:58:59.247257948 CET44549870101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:58:59.247322083 CET49870445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:58:59.247354031 CET49870445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:58:59.252140045 CET44549870101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:01.247191906 CET49905445192.168.2.663.231.161.18
                                        Jan 15, 2025 02:59:01.252101898 CET4454990563.231.161.18192.168.2.6
                                        Jan 15, 2025 02:59:01.252233028 CET49905445192.168.2.663.231.161.18
                                        Jan 15, 2025 02:59:01.252309084 CET49905445192.168.2.663.231.161.18
                                        Jan 15, 2025 02:59:01.252456903 CET49906445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:01.257368088 CET4454990663.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:01.257383108 CET4454990563.231.161.18192.168.2.6
                                        Jan 15, 2025 02:59:01.257443905 CET49905445192.168.2.663.231.161.18
                                        Jan 15, 2025 02:59:01.257458925 CET49906445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:01.257577896 CET49906445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:01.258668900 CET49907445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:01.262667894 CET4454990663.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:01.262722969 CET49906445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:01.263420105 CET4454990763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:01.263498068 CET49907445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:01.263648033 CET49907445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:01.268392086 CET4454990763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:03.262016058 CET49939445192.168.2.640.9.17.111
                                        Jan 15, 2025 02:59:03.266798019 CET4454993940.9.17.111192.168.2.6
                                        Jan 15, 2025 02:59:03.267005920 CET49939445192.168.2.640.9.17.111
                                        Jan 15, 2025 02:59:03.267005920 CET49939445192.168.2.640.9.17.111
                                        Jan 15, 2025 02:59:03.267170906 CET49940445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:03.271976948 CET4454994040.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:03.272032976 CET4454993940.9.17.111192.168.2.6
                                        Jan 15, 2025 02:59:03.272049904 CET49940445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:03.272108078 CET49939445192.168.2.640.9.17.111
                                        Jan 15, 2025 02:59:03.272111893 CET49940445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:03.272552013 CET49941445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:03.277004004 CET4454994040.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:03.277059078 CET49940445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:03.277379990 CET4454994140.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:03.277446985 CET49941445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:03.277537107 CET49941445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:03.282335043 CET4454994140.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:04.120349884 CET49706443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:59:04.120496988 CET49706443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:59:04.121084929 CET49956443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:59:04.121169090 CET44349956173.222.162.64192.168.2.6
                                        Jan 15, 2025 02:59:04.121328115 CET49956443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:59:04.122010946 CET49956443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:59:04.122030020 CET44349956173.222.162.64192.168.2.6
                                        Jan 15, 2025 02:59:04.129115105 CET44349706173.222.162.64192.168.2.6
                                        Jan 15, 2025 02:59:04.129127026 CET44349706173.222.162.64192.168.2.6
                                        Jan 15, 2025 02:59:04.715955019 CET44349956173.222.162.64192.168.2.6
                                        Jan 15, 2025 02:59:04.716125011 CET49956443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:59:05.277646065 CET49980445192.168.2.6155.184.140.85
                                        Jan 15, 2025 02:59:05.282529116 CET44549980155.184.140.85192.168.2.6
                                        Jan 15, 2025 02:59:05.283137083 CET49980445192.168.2.6155.184.140.85
                                        Jan 15, 2025 02:59:05.283236980 CET49980445192.168.2.6155.184.140.85
                                        Jan 15, 2025 02:59:05.288197994 CET44549980155.184.140.85192.168.2.6
                                        Jan 15, 2025 02:59:05.288413048 CET49980445192.168.2.6155.184.140.85
                                        Jan 15, 2025 02:59:05.291387081 CET49981445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:05.296633005 CET44549981155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:05.296699047 CET49981445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:05.296730042 CET49981445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:05.297135115 CET49982445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:05.301843882 CET44549981155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:05.301903009 CET49981445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:05.301966906 CET44549982155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:05.302210093 CET49982445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:05.302210093 CET49982445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:05.307024956 CET44549982155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:05.974064112 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:05.974109888 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:05.974373102 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:05.975547075 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:05.975562096 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.765645981 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.765703917 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:06.772289991 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:06.772301912 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.772658110 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.778918028 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:06.778990984 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:06.778995991 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.779136896 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:06.819349051 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.955692053 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.956413984 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:06.956494093 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:06.960335970 CET49992443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:06.960350990 CET4434999240.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:07.513768911 CET50016445192.168.2.672.138.233.78
                                        Jan 15, 2025 02:59:07.518588066 CET4455001672.138.233.78192.168.2.6
                                        Jan 15, 2025 02:59:07.520174980 CET50016445192.168.2.672.138.233.78
                                        Jan 15, 2025 02:59:07.520551920 CET50016445192.168.2.672.138.233.78
                                        Jan 15, 2025 02:59:07.524461031 CET50019445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:07.525412083 CET4455001672.138.233.78192.168.2.6
                                        Jan 15, 2025 02:59:07.525465012 CET50016445192.168.2.672.138.233.78
                                        Jan 15, 2025 02:59:07.529320002 CET4455001972.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:07.529400110 CET50019445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:07.529913902 CET50019445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:07.530874014 CET50021445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:07.534764051 CET4455001972.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:07.534826994 CET50019445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:07.535710096 CET4455002172.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:07.535770893 CET50021445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:07.535816908 CET50021445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:07.540611029 CET4455002172.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:09.495798111 CET50056445192.168.2.618.166.199.139
                                        Jan 15, 2025 02:59:09.500636101 CET4455005618.166.199.139192.168.2.6
                                        Jan 15, 2025 02:59:09.500823975 CET50056445192.168.2.618.166.199.139
                                        Jan 15, 2025 02:59:09.500897884 CET50056445192.168.2.618.166.199.139
                                        Jan 15, 2025 02:59:09.501081944 CET50057445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:09.505753994 CET4455005618.166.199.139192.168.2.6
                                        Jan 15, 2025 02:59:09.505808115 CET50056445192.168.2.618.166.199.139
                                        Jan 15, 2025 02:59:09.505855083 CET4455005718.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:09.505922079 CET50057445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:09.505987883 CET50057445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:09.506267071 CET50058445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:09.510957003 CET4455005718.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:09.511008024 CET50057445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:09.511038065 CET4455005818.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:09.511113882 CET50058445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:09.511137962 CET50058445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:09.515927076 CET4455005818.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:11.512042046 CET50093445192.168.2.623.170.165.153
                                        Jan 15, 2025 02:59:11.516910076 CET4455009323.170.165.153192.168.2.6
                                        Jan 15, 2025 02:59:11.517024994 CET50093445192.168.2.623.170.165.153
                                        Jan 15, 2025 02:59:11.521989107 CET50093445192.168.2.623.170.165.153
                                        Jan 15, 2025 02:59:11.522433043 CET50094445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:11.526806116 CET4455009323.170.165.153192.168.2.6
                                        Jan 15, 2025 02:59:11.526864052 CET50093445192.168.2.623.170.165.153
                                        Jan 15, 2025 02:59:11.527177095 CET4455009423.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:11.527235985 CET50094445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:11.527328968 CET50094445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:11.527611017 CET50095445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:11.532118082 CET4455009423.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:11.532165051 CET50094445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:11.532386065 CET4455009523.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:11.532445908 CET50095445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:11.532483101 CET50095445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:11.537188053 CET4455009523.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:12.613862038 CET4454972435.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:12.614136934 CET49724445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:12.614195108 CET49724445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:12.614264011 CET49724445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:12.618957996 CET4454972435.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:12.619368076 CET4454972435.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:13.527268887 CET50129445192.168.2.631.108.191.151
                                        Jan 15, 2025 02:59:13.532227039 CET4455012931.108.191.151192.168.2.6
                                        Jan 15, 2025 02:59:13.532351971 CET50129445192.168.2.631.108.191.151
                                        Jan 15, 2025 02:59:13.532351971 CET50129445192.168.2.631.108.191.151
                                        Jan 15, 2025 02:59:13.532584906 CET50130445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:13.537305117 CET4455012931.108.191.151192.168.2.6
                                        Jan 15, 2025 02:59:13.537365913 CET50129445192.168.2.631.108.191.151
                                        Jan 15, 2025 02:59:13.537367105 CET4455013031.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:13.537431002 CET50130445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:13.537574053 CET50130445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:13.537918091 CET50131445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:13.542344093 CET4455013031.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:13.542550087 CET50130445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:13.542674065 CET4455013131.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:13.542732000 CET50131445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:13.542884111 CET50131445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:13.547693014 CET4455013131.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:14.550262928 CET44549764161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:14.550335884 CET49764445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:14.550398111 CET49764445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:14.550471067 CET49764445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:14.555150986 CET44549764161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:14.555258989 CET44549764161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:15.543045044 CET50166445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.547890902 CET44550166100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:15.547971010 CET50166445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.548064947 CET50166445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.548199892 CET50167445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.553081036 CET44550166100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:15.553112984 CET44550167100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:15.553150892 CET50166445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.553189993 CET50167445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.553275108 CET50167445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.553596020 CET50168445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.558154106 CET44550167100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:15.558206081 CET50167445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.558525085 CET44550168100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:15.558630943 CET50168445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.558630943 CET50168445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:15.563580036 CET44550168100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:15.620507002 CET50171445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:15.625468969 CET4455017135.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:15.625577927 CET50171445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:15.625619888 CET50171445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:15.630528927 CET4455017135.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:16.613444090 CET44549800185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:16.613514900 CET49800445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:16.613595963 CET49800445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:16.613696098 CET49800445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:16.618454933 CET44549800185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:16.618464947 CET44549800185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:17.558113098 CET50190445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:17.558442116 CET50191445192.168.2.6148.225.116.104
                                        Jan 15, 2025 02:59:17.623383045 CET44550190161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:17.623416901 CET44550191148.225.116.104192.168.2.6
                                        Jan 15, 2025 02:59:17.623475075 CET50190445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:17.623507023 CET50191445192.168.2.6148.225.116.104
                                        Jan 15, 2025 02:59:17.623549938 CET50190445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:17.623779058 CET50191445192.168.2.6148.225.116.104
                                        Jan 15, 2025 02:59:17.623982906 CET50192445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:17.632230997 CET44550190161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:17.632251978 CET44550191148.225.116.104192.168.2.6
                                        Jan 15, 2025 02:59:17.632266045 CET44550192148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:17.632307053 CET50191445192.168.2.6148.225.116.104
                                        Jan 15, 2025 02:59:17.632360935 CET50192445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:17.632445097 CET50192445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:17.632771969 CET50193445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:17.637506008 CET44550192148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:17.637582064 CET50192445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:17.637747049 CET44550193148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:17.637813091 CET50193445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:17.637849092 CET50193445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:17.642602921 CET44550193148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:18.603419065 CET4454983646.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:18.603575945 CET49836445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:18.603828907 CET49836445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:18.603828907 CET49836445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:18.608632088 CET4454983646.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:18.608661890 CET4454983646.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:19.573872089 CET50208445192.168.2.6163.151.111.193
                                        Jan 15, 2025 02:59:19.578675985 CET44550208163.151.111.193192.168.2.6
                                        Jan 15, 2025 02:59:19.578785896 CET50208445192.168.2.6163.151.111.193
                                        Jan 15, 2025 02:59:19.578850985 CET50208445192.168.2.6163.151.111.193
                                        Jan 15, 2025 02:59:19.579009056 CET50209445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:19.583733082 CET44550208163.151.111.193192.168.2.6
                                        Jan 15, 2025 02:59:19.583836079 CET44550209163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:19.583847046 CET50208445192.168.2.6163.151.111.193
                                        Jan 15, 2025 02:59:19.583920002 CET50209445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:19.583956957 CET50209445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:19.584259033 CET50211445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:19.589543104 CET44550211163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:19.589610100 CET50211445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:19.589670897 CET50211445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:19.589709997 CET44550209163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:19.589760065 CET50209445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:19.594538927 CET44550211163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:19.620481968 CET50212445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:19.625319004 CET44550212185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:19.625391006 CET50212445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:19.625435114 CET50212445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:19.630182028 CET44550212185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:20.613401890 CET44549870101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:20.613498926 CET49870445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:20.613898039 CET49870445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:20.614029884 CET49870445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:20.618731022 CET44549870101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:20.618761063 CET44549870101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:21.589657068 CET50224445192.168.2.6220.177.196.132
                                        Jan 15, 2025 02:59:21.594506025 CET44550224220.177.196.132192.168.2.6
                                        Jan 15, 2025 02:59:21.594599962 CET50224445192.168.2.6220.177.196.132
                                        Jan 15, 2025 02:59:21.594630003 CET50224445192.168.2.6220.177.196.132
                                        Jan 15, 2025 02:59:21.594909906 CET50225445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:21.599680901 CET44550224220.177.196.132192.168.2.6
                                        Jan 15, 2025 02:59:21.599741936 CET44550225220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:21.599747896 CET50224445192.168.2.6220.177.196.132
                                        Jan 15, 2025 02:59:21.599828005 CET50225445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:21.599947929 CET50225445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:21.600231886 CET50226445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:21.604909897 CET50227445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:21.605242968 CET44550225220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:21.605307102 CET50225445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:21.605715990 CET44550226220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:21.605787992 CET50226445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:21.605798006 CET50226445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:21.610646009 CET4455022746.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:21.610716105 CET50227445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:21.610815048 CET50227445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:21.611095905 CET44550226220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:21.616266012 CET4455022746.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:22.613643885 CET4454990763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:22.613711119 CET49907445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:22.613837957 CET49907445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:22.613955975 CET49907445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:22.618598938 CET4454990763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:22.618769884 CET4454990763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:23.605575085 CET50242445192.168.2.6159.140.202.246
                                        Jan 15, 2025 02:59:23.610637903 CET44550242159.140.202.246192.168.2.6
                                        Jan 15, 2025 02:59:23.610713005 CET50242445192.168.2.6159.140.202.246
                                        Jan 15, 2025 02:59:23.610764027 CET50242445192.168.2.6159.140.202.246
                                        Jan 15, 2025 02:59:23.610963106 CET50243445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:23.615935087 CET44550243159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:23.615998983 CET50243445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:23.616027117 CET50243445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:23.616060972 CET44550242159.140.202.246192.168.2.6
                                        Jan 15, 2025 02:59:23.616111040 CET50242445192.168.2.6159.140.202.246
                                        Jan 15, 2025 02:59:23.616380930 CET50244445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:23.620429993 CET50245445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:23.621036053 CET44550243159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:23.621093035 CET50243445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:23.621197939 CET44550244159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:23.621268034 CET50244445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:23.621299982 CET50244445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:23.625195980 CET44550245101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:23.625257015 CET50245445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:23.625293016 CET50245445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:23.626141071 CET44550244159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:23.630032063 CET44550245101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:23.868396044 CET44349956173.222.162.64192.168.2.6
                                        Jan 15, 2025 02:59:23.868530035 CET49956443192.168.2.6173.222.162.64
                                        Jan 15, 2025 02:59:24.595587015 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:24.595628977 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:24.595699072 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:24.596419096 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:24.596431971 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:24.629334927 CET4454994140.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:24.629417896 CET49941445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:24.629453897 CET49941445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:24.629488945 CET49941445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:24.634325027 CET4454994140.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:24.634356022 CET4454994140.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:25.416003942 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.416105032 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:25.417964935 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:25.417978048 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.418766022 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.421250105 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:25.421308041 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:25.421312094 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.421436071 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:25.467333078 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.606719971 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.606944084 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.607007980 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:25.607269049 CET50251443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:25.607290030 CET4435025140.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:25.620690107 CET50257445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:25.621023893 CET50258445192.168.2.6148.177.241.3
                                        Jan 15, 2025 02:59:25.625494957 CET4455025763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:25.625574112 CET50257445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:25.625643969 CET50257445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:25.625910997 CET44550258148.177.241.3192.168.2.6
                                        Jan 15, 2025 02:59:25.625967026 CET50258445192.168.2.6148.177.241.3
                                        Jan 15, 2025 02:59:25.625994921 CET50258445192.168.2.6148.177.241.3
                                        Jan 15, 2025 02:59:25.626149893 CET50259445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:25.630398035 CET4455025763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:25.630850077 CET44550258148.177.241.3192.168.2.6
                                        Jan 15, 2025 02:59:25.630861998 CET44550259148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:25.630901098 CET50258445192.168.2.6148.177.241.3
                                        Jan 15, 2025 02:59:25.630935907 CET50259445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:25.630992889 CET50259445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:25.631246090 CET50260445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:25.635881901 CET44550259148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:25.635922909 CET50259445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:25.636058092 CET44550260148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:25.636116982 CET50260445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:25.636132956 CET50260445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:25.640878916 CET44550260148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:26.644747972 CET44549982155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:26.646941900 CET49982445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:26.646994114 CET49982445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:26.647080898 CET49982445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:26.651802063 CET44549982155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:26.651889086 CET44549982155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:27.495876074 CET50275445192.168.2.6175.101.165.72
                                        Jan 15, 2025 02:59:27.500751019 CET44550275175.101.165.72192.168.2.6
                                        Jan 15, 2025 02:59:27.502538919 CET50275445192.168.2.6175.101.165.72
                                        Jan 15, 2025 02:59:27.502634048 CET50275445192.168.2.6175.101.165.72
                                        Jan 15, 2025 02:59:27.502739906 CET50276445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:27.507517099 CET44550276175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:27.507571936 CET44550275175.101.165.72192.168.2.6
                                        Jan 15, 2025 02:59:27.507719040 CET50275445192.168.2.6175.101.165.72
                                        Jan 15, 2025 02:59:27.507735014 CET50276445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:27.507735014 CET50276445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:27.508021116 CET50277445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:27.512645960 CET44550276175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:27.512718916 CET50276445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:27.512754917 CET44550277175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:27.514591932 CET50277445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:27.514591932 CET50277445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:27.519404888 CET44550277175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:27.694224119 CET50279445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:27.699124098 CET4455027940.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:27.700756073 CET50279445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:27.702395916 CET50279445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:27.707159996 CET4455027940.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:28.917570114 CET4455002172.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:28.917792082 CET50021445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:28.917860985 CET50021445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:28.917901039 CET50021445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:28.924515963 CET4455002172.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:28.924547911 CET4455002172.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:29.245857954 CET50290445192.168.2.6159.199.82.84
                                        Jan 15, 2025 02:59:29.250917912 CET44550290159.199.82.84192.168.2.6
                                        Jan 15, 2025 02:59:29.251046896 CET50290445192.168.2.6159.199.82.84
                                        Jan 15, 2025 02:59:29.251146078 CET50290445192.168.2.6159.199.82.84
                                        Jan 15, 2025 02:59:29.251449108 CET50291445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:29.256145954 CET44550290159.199.82.84192.168.2.6
                                        Jan 15, 2025 02:59:29.256237030 CET50290445192.168.2.6159.199.82.84
                                        Jan 15, 2025 02:59:29.256331921 CET44550291159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:29.256495953 CET50291445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:29.256495953 CET50291445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:29.256884098 CET50292445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:29.261497974 CET44550291159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:29.261723042 CET44550292159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:29.261883974 CET50292445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:29.261913061 CET50292445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:29.261934996 CET50291445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:29.266787052 CET44550292159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:29.651747942 CET50293445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:29.656716108 CET44550293155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:29.656991005 CET50293445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:29.657285929 CET50293445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:29.662132025 CET44550293155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:30.883280039 CET4455005818.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:30.883372068 CET50058445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:30.884285927 CET50058445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:30.884329081 CET50058445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:30.889147997 CET4455005818.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:30.889178038 CET4455005818.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:30.892954111 CET50304445192.168.2.655.211.247.250
                                        Jan 15, 2025 02:59:30.897887945 CET4455030455.211.247.250192.168.2.6
                                        Jan 15, 2025 02:59:30.897969961 CET50304445192.168.2.655.211.247.250
                                        Jan 15, 2025 02:59:30.898066044 CET50304445192.168.2.655.211.247.250
                                        Jan 15, 2025 02:59:30.898212910 CET50305445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:30.903110027 CET4455030455.211.247.250192.168.2.6
                                        Jan 15, 2025 02:59:30.903141022 CET4455030555.211.247.1192.168.2.6
                                        Jan 15, 2025 02:59:30.903160095 CET50304445192.168.2.655.211.247.250
                                        Jan 15, 2025 02:59:30.903202057 CET50305445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:30.903625011 CET50305445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:30.907711983 CET50306445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:30.908524036 CET4455030555.211.247.1192.168.2.6
                                        Jan 15, 2025 02:59:30.908575058 CET50305445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:30.912581921 CET4455030655.211.247.1192.168.2.6
                                        Jan 15, 2025 02:59:30.912647009 CET50306445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:30.912748098 CET50306445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:30.917526007 CET4455030655.211.247.1192.168.2.6
                                        Jan 15, 2025 02:59:31.933258057 CET50313445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:31.938059092 CET4455031372.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:31.941818953 CET50313445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:31.941818953 CET50313445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:31.946723938 CET4455031372.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:32.417658091 CET50318445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.422525883 CET4455031814.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:32.426441908 CET50318445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.426565886 CET50318445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.426573038 CET50319445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.431431055 CET4455031914.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:32.431487083 CET4455031814.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:32.431565046 CET50318445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.431641102 CET50319445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.431642056 CET50319445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.431865931 CET50320445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.436604977 CET4455031914.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:32.436680079 CET4455032014.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:32.436700106 CET50319445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.436777115 CET50320445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.436794043 CET50320445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:32.441601038 CET4455032014.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:32.895006895 CET4455009523.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:32.895096064 CET50095445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:32.895145893 CET50095445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:32.895175934 CET50095445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:32.899998903 CET4455009523.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:32.900010109 CET4455009523.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:33.839548111 CET50322445192.168.2.6114.251.20.227
                                        Jan 15, 2025 02:59:33.844341993 CET44550322114.251.20.227192.168.2.6
                                        Jan 15, 2025 02:59:33.844424009 CET50322445192.168.2.6114.251.20.227
                                        Jan 15, 2025 02:59:33.844506979 CET50322445192.168.2.6114.251.20.227
                                        Jan 15, 2025 02:59:33.844652891 CET50323445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:33.849457979 CET44550322114.251.20.227192.168.2.6
                                        Jan 15, 2025 02:59:33.849503994 CET44550323114.251.20.1192.168.2.6
                                        Jan 15, 2025 02:59:33.849538088 CET50322445192.168.2.6114.251.20.227
                                        Jan 15, 2025 02:59:33.849564075 CET50323445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:33.849632025 CET50323445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:33.849942923 CET50324445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:33.854523897 CET44550323114.251.20.1192.168.2.6
                                        Jan 15, 2025 02:59:33.854593992 CET50323445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:33.854743004 CET44550324114.251.20.1192.168.2.6
                                        Jan 15, 2025 02:59:33.854805946 CET50324445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:33.854859114 CET50324445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:33.859622002 CET44550324114.251.20.1192.168.2.6
                                        Jan 15, 2025 02:59:33.886084080 CET50325445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:33.891094923 CET4455032518.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:33.891186953 CET50325445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:33.891186953 CET50325445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:33.896285057 CET4455032518.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:34.927978039 CET4455013131.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:34.928082943 CET50131445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:34.928113937 CET50131445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:34.928169966 CET50131445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:34.932975054 CET4455013131.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:34.933007002 CET4455013131.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:35.167762995 CET50326445192.168.2.6181.130.123.70
                                        Jan 15, 2025 02:59:35.172593117 CET44550326181.130.123.70192.168.2.6
                                        Jan 15, 2025 02:59:35.172714949 CET50326445192.168.2.6181.130.123.70
                                        Jan 15, 2025 02:59:35.172728062 CET50326445192.168.2.6181.130.123.70
                                        Jan 15, 2025 02:59:35.172986984 CET50327445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:35.177810907 CET44550326181.130.123.70192.168.2.6
                                        Jan 15, 2025 02:59:35.177875996 CET50326445192.168.2.6181.130.123.70
                                        Jan 15, 2025 02:59:35.177922010 CET44550327181.130.123.1192.168.2.6
                                        Jan 15, 2025 02:59:35.178020954 CET50327445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:35.178101063 CET50327445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:35.178278923 CET50328445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:35.183046103 CET44550327181.130.123.1192.168.2.6
                                        Jan 15, 2025 02:59:35.183100939 CET44550328181.130.123.1192.168.2.6
                                        Jan 15, 2025 02:59:35.183120012 CET50327445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:35.183170080 CET50328445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:35.183196068 CET50328445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:35.187974930 CET44550328181.130.123.1192.168.2.6
                                        Jan 15, 2025 02:59:35.901792049 CET50329445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:35.906673908 CET4455032923.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:35.906758070 CET50329445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:35.906785011 CET50329445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:35.911601067 CET4455032923.170.165.1192.168.2.6
                                        Jan 15, 2025 02:59:36.407246113 CET50330445192.168.2.684.223.7.174
                                        Jan 15, 2025 02:59:36.412236929 CET4455033084.223.7.174192.168.2.6
                                        Jan 15, 2025 02:59:36.412324905 CET50330445192.168.2.684.223.7.174
                                        Jan 15, 2025 02:59:36.412405968 CET50330445192.168.2.684.223.7.174
                                        Jan 15, 2025 02:59:36.412571907 CET50331445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:36.417363882 CET4455033184.223.7.1192.168.2.6
                                        Jan 15, 2025 02:59:36.417435884 CET4455033084.223.7.174192.168.2.6
                                        Jan 15, 2025 02:59:36.417442083 CET50331445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:36.417484999 CET50330445192.168.2.684.223.7.174
                                        Jan 15, 2025 02:59:36.419420004 CET50331445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:36.423080921 CET50332445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:36.424267054 CET4455033184.223.7.1192.168.2.6
                                        Jan 15, 2025 02:59:36.424284935 CET4455033184.223.7.1192.168.2.6
                                        Jan 15, 2025 02:59:36.424329996 CET50331445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:36.427968979 CET4455033284.223.7.1192.168.2.6
                                        Jan 15, 2025 02:59:36.428044081 CET50332445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:36.430110931 CET50332445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:36.434974909 CET4455033284.223.7.1192.168.2.6
                                        Jan 15, 2025 02:59:36.946058989 CET44550168100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:36.946122885 CET50168445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:36.946202993 CET50168445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:36.946202993 CET50168445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:36.950962067 CET44550168100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:36.950984955 CET44550168100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:36.973092079 CET4455017135.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:36.973169088 CET50171445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:36.973223925 CET50171445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:36.973290920 CET50171445192.168.2.635.203.187.1
                                        Jan 15, 2025 02:59:36.978108883 CET4455017135.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:36.978121996 CET4455017135.203.187.1192.168.2.6
                                        Jan 15, 2025 02:59:37.027266026 CET50333445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:37.032100916 CET4455033335.203.187.2192.168.2.6
                                        Jan 15, 2025 02:59:37.032185078 CET50333445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:37.032272100 CET50333445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:37.032751083 CET50334445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:37.037139893 CET4455033335.203.187.2192.168.2.6
                                        Jan 15, 2025 02:59:37.037206888 CET50333445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:37.037549019 CET4455033435.203.187.2192.168.2.6
                                        Jan 15, 2025 02:59:37.037611961 CET50334445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:37.037655115 CET50334445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:37.042376995 CET4455033435.203.187.2192.168.2.6
                                        Jan 15, 2025 02:59:37.558612108 CET50335445192.168.2.665.242.217.35
                                        Jan 15, 2025 02:59:37.563648939 CET4455033565.242.217.35192.168.2.6
                                        Jan 15, 2025 02:59:37.563771963 CET50335445192.168.2.665.242.217.35
                                        Jan 15, 2025 02:59:37.563771963 CET50335445192.168.2.665.242.217.35
                                        Jan 15, 2025 02:59:37.563961983 CET50336445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:37.568973064 CET4455033665.242.217.1192.168.2.6
                                        Jan 15, 2025 02:59:37.568994045 CET4455033565.242.217.35192.168.2.6
                                        Jan 15, 2025 02:59:37.569039106 CET50336445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:37.569118023 CET50335445192.168.2.665.242.217.35
                                        Jan 15, 2025 02:59:37.569189072 CET50336445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:37.569590092 CET50337445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:37.574029922 CET4455033665.242.217.1192.168.2.6
                                        Jan 15, 2025 02:59:37.574263096 CET50336445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:37.574454069 CET4455033765.242.217.1192.168.2.6
                                        Jan 15, 2025 02:59:37.574522972 CET50337445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:37.574558020 CET50337445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:37.579293966 CET4455033765.242.217.1192.168.2.6
                                        Jan 15, 2025 02:59:37.933125973 CET50338445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:37.938086033 CET4455033831.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:37.940905094 CET50338445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:37.940949917 CET50338445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:37.945806026 CET4455033831.108.191.1192.168.2.6
                                        Jan 15, 2025 02:59:38.637471914 CET50339445192.168.2.623.53.146.99
                                        Jan 15, 2025 02:59:38.642410040 CET4455033923.53.146.99192.168.2.6
                                        Jan 15, 2025 02:59:38.645822048 CET50339445192.168.2.623.53.146.99
                                        Jan 15, 2025 02:59:38.645937920 CET50339445192.168.2.623.53.146.99
                                        Jan 15, 2025 02:59:38.646133900 CET50340445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:38.650816917 CET4455033923.53.146.99192.168.2.6
                                        Jan 15, 2025 02:59:38.650913954 CET4455034023.53.146.1192.168.2.6
                                        Jan 15, 2025 02:59:38.650976896 CET50339445192.168.2.623.53.146.99
                                        Jan 15, 2025 02:59:38.651005983 CET50340445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:38.651073933 CET50340445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:38.651354074 CET50341445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:38.655987978 CET4455034023.53.146.1192.168.2.6
                                        Jan 15, 2025 02:59:38.656172991 CET4455034123.53.146.1192.168.2.6
                                        Jan 15, 2025 02:59:38.656223059 CET50340445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:38.656248093 CET50341445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:38.656287909 CET50341445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:38.661011934 CET4455034123.53.146.1192.168.2.6
                                        Jan 15, 2025 02:59:39.004539013 CET44550190161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:39.004626036 CET50190445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:39.005204916 CET44550193148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:39.005258083 CET50193445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:39.006354094 CET50190445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:39.006386995 CET50193445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:39.006422043 CET50190445192.168.2.6161.113.71.1
                                        Jan 15, 2025 02:59:39.010813951 CET50193445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:39.011127949 CET44550190161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:39.011185884 CET44550193148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:39.011221886 CET44550190161.113.71.1192.168.2.6
                                        Jan 15, 2025 02:59:39.015582085 CET44550193148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:39.125732899 CET50342445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:39.130811930 CET44550342161.113.71.2192.168.2.6
                                        Jan 15, 2025 02:59:39.130902052 CET50342445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:39.131004095 CET50342445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:39.133006096 CET50343445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:39.136291027 CET44550342161.113.71.2192.168.2.6
                                        Jan 15, 2025 02:59:39.136651993 CET44550342161.113.71.2192.168.2.6
                                        Jan 15, 2025 02:59:39.136727095 CET50342445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:39.137803078 CET44550343161.113.71.2192.168.2.6
                                        Jan 15, 2025 02:59:39.137871027 CET50343445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:39.137928963 CET50343445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:39.142786980 CET44550343161.113.71.2192.168.2.6
                                        Jan 15, 2025 02:59:39.652014017 CET50344445192.168.2.6171.163.176.74
                                        Jan 15, 2025 02:59:39.656925917 CET44550344171.163.176.74192.168.2.6
                                        Jan 15, 2025 02:59:39.657037020 CET50344445192.168.2.6171.163.176.74
                                        Jan 15, 2025 02:59:39.657037020 CET50344445192.168.2.6171.163.176.74
                                        Jan 15, 2025 02:59:39.657262087 CET50345445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:39.662086010 CET44550345171.163.176.1192.168.2.6
                                        Jan 15, 2025 02:59:39.662117958 CET44550344171.163.176.74192.168.2.6
                                        Jan 15, 2025 02:59:39.662156105 CET50345445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:39.662178040 CET50345445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:39.662185907 CET50344445192.168.2.6171.163.176.74
                                        Jan 15, 2025 02:59:39.662561893 CET50346445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:39.667442083 CET44550345171.163.176.1192.168.2.6
                                        Jan 15, 2025 02:59:39.667454958 CET44550346171.163.176.1192.168.2.6
                                        Jan 15, 2025 02:59:39.667496920 CET50345445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:39.667531013 CET50346445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:39.667552948 CET50346445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:39.672313929 CET44550346171.163.176.1192.168.2.6
                                        Jan 15, 2025 02:59:39.948787928 CET50347445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:39.953788996 CET44550347100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:39.956573009 CET50347445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:39.956666946 CET50347445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:39.961805105 CET44550347100.236.46.1192.168.2.6
                                        Jan 15, 2025 02:59:40.589708090 CET50348445192.168.2.649.55.159.218
                                        Jan 15, 2025 02:59:40.594624996 CET4455034849.55.159.218192.168.2.6
                                        Jan 15, 2025 02:59:40.596609116 CET50348445192.168.2.649.55.159.218
                                        Jan 15, 2025 02:59:40.596682072 CET50348445192.168.2.649.55.159.218
                                        Jan 15, 2025 02:59:40.596843958 CET50349445192.168.2.649.55.159.1
                                        Jan 15, 2025 02:59:40.601708889 CET4455034949.55.159.1192.168.2.6
                                        Jan 15, 2025 02:59:40.601723909 CET4455034849.55.159.218192.168.2.6
                                        Jan 15, 2025 02:59:40.601819992 CET50348445192.168.2.649.55.159.218
                                        Jan 15, 2025 02:59:40.601819992 CET50349445192.168.2.649.55.159.1
                                        Jan 15, 2025 02:59:40.602257013 CET50350445192.168.2.649.55.159.1
                                        Jan 15, 2025 02:59:40.606734991 CET4455034949.55.159.1192.168.2.6
                                        Jan 15, 2025 02:59:40.607068062 CET4455035049.55.159.1192.168.2.6
                                        Jan 15, 2025 02:59:40.607129097 CET50349445192.168.2.649.55.159.1
                                        Jan 15, 2025 02:59:40.607166052 CET50350445192.168.2.649.55.159.1
                                        Jan 15, 2025 02:59:40.607214928 CET50350445192.168.2.649.55.159.1
                                        Jan 15, 2025 02:59:40.611973047 CET4455035049.55.159.1192.168.2.6
                                        Jan 15, 2025 02:59:40.961513996 CET44550211163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:40.961668968 CET50211445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:40.961703062 CET50211445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:40.961750031 CET50211445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:40.966480017 CET44550211163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:40.966496944 CET44550211163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:40.973335028 CET44550212185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:40.973438978 CET50212445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:40.973486900 CET50212445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:40.973547935 CET50212445192.168.2.6185.104.232.1
                                        Jan 15, 2025 02:59:40.978357077 CET44550212185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:40.978373051 CET44550212185.104.232.1192.168.2.6
                                        Jan 15, 2025 02:59:41.026953936 CET50352445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:41.031899929 CET44550352185.104.232.2192.168.2.6
                                        Jan 15, 2025 02:59:41.031996965 CET50352445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:41.032053947 CET50352445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:41.032377958 CET50353445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:41.037179947 CET44550352185.104.232.2192.168.2.6
                                        Jan 15, 2025 02:59:41.037260056 CET44550353185.104.232.2192.168.2.6
                                        Jan 15, 2025 02:59:41.037261963 CET50352445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:41.037367105 CET50353445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:41.037395000 CET50353445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:41.042188883 CET44550353185.104.232.2192.168.2.6
                                        Jan 15, 2025 02:59:41.466263056 CET50354445192.168.2.6207.2.237.20
                                        Jan 15, 2025 02:59:41.471215963 CET44550354207.2.237.20192.168.2.6
                                        Jan 15, 2025 02:59:41.471327066 CET50354445192.168.2.6207.2.237.20
                                        Jan 15, 2025 02:59:41.471391916 CET50354445192.168.2.6207.2.237.20
                                        Jan 15, 2025 02:59:41.471489906 CET50355445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:41.476270914 CET44550354207.2.237.20192.168.2.6
                                        Jan 15, 2025 02:59:41.476347923 CET44550354207.2.237.20192.168.2.6
                                        Jan 15, 2025 02:59:41.476365089 CET44550355207.2.237.1192.168.2.6
                                        Jan 15, 2025 02:59:41.476411104 CET50354445192.168.2.6207.2.237.20
                                        Jan 15, 2025 02:59:41.476454973 CET50355445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:41.476547956 CET50355445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:41.476798058 CET50356445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:41.481597900 CET44550355207.2.237.1192.168.2.6
                                        Jan 15, 2025 02:59:41.481693029 CET44550356207.2.237.1192.168.2.6
                                        Jan 15, 2025 02:59:41.481724977 CET50355445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:41.481759071 CET50356445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:41.481803894 CET50356445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:41.486576080 CET44550356207.2.237.1192.168.2.6
                                        Jan 15, 2025 02:59:42.014210939 CET50357445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:42.019140959 CET44550357148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:42.019216061 CET50357445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:42.019522905 CET50357445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:42.024410963 CET44550357148.225.116.1192.168.2.6
                                        Jan 15, 2025 02:59:42.292845011 CET50358445192.168.2.672.167.90.103
                                        Jan 15, 2025 02:59:42.297864914 CET4455035872.167.90.103192.168.2.6
                                        Jan 15, 2025 02:59:42.297950029 CET50358445192.168.2.672.167.90.103
                                        Jan 15, 2025 02:59:42.297986031 CET50358445192.168.2.672.167.90.103
                                        Jan 15, 2025 02:59:42.298332930 CET50359445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:42.303092957 CET4455035872.167.90.103192.168.2.6
                                        Jan 15, 2025 02:59:42.303143978 CET50358445192.168.2.672.167.90.103
                                        Jan 15, 2025 02:59:42.303244114 CET4455035972.167.90.1192.168.2.6
                                        Jan 15, 2025 02:59:42.303318024 CET50359445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:42.303333998 CET50359445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:42.303719044 CET50360445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:42.308295012 CET4455035972.167.90.1192.168.2.6
                                        Jan 15, 2025 02:59:42.308360100 CET50359445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:42.308509111 CET4455036072.167.90.1192.168.2.6
                                        Jan 15, 2025 02:59:42.308588982 CET50360445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:42.308666945 CET50360445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:42.313419104 CET4455036072.167.90.1192.168.2.6
                                        Jan 15, 2025 02:59:42.973453999 CET4455022746.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:42.973619938 CET50227445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:42.973752022 CET50227445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:42.973829985 CET50227445192.168.2.646.91.122.1
                                        Jan 15, 2025 02:59:42.978524923 CET4455022746.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:42.978595972 CET4455022746.91.122.1192.168.2.6
                                        Jan 15, 2025 02:59:42.989053965 CET44550226220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:42.989140987 CET50226445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:42.989183903 CET50226445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:42.989221096 CET50226445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:42.993943930 CET44550226220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:42.993969917 CET44550226220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:43.027003050 CET50361445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:43.032001019 CET4455036146.91.122.2192.168.2.6
                                        Jan 15, 2025 02:59:43.032098055 CET50361445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:43.032138109 CET50361445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:43.032546997 CET50362445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:43.037137032 CET4455036146.91.122.2192.168.2.6
                                        Jan 15, 2025 02:59:43.037220955 CET50361445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:43.037486076 CET4455036246.91.122.2192.168.2.6
                                        Jan 15, 2025 02:59:43.037558079 CET50362445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:43.037597895 CET50362445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:43.042361975 CET4455036246.91.122.2192.168.2.6
                                        Jan 15, 2025 02:59:43.058190107 CET50363445192.168.2.6115.165.57.231
                                        Jan 15, 2025 02:59:43.063375950 CET44550363115.165.57.231192.168.2.6
                                        Jan 15, 2025 02:59:43.063462019 CET50363445192.168.2.6115.165.57.231
                                        Jan 15, 2025 02:59:43.063477993 CET50363445192.168.2.6115.165.57.231
                                        Jan 15, 2025 02:59:43.063604116 CET50364445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:43.068471909 CET44550363115.165.57.231192.168.2.6
                                        Jan 15, 2025 02:59:43.068486929 CET44550364115.165.57.1192.168.2.6
                                        Jan 15, 2025 02:59:43.068583965 CET50364445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:43.068634987 CET50363445192.168.2.6115.165.57.231
                                        Jan 15, 2025 02:59:43.068703890 CET50364445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:43.069026947 CET50365445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:43.073529959 CET44550364115.165.57.1192.168.2.6
                                        Jan 15, 2025 02:59:43.073698997 CET50364445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:43.073959112 CET44550365115.165.57.1192.168.2.6
                                        Jan 15, 2025 02:59:43.074019909 CET50365445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:43.074059010 CET50365445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:43.078933954 CET44550365115.165.57.1192.168.2.6
                                        Jan 15, 2025 02:59:43.968527079 CET50367445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:43.973534107 CET44550367163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:43.973622084 CET50367445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:43.973691940 CET50367445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:43.978569984 CET44550367163.151.111.1192.168.2.6
                                        Jan 15, 2025 02:59:44.988857985 CET44550245101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:44.988936901 CET50245445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:44.988990068 CET50245445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:44.989047050 CET50245445192.168.2.6101.167.235.1
                                        Jan 15, 2025 02:59:44.993120909 CET44550244159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:44.993201971 CET50244445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:44.993315935 CET50244445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:44.993315935 CET50244445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:44.993808985 CET44550245101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:44.993823051 CET44550245101.167.235.1192.168.2.6
                                        Jan 15, 2025 02:59:44.998146057 CET44550244159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:44.998159885 CET44550244159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:45.042644024 CET50370445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:45.047481060 CET44550370101.167.235.2192.168.2.6
                                        Jan 15, 2025 02:59:45.047569036 CET50370445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:45.047667980 CET50370445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:45.048118114 CET50371445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:45.052560091 CET44550370101.167.235.2192.168.2.6
                                        Jan 15, 2025 02:59:45.052628040 CET50370445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:45.052922010 CET44550371101.167.235.2192.168.2.6
                                        Jan 15, 2025 02:59:45.052989006 CET50371445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:45.053035021 CET50371445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:45.057751894 CET44550371101.167.235.2192.168.2.6
                                        Jan 15, 2025 02:59:45.997000933 CET50375445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:46.002208948 CET44550375220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:46.002301931 CET50375445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:46.002351999 CET50375445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:46.007183075 CET44550375220.177.196.1192.168.2.6
                                        Jan 15, 2025 02:59:46.973450899 CET4455025763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:46.973547935 CET50257445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:46.973663092 CET50257445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:46.973663092 CET50257445192.168.2.663.231.161.1
                                        Jan 15, 2025 02:59:46.978471041 CET4455025763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:46.978482008 CET4455025763.231.161.1192.168.2.6
                                        Jan 15, 2025 02:59:47.022381067 CET44550260148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:47.022511959 CET50260445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:47.022608995 CET50260445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:47.022690058 CET50260445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:47.026921988 CET50382445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:47.027386904 CET44550260148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:47.027437925 CET44550260148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:47.031714916 CET4455038263.231.161.2192.168.2.6
                                        Jan 15, 2025 02:59:47.031780005 CET50382445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:47.031879902 CET50382445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:47.032150030 CET50383445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:47.036736012 CET4455038263.231.161.2192.168.2.6
                                        Jan 15, 2025 02:59:47.037056923 CET4455038363.231.161.2192.168.2.6
                                        Jan 15, 2025 02:59:47.037115097 CET50383445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:47.037153006 CET50383445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:47.037170887 CET50382445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:47.041955948 CET4455038363.231.161.2192.168.2.6
                                        Jan 15, 2025 02:59:47.995784044 CET50389445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:48.000926971 CET44550389159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:48.001048088 CET50389445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:48.001094103 CET50389445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:48.005862951 CET44550389159.140.202.1192.168.2.6
                                        Jan 15, 2025 02:59:48.317640066 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:48.317711115 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:48.317917109 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:48.318461895 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:48.318474054 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:48.895643950 CET44550277175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:48.895745993 CET50277445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:48.895778894 CET50277445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:48.895823956 CET50277445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:48.902173042 CET44550277175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:48.902187109 CET44550277175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:49.069097996 CET4455027940.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:49.069341898 CET50279445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:49.069341898 CET50279445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:49.069600105 CET50279445192.168.2.640.9.17.1
                                        Jan 15, 2025 02:59:49.074268103 CET4455027940.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:49.074342012 CET4455027940.9.17.1192.168.2.6
                                        Jan 15, 2025 02:59:49.120771885 CET50404445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:49.125782013 CET4455040440.9.17.2192.168.2.6
                                        Jan 15, 2025 02:59:49.125863075 CET50404445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:49.125912905 CET50404445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:49.126271009 CET50405445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:49.130784035 CET4455040440.9.17.2192.168.2.6
                                        Jan 15, 2025 02:59:49.130862951 CET50404445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:49.131016970 CET4455040540.9.17.2192.168.2.6
                                        Jan 15, 2025 02:59:49.131076097 CET50405445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:49.131114006 CET50405445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:49.135837078 CET4455040540.9.17.2192.168.2.6
                                        Jan 15, 2025 02:59:49.138397932 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.138508081 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.140450001 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.140463114 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.141225100 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.144345999 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.144397974 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.144407034 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.144515991 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.191332102 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.324827909 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.324920893 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.325372934 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.325406075 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:49.325418949 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.325418949 CET50394443192.168.2.640.113.110.67
                                        Jan 15, 2025 02:59:49.325428009 CET4435039440.113.110.67192.168.2.6
                                        Jan 15, 2025 02:59:50.026818037 CET50415445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:50.032834053 CET44550415148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:50.032927036 CET50415445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:50.032954931 CET50415445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:50.038794994 CET44550415148.177.241.1192.168.2.6
                                        Jan 15, 2025 02:59:50.660984993 CET44550292159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:50.661216021 CET50292445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:50.661216021 CET50292445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:50.661258936 CET50292445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:50.666258097 CET44550292159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:50.666269064 CET44550292159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:51.004616022 CET44550293155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:51.004678965 CET50293445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:51.004719973 CET50293445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:51.004740000 CET50293445192.168.2.6155.184.140.1
                                        Jan 15, 2025 02:59:51.009515047 CET44550293155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:51.009526014 CET44550293155.184.140.1192.168.2.6
                                        Jan 15, 2025 02:59:51.058399916 CET50433445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:51.063311100 CET44550433155.184.140.2192.168.2.6
                                        Jan 15, 2025 02:59:51.063478947 CET50433445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:51.063555956 CET50433445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:51.064162970 CET50434445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:51.068424940 CET44550433155.184.140.2192.168.2.6
                                        Jan 15, 2025 02:59:51.068520069 CET50433445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:51.068938971 CET44550434155.184.140.2192.168.2.6
                                        Jan 15, 2025 02:59:51.068996906 CET50434445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:51.069030046 CET50434445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:51.073759079 CET44550434155.184.140.2192.168.2.6
                                        Jan 15, 2025 02:59:51.902019978 CET50451445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:51.907342911 CET44550451175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:51.907478094 CET50451445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:51.907804966 CET50451445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:51.912739038 CET44550451175.101.165.1192.168.2.6
                                        Jan 15, 2025 02:59:52.286830902 CET4455030655.211.247.1192.168.2.6
                                        Jan 15, 2025 02:59:52.286952972 CET50306445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:52.287072897 CET50306445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:52.287112951 CET50306445192.168.2.655.211.247.1
                                        Jan 15, 2025 02:59:52.291800022 CET4455030655.211.247.1192.168.2.6
                                        Jan 15, 2025 02:59:52.291939020 CET4455030655.211.247.1192.168.2.6
                                        Jan 15, 2025 02:59:53.317320108 CET4455031372.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:53.317630053 CET50313445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:53.317630053 CET50313445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:53.317630053 CET50313445192.168.2.672.138.233.1
                                        Jan 15, 2025 02:59:53.322458982 CET4455031372.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:53.322473049 CET4455031372.138.233.1192.168.2.6
                                        Jan 15, 2025 02:59:53.370631933 CET50495445192.168.2.672.138.233.2
                                        Jan 15, 2025 02:59:53.375477076 CET4455049572.138.233.2192.168.2.6
                                        Jan 15, 2025 02:59:53.375566959 CET50495445192.168.2.672.138.233.2
                                        Jan 15, 2025 02:59:53.375638962 CET50495445192.168.2.672.138.233.2
                                        Jan 15, 2025 02:59:53.375834942 CET50497445192.168.2.672.138.233.2
                                        Jan 15, 2025 02:59:53.380695105 CET4455049572.138.233.2192.168.2.6
                                        Jan 15, 2025 02:59:53.380711079 CET4455049772.138.233.2192.168.2.6
                                        Jan 15, 2025 02:59:53.380779982 CET50495445192.168.2.672.138.233.2
                                        Jan 15, 2025 02:59:53.380832911 CET50497445192.168.2.672.138.233.2
                                        Jan 15, 2025 02:59:53.380873919 CET50497445192.168.2.672.138.233.2
                                        Jan 15, 2025 02:59:53.385694027 CET4455049772.138.233.2192.168.2.6
                                        Jan 15, 2025 02:59:53.667391062 CET50511445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:53.672282934 CET44550511159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:53.672370911 CET50511445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:53.672390938 CET50511445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:53.677256107 CET44550511159.199.82.1192.168.2.6
                                        Jan 15, 2025 02:59:53.822762012 CET4455032014.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:53.822843075 CET50320445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:53.822882891 CET50320445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:53.822958946 CET50320445192.168.2.614.41.247.1
                                        Jan 15, 2025 02:59:53.827691078 CET4455032014.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:53.827737093 CET4455032014.41.247.1192.168.2.6
                                        Jan 15, 2025 02:59:55.244856119 CET44550324114.251.20.1192.168.2.6
                                        Jan 15, 2025 02:59:55.244921923 CET50324445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:55.287705898 CET4455032518.166.199.1192.168.2.6
                                        Jan 15, 2025 02:59:55.287760973 CET50325445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:56.128369093 CET50334445192.168.2.635.203.187.2
                                        Jan 15, 2025 02:59:56.128379107 CET50415445192.168.2.6148.177.241.1
                                        Jan 15, 2025 02:59:56.128457069 CET50360445192.168.2.672.167.90.1
                                        Jan 15, 2025 02:59:56.128475904 CET50383445192.168.2.663.231.161.2
                                        Jan 15, 2025 02:59:56.128526926 CET50451445192.168.2.6175.101.165.1
                                        Jan 15, 2025 02:59:56.128566027 CET50343445192.168.2.6161.113.71.2
                                        Jan 15, 2025 02:59:56.128597975 CET50362445192.168.2.646.91.122.2
                                        Jan 15, 2025 02:59:56.128654957 CET50405445192.168.2.640.9.17.2
                                        Jan 15, 2025 02:59:56.128653049 CET50325445192.168.2.618.166.199.1
                                        Jan 15, 2025 02:59:56.128679037 CET50371445192.168.2.6101.167.235.2
                                        Jan 15, 2025 02:59:56.128725052 CET50375445192.168.2.6220.177.196.1
                                        Jan 15, 2025 02:59:56.128856897 CET50329445192.168.2.623.170.165.1
                                        Jan 15, 2025 02:59:56.128894091 CET50332445192.168.2.684.223.7.1
                                        Jan 15, 2025 02:59:56.128912926 CET50328445192.168.2.6181.130.123.1
                                        Jan 15, 2025 02:59:56.128912926 CET50337445192.168.2.665.242.217.1
                                        Jan 15, 2025 02:59:56.128930092 CET50324445192.168.2.6114.251.20.1
                                        Jan 15, 2025 02:59:56.128932953 CET50338445192.168.2.631.108.191.1
                                        Jan 15, 2025 02:59:56.128972054 CET50341445192.168.2.623.53.146.1
                                        Jan 15, 2025 02:59:56.128998995 CET50346445192.168.2.6171.163.176.1
                                        Jan 15, 2025 02:59:56.129062891 CET50350445192.168.2.649.55.159.1
                                        Jan 15, 2025 02:59:56.129107952 CET50353445192.168.2.6185.104.232.2
                                        Jan 15, 2025 02:59:56.129139900 CET50356445192.168.2.6207.2.237.1
                                        Jan 15, 2025 02:59:56.129163027 CET50347445192.168.2.6100.236.46.1
                                        Jan 15, 2025 02:59:56.129164934 CET50357445192.168.2.6148.225.116.1
                                        Jan 15, 2025 02:59:56.129190922 CET50365445192.168.2.6115.165.57.1
                                        Jan 15, 2025 02:59:56.129215002 CET50367445192.168.2.6163.151.111.1
                                        Jan 15, 2025 02:59:56.129326105 CET50434445192.168.2.6155.184.140.2
                                        Jan 15, 2025 02:59:56.129412889 CET50389445192.168.2.6159.140.202.1
                                        Jan 15, 2025 02:59:56.129415989 CET50511445192.168.2.6159.199.82.1
                                        Jan 15, 2025 02:59:56.129502058 CET50497445192.168.2.672.138.233.2
                                        Jan 15, 2025 03:00:20.881232023 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:20.881258011 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:20.881321907 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:20.882158041 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:20.882169008 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.690294981 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.690385103 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:21.695239067 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:21.695250988 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.695506096 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.697094917 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:21.697151899 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:21.697158098 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.697360992 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:21.743333101 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.855133057 CET4970580192.168.2.62.23.77.188
                                        Jan 15, 2025 03:00:21.855436087 CET49703443192.168.2.620.190.159.75
                                        Jan 15, 2025 03:00:21.860076904 CET80497052.23.77.188192.168.2.6
                                        Jan 15, 2025 03:00:21.860133886 CET4970580192.168.2.62.23.77.188
                                        Jan 15, 2025 03:00:21.860511065 CET4434970320.190.159.75192.168.2.6
                                        Jan 15, 2025 03:00:21.860565901 CET49703443192.168.2.620.190.159.75
                                        Jan 15, 2025 03:00:21.868665934 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.868774891 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:21.868837118 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:21.869064093 CET50630443192.168.2.640.113.110.67
                                        Jan 15, 2025 03:00:21.869082928 CET4435063040.113.110.67192.168.2.6
                                        Jan 15, 2025 03:00:24.120584965 CET49707443192.168.2.620.190.159.75
                                        Jan 15, 2025 03:00:24.125663042 CET4434970720.190.159.75192.168.2.6
                                        Jan 15, 2025 03:00:24.125734091 CET49707443192.168.2.620.190.159.75
                                        TimestampSource PortDest PortSource IPDest IP
                                        Jan 15, 2025 02:58:48.174979925 CET5660653192.168.2.61.1.1.1
                                        Jan 15, 2025 02:58:48.480828047 CET53566061.1.1.1192.168.2.6
                                        Jan 15, 2025 02:58:49.228581905 CET5719353192.168.2.61.1.1.1
                                        Jan 15, 2025 02:58:49.411623955 CET53571931.1.1.1192.168.2.6
                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                        Jan 15, 2025 02:58:48.174979925 CET192.168.2.61.1.1.10xa498Standard query (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                        Jan 15, 2025 02:58:49.228581905 CET192.168.2.61.1.1.10x3d9bStandard query (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                        Jan 15, 2025 02:58:48.480828047 CET1.1.1.1192.168.2.60xa498No error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com103.224.212.215A (IP address)IN (0x0001)false
                                        Jan 15, 2025 02:58:49.411623955 CET1.1.1.1192.168.2.60x3d9bNo error (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com77026.bodis.comCNAME (Canonical name)IN (0x0001)false
                                        Jan 15, 2025 02:58:49.411623955 CET1.1.1.1192.168.2.60x3d9bNo error (0)77026.bodis.com199.59.243.228A (IP address)IN (0x0001)false
                                        • www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        • ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        0192.168.2.649710103.224.212.215806656C:\Windows\mssecsvr.exe
                                        TimestampBytes transferredDirectionData
                                        Jan 15, 2025 02:58:48.492455006 CET100OUTGET / HTTP/1.1
                                        Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        Cache-Control: no-cache
                                        Jan 15, 2025 02:58:49.093451977 CET365INHTTP/1.1 302 Found
                                        date: Wed, 15 Jan 2025 01:58:49 GMT
                                        server: Apache
                                        set-cookie: __tad=1736906329.4755573; expires=Sat, 13-Jan-2035 01:58:49 GMT; Max-Age=315360000
                                        location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-49b3-8be1-4b52c7dcf2a9
                                        content-length: 2
                                        content-type: text/html; charset=UTF-8
                                        connection: close
                                        Data Raw: 0a 0a
                                        Data Ascii:


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        1192.168.2.649712199.59.243.228806656C:\Windows\mssecsvr.exe
                                        TimestampBytes transferredDirectionData
                                        Jan 15, 2025 02:58:49.429986954 CET169OUTGET /?subid1=20250115-1258-49b3-8be1-4b52c7dcf2a9 HTTP/1.1
                                        Cache-Control: no-cache
                                        Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        Connection: Keep-Alive
                                        Jan 15, 2025 02:58:49.895385027 CET1236INHTTP/1.1 200 OK
                                        date: Wed, 15 Jan 2025 01:58:49 GMT
                                        content-type: text/html; charset=utf-8
                                        content-length: 1262
                                        x-request-id: a1a59836-c29b-4307-ae59-a2380c47c41f
                                        cache-control: no-store, max-age=0
                                        accept-ch: sec-ch-prefers-color-scheme
                                        critical-ch: sec-ch-prefers-color-scheme
                                        vary: sec-ch-prefers-color-scheme
                                        x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_lSqKrO7JRS8rpdAoqZdeFSX3m77Kc56FqN36DP2zY6K2p3B/S1tHVCpeSg0EIroHWk05nWu2WS8SLJDVe3uMXA==
                                        set-cookie: parking_session=a1a59836-c29b-4307-ae59-a2380c47c41f; expires=Wed, 15 Jan 2025 02:13:49 GMT; path=/
                                        Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 6c 53 71 4b 72 4f 37 4a 52 53 38 72 70 64 41 6f 71 5a 64 65 46 53 58 33 6d 37 37 4b 63 35 36 46 71 4e 33 36 44 50 32 7a 59 36 4b 32 70 33 42 2f 53 31 74 48 56 43 70 65 53 67 30 45 49 72 6f 48 57 6b 30 35 6e 57 75 32 57 53 38 53 4c 4a 44 56 65 33 75 4d 58 41 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                        Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_lSqKrO7JRS8rpdAoqZdeFSX3m77Kc56FqN36DP2zY6K2p3B/S1tHVCpeSg0EIroHWk05nWu2WS8SLJDVe3uMXA==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                        Jan 15, 2025 02:58:49.895508051 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                        Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiYTFhNTk4MzYtYzI5Yi00MzA3LWFlNTktYTIzODBjNDdjNDFmIiwicGFnZV90aW1lIjoxNzM2OTA2MzI5LCJwYWdlX3VybCI6I


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        2192.168.2.649713103.224.212.215805396C:\Windows\mssecsvr.exe
                                        TimestampBytes transferredDirectionData
                                        Jan 15, 2025 02:58:50.030791044 CET100OUTGET / HTTP/1.1
                                        Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        Cache-Control: no-cache
                                        Jan 15, 2025 02:58:50.638276100 CET365INHTTP/1.1 302 Found
                                        date: Wed, 15 Jan 2025 01:58:50 GMT
                                        server: Apache
                                        set-cookie: __tad=1736906330.8135627; expires=Sat, 13-Jan-2035 01:58:50 GMT; Max-Age=315360000
                                        location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50c9-a80a-e88809fc110a
                                        content-length: 2
                                        content-type: text/html; charset=UTF-8
                                        connection: close
                                        Data Raw: 0a 0a
                                        Data Ascii:


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        3192.168.2.649714103.224.212.215806752C:\Windows\mssecsvr.exe
                                        TimestampBytes transferredDirectionData
                                        Jan 15, 2025 02:58:50.443291903 CET134OUTGET / HTTP/1.1
                                        Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        Cache-Control: no-cache
                                        Cookie: __tad=1736906329.4755573
                                        Jan 15, 2025 02:58:51.042836905 CET269INHTTP/1.1 302 Found
                                        date: Wed, 15 Jan 2025 01:58:50 GMT
                                        server: Apache
                                        location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250115-1258-50a1-9cf3-708b13423bb5
                                        content-length: 2
                                        content-type: text/html; charset=UTF-8
                                        connection: close
                                        Data Raw: 0a 0a
                                        Data Ascii:


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        4192.168.2.649720199.59.243.228805396C:\Windows\mssecsvr.exe
                                        TimestampBytes transferredDirectionData
                                        Jan 15, 2025 02:58:50.647815943 CET169OUTGET /?subid1=20250115-1258-50c9-a80a-e88809fc110a HTTP/1.1
                                        Cache-Control: no-cache
                                        Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        Connection: Keep-Alive
                                        Jan 15, 2025 02:58:51.136511087 CET1236INHTTP/1.1 200 OK
                                        date: Wed, 15 Jan 2025 01:58:50 GMT
                                        content-type: text/html; charset=utf-8
                                        content-length: 1262
                                        x-request-id: b18ba605-2ff0-49d5-9465-ecf7ed54bef4
                                        cache-control: no-store, max-age=0
                                        accept-ch: sec-ch-prefers-color-scheme
                                        critical-ch: sec-ch-prefers-color-scheme
                                        vary: sec-ch-prefers-color-scheme
                                        x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_hmpkYa8f/shn/0Qs+xlKDE3o8PzHE1LptxT6oRrXBTZJ82WdAa/LoceoKbfebHz5WfrZwtQZi5QG+TQ0ksHD4A==
                                        set-cookie: parking_session=b18ba605-2ff0-49d5-9465-ecf7ed54bef4; expires=Wed, 15 Jan 2025 02:13:51 GMT; path=/
                                        Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 68 6d 70 6b 59 61 38 66 2f 73 68 6e 2f 30 51 73 2b 78 6c 4b 44 45 33 6f 38 50 7a 48 45 31 4c 70 74 78 54 36 6f 52 72 58 42 54 5a 4a 38 32 57 64 41 61 2f 4c 6f 63 65 6f 4b 62 66 65 62 48 7a 35 57 66 72 5a 77 74 51 5a 69 35 51 47 2b 54 51 30 6b 73 48 44 34 41 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                        Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_hmpkYa8f/shn/0Qs+xlKDE3o8PzHE1LptxT6oRrXBTZJ82WdAa/LoceoKbfebHz5WfrZwtQZi5QG+TQ0ksHD4A==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                        Jan 15, 2025 02:58:51.136528969 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                        Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiYjE4YmE2MDUtMmZmMC00OWQ1LTk0NjUtZWNmN2VkNTRiZWY0IiwicGFnZV90aW1lIjoxNzM2OTA2MzMxLCJwYWdlX3VybCI6I


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        5192.168.2.649721199.59.243.228806752C:\Windows\mssecsvr.exe
                                        TimestampBytes transferredDirectionData
                                        Jan 15, 2025 02:58:51.052824020 CET231OUTGET /?subid1=20250115-1258-50a1-9cf3-708b13423bb5 HTTP/1.1
                                        Cache-Control: no-cache
                                        Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                        Connection: Keep-Alive
                                        Cookie: parking_session=a1a59836-c29b-4307-ae59-a2380c47c41f
                                        Jan 15, 2025 02:58:51.518809080 CET1236INHTTP/1.1 200 OK
                                        date: Wed, 15 Jan 2025 01:58:51 GMT
                                        content-type: text/html; charset=utf-8
                                        content-length: 1262
                                        x-request-id: f9321d36-9857-44c9-b5e8-ed5c41173b96
                                        cache-control: no-store, max-age=0
                                        accept-ch: sec-ch-prefers-color-scheme
                                        critical-ch: sec-ch-prefers-color-scheme
                                        vary: sec-ch-prefers-color-scheme
                                        x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_IzXOzdmbIhNshfk3snOdy4NGDq8qxPryCsWM7wUhl/b++WP4Hb27fW6nnWnCzjXmemT0eoNf5z3wYJEbIVrJug==
                                        set-cookie: parking_session=a1a59836-c29b-4307-ae59-a2380c47c41f; expires=Wed, 15 Jan 2025 02:13:51 GMT
                                        Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 49 7a 58 4f 7a 64 6d 62 49 68 4e 73 68 66 6b 33 73 6e 4f 64 79 34 4e 47 44 71 38 71 78 50 72 79 43 73 57 4d 37 77 55 68 6c 2f 62 2b 2b 57 50 34 48 62 32 37 66 57 36 6e 6e 57 6e 43 7a 6a 58 6d 65 6d 54 30 65 6f 4e 66 35 7a 33 77 59 4a 45 62 49 56 72 4a 75 67 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                        Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_IzXOzdmbIhNshfk3snOdy4NGDq8qxPryCsWM7wUhl/b++WP4Hb27fW6nnWnCzjXmemT0eoNf5z3wYJEbIVrJug==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="preconnect
                                        Jan 15, 2025 02:58:51.518829107 CET688INData Raw: 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65 74 22 20 73 74 79 6c 65
                                        Data Ascii: " href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiYTFhNTk4MzYtYzI5Yi00MzA3LWFlNTktYTIzODBjNDdjNDFmIiwicGFnZV90aW1lIjoxNzM2OTA2MzMxLCJwYWdlX3VybCI6Imh0dHA6L


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        0192.168.2.64970940.113.110.67443
                                        TimestampBytes transferredDirectionData
                                        2025-01-15 01:58:46 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 69 4e 48 41 36 72 71 45 42 6b 6d 52 71 54 71 76 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 34 31 39 37 61 35 32 36 37 36 63 35 65 63 35 39 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 305MS-CV: iNHA6rqEBkmRqTqv.1Context: 4197a52676c5ec59
                                        2025-01-15 01:58:46 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                        2025-01-15 01:58:46 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 69 4e 48 41 36 72 71 45 42 6b 6d 52 71 54 71 76 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 34 31 39 37 61 35 32 36 37 36 63 35 65 63 35 39 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 48 6f 32 6b 35 34 70 50 46 49 41 55 4f 77 76 5a 70 49 39 75 59 59 6b 71 35 5a 54 7a 44 74 4f 48 34 32 48 69 4f 58 4e 78 6d 6c 52 61 69 72 68 45 49 79 6a 74 74 4b 68 39 2f 63 39 58 61 48 36 78 62 2f 6f 6c 63 64 47 48 56 4d 6e 70 51 4e 59 6f 4b 66 72 33 38 78 7a 31 30 74 62 78 73 42 63 50 67 4d 75 56 34 30 31 53 78 49 55 70
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: iNHA6rqEBkmRqTqv.2Context: 4197a52676c5ec59<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATHo2k54pPFIAUOwvZpI9uYYkq5ZTzDtOH42HiOXNxmlRairhEIyjttKh9/c9XaH6xb/olcdGHVMnpQNYoKfr38xz10tbxsBcPgMuV401SxIUp
                                        2025-01-15 01:58:46 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 69 4e 48 41 36 72 71 45 42 6b 6d 52 71 54 71 76 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 34 31 39 37 61 35 32 36 37 36 63 35 65 63 35 39 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 0 197MS-CV: iNHA6rqEBkmRqTqv.3Context: 4197a52676c5ec59<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2025-01-15 01:58:46 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2025-01-15 01:58:46 UTC58INData Raw: 4d 53 2d 43 56 3a 20 78 48 67 63 64 75 54 73 41 6b 61 73 37 50 75 34 68 6f 50 4f 45 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: xHgcduTsAkas7Pu4hoPOEg.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        1192.168.2.64977240.113.110.67443
                                        TimestampBytes transferredDirectionData
                                        2025-01-15 01:58:54 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 63 2f 31 62 6c 34 7a 6b 7a 30 2b 79 61 36 67 4c 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 63 63 34 34 30 30 35 38 65 35 66 62 34 64 63 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 305MS-CV: c/1bl4zkz0+ya6gL.1Context: bcc440058e5fb4dc
                                        2025-01-15 01:58:54 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                        2025-01-15 01:58:54 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 63 2f 31 62 6c 34 7a 6b 7a 30 2b 79 61 36 67 4c 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 63 63 34 34 30 30 35 38 65 35 66 62 34 64 63 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 48 6f 32 6b 35 34 70 50 46 49 41 55 4f 77 76 5a 70 49 39 75 59 59 6b 71 35 5a 54 7a 44 74 4f 48 34 32 48 69 4f 58 4e 78 6d 6c 52 61 69 72 68 45 49 79 6a 74 74 4b 68 39 2f 63 39 58 61 48 36 78 62 2f 6f 6c 63 64 47 48 56 4d 6e 70 51 4e 59 6f 4b 66 72 33 38 78 7a 31 30 74 62 78 73 42 63 50 67 4d 75 56 34 30 31 53 78 49 55 70
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: c/1bl4zkz0+ya6gL.2Context: bcc440058e5fb4dc<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATHo2k54pPFIAUOwvZpI9uYYkq5ZTzDtOH42HiOXNxmlRairhEIyjttKh9/c9XaH6xb/olcdGHVMnpQNYoKfr38xz10tbxsBcPgMuV401SxIUp
                                        2025-01-15 01:58:54 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 63 2f 31 62 6c 34 7a 6b 7a 30 2b 79 61 36 67 4c 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 63 63 34 34 30 30 35 38 65 35 66 62 34 64 63 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 0 197MS-CV: c/1bl4zkz0+ya6gL.3Context: bcc440058e5fb4dc<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2025-01-15 01:58:54 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2025-01-15 01:58:54 UTC58INData Raw: 4d 53 2d 43 56 3a 20 31 4a 48 34 58 31 41 47 59 45 6d 54 5a 73 44 6e 50 6d 35 2b 33 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: 1JH4X1AGYEmTZsDnPm5+3w.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        2192.168.2.64999240.113.110.67443
                                        TimestampBytes transferredDirectionData
                                        2025-01-15 01:59:06 UTC70OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 34 0d 0a 4d 53 2d 43 56 3a 20 45 72 6e 41 4e 72 50 36 79 55 4b 76 64 32 6e 48 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 64 33 30 38 37 36 61 65 35 35 33 33 33 32 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 304MS-CV: ErnANrP6yUKvd2nH.1Context: 7d30876ae553332
                                        2025-01-15 01:59:06 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                        2025-01-15 01:59:06 UTC1083OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 30 0d 0a 4d 53 2d 43 56 3a 20 45 72 6e 41 4e 72 50 36 79 55 4b 76 64 32 6e 48 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 64 33 30 38 37 36 61 65 35 35 33 33 33 32 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 48 6f 32 6b 35 34 70 50 46 49 41 55 4f 77 76 5a 70 49 39 75 59 59 6b 71 35 5a 54 7a 44 74 4f 48 34 32 48 69 4f 58 4e 78 6d 6c 52 61 69 72 68 45 49 79 6a 74 74 4b 68 39 2f 63 39 58 61 48 36 78 62 2f 6f 6c 63 64 47 48 56 4d 6e 70 51 4e 59 6f 4b 66 72 33 38 78 7a 31 30 74 62 78 73 42 63 50 67 4d 75 56 34 30 31 53 78 49 55 70 51
                                        Data Ascii: ATH 2 CON\DEVICE 1060MS-CV: ErnANrP6yUKvd2nH.2Context: 7d30876ae553332<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATHo2k54pPFIAUOwvZpI9uYYkq5ZTzDtOH42HiOXNxmlRairhEIyjttKh9/c9XaH6xb/olcdGHVMnpQNYoKfr38xz10tbxsBcPgMuV401SxIUpQ
                                        2025-01-15 01:59:06 UTC217OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 36 0d 0a 4d 53 2d 43 56 3a 20 45 72 6e 41 4e 72 50 36 79 55 4b 76 64 32 6e 48 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 64 33 30 38 37 36 61 65 35 35 33 33 33 32 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 0 196MS-CV: ErnANrP6yUKvd2nH.3Context: 7d30876ae553332<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2025-01-15 01:59:06 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2025-01-15 01:59:06 UTC58INData Raw: 4d 53 2d 43 56 3a 20 63 64 65 79 66 71 2b 58 72 55 71 72 77 64 49 56 4f 61 75 73 74 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: cdeyfq+XrUqrwdIVOaustw.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        3192.168.2.65025140.113.110.67443
                                        TimestampBytes transferredDirectionData
                                        2025-01-15 01:59:25 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 54 59 4b 42 35 75 61 2f 54 6b 47 4e 59 49 41 33 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 39 66 65 32 31 62 65 32 66 35 62 32 31 35 62 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 305MS-CV: TYKB5ua/TkGNYIA3.1Context: b9fe21be2f5b215b
                                        2025-01-15 01:59:25 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                        2025-01-15 01:59:25 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 54 59 4b 42 35 75 61 2f 54 6b 47 4e 59 49 41 33 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 39 66 65 32 31 62 65 32 66 35 62 32 31 35 62 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 48 6f 32 6b 35 34 70 50 46 49 41 55 4f 77 76 5a 70 49 39 75 59 59 6b 71 35 5a 54 7a 44 74 4f 48 34 32 48 69 4f 58 4e 78 6d 6c 52 61 69 72 68 45 49 79 6a 74 74 4b 68 39 2f 63 39 58 61 48 36 78 62 2f 6f 6c 63 64 47 48 56 4d 6e 70 51 4e 59 6f 4b 66 72 33 38 78 7a 31 30 74 62 78 73 42 63 50 67 4d 75 56 34 30 31 53 78 49 55 70
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: TYKB5ua/TkGNYIA3.2Context: b9fe21be2f5b215b<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATHo2k54pPFIAUOwvZpI9uYYkq5ZTzDtOH42HiOXNxmlRairhEIyjttKh9/c9XaH6xb/olcdGHVMnpQNYoKfr38xz10tbxsBcPgMuV401SxIUp
                                        2025-01-15 01:59:25 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 54 59 4b 42 35 75 61 2f 54 6b 47 4e 59 49 41 33 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 62 39 66 65 32 31 62 65 32 66 35 62 32 31 35 62 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 0 197MS-CV: TYKB5ua/TkGNYIA3.3Context: b9fe21be2f5b215b<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2025-01-15 01:59:25 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2025-01-15 01:59:25 UTC58INData Raw: 4d 53 2d 43 56 3a 20 55 7a 6a 68 69 45 59 4e 75 45 79 70 6d 42 6c 6d 58 5a 72 30 57 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: UzjhiEYNuEypmBlmXZr0Wg.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        4192.168.2.65039440.113.110.67443
                                        TimestampBytes transferredDirectionData
                                        2025-01-15 01:59:49 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 67 69 54 78 4a 6e 6b 4b 64 45 2b 35 4e 39 45 78 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 33 30 63 30 61 39 61 65 63 66 39 33 61 35 37 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 305MS-CV: giTxJnkKdE+5N9Ex.1Context: 730c0a9aecf93a57
                                        2025-01-15 01:59:49 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                        2025-01-15 01:59:49 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 67 69 54 78 4a 6e 6b 4b 64 45 2b 35 4e 39 45 78 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 33 30 63 30 61 39 61 65 63 66 39 33 61 35 37 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 48 6f 32 6b 35 34 70 50 46 49 41 55 4f 77 76 5a 70 49 39 75 59 59 6b 71 35 5a 54 7a 44 74 4f 48 34 32 48 69 4f 58 4e 78 6d 6c 52 61 69 72 68 45 49 79 6a 74 74 4b 68 39 2f 63 39 58 61 48 36 78 62 2f 6f 6c 63 64 47 48 56 4d 6e 70 51 4e 59 6f 4b 66 72 33 38 78 7a 31 30 74 62 78 73 42 63 50 67 4d 75 56 34 30 31 53 78 49 55 70
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: giTxJnkKdE+5N9Ex.2Context: 730c0a9aecf93a57<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATHo2k54pPFIAUOwvZpI9uYYkq5ZTzDtOH42HiOXNxmlRairhEIyjttKh9/c9XaH6xb/olcdGHVMnpQNYoKfr38xz10tbxsBcPgMuV401SxIUp
                                        2025-01-15 01:59:49 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 67 69 54 78 4a 6e 6b 4b 64 45 2b 35 4e 39 45 78 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 37 33 30 63 30 61 39 61 65 63 66 39 33 61 35 37 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 0 197MS-CV: giTxJnkKdE+5N9Ex.3Context: 730c0a9aecf93a57<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2025-01-15 01:59:49 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2025-01-15 01:59:49 UTC58INData Raw: 4d 53 2d 43 56 3a 20 54 65 30 78 65 33 4b 73 61 45 53 4a 57 2f 79 6d 78 6a 64 56 76 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: Te0xe3KsaESJW/ymxjdVvA.0Payload parsing failed.


                                        Session IDSource IPSource PortDestination IPDestination Port
                                        5192.168.2.65063040.113.110.67443
                                        TimestampBytes transferredDirectionData
                                        2025-01-15 02:00:21 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 55 45 50 43 4a 51 52 50 4d 45 69 66 6a 58 46 30 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 66 38 63 34 36 35 66 61 66 36 33 35 35 61 33 0d 0a 0d 0a
                                        Data Ascii: CNT 1 CON 305MS-CV: UEPCJQRPMEifjXF0.1Context: 5f8c465faf6355a3
                                        2025-01-15 02:00:21 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                        Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                        2025-01-15 02:00:21 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 55 45 50 43 4a 51 52 50 4d 45 69 66 6a 58 46 30 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 66 38 63 34 36 35 66 61 66 36 33 35 35 61 33 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 54 48 6f 32 6b 35 34 70 50 46 49 41 55 4f 77 76 5a 70 49 39 75 59 59 6b 71 35 5a 54 7a 44 74 4f 48 34 32 48 69 4f 58 4e 78 6d 6c 52 61 69 72 68 45 49 79 6a 74 74 4b 68 39 2f 63 39 58 61 48 36 78 62 2f 6f 6c 63 64 47 48 56 4d 6e 70 51 4e 59 6f 4b 66 72 33 38 78 7a 31 30 74 62 78 73 42 63 50 67 4d 75 56 34 30 31 53 78 49 55 70
                                        Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: UEPCJQRPMEifjXF0.2Context: 5f8c465faf6355a3<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAATHo2k54pPFIAUOwvZpI9uYYkq5ZTzDtOH42HiOXNxmlRairhEIyjttKh9/c9XaH6xb/olcdGHVMnpQNYoKfr38xz10tbxsBcPgMuV401SxIUp
                                        2025-01-15 02:00:21 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 55 45 50 43 4a 51 52 50 4d 45 69 66 6a 58 46 30 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 66 38 63 34 36 35 66 61 66 36 33 35 35 61 33 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                        Data Ascii: BND 3 CON\WNS 0 197MS-CV: UEPCJQRPMEifjXF0.3Context: 5f8c465faf6355a3<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                        2025-01-15 02:00:21 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                        Data Ascii: 202 1 CON 58
                                        2025-01-15 02:00:21 UTC58INData Raw: 4d 53 2d 43 56 3a 20 34 32 49 78 52 63 75 65 6b 45 6d 48 75 4a 42 58 63 57 65 38 76 51 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                        Data Ascii: MS-CV: 42IxRcuekEmHuJBXcWe8vQ.0Payload parsing failed.


                                        Click to jump to process

                                        Click to jump to process

                                        Click to dive into process behavior distribution

                                        Click to jump to process

                                        Target ID:0
                                        Start time:20:58:46
                                        Start date:14/01/2025
                                        Path:C:\Windows\System32\loaddll32.exe
                                        Wow64 process (32bit):true
                                        Commandline:loaddll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll"
                                        Imagebase:0x900000
                                        File size:126'464 bytes
                                        MD5 hash:51E6071F9CBA48E79F10C84515AAE618
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Target ID:1
                                        Start time:20:58:46
                                        Start date:14/01/2025
                                        Path:C:\Windows\System32\conhost.exe
                                        Wow64 process (32bit):false
                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                        Imagebase:0x7ff66e660000
                                        File size:862'208 bytes
                                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Target ID:2
                                        Start time:20:58:46
                                        Start date:14/01/2025
                                        Path:C:\Windows\SysWOW64\cmd.exe
                                        Wow64 process (32bit):true
                                        Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1
                                        Imagebase:0x1c0000
                                        File size:236'544 bytes
                                        MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Target ID:3
                                        Start time:20:58:46
                                        Start date:14/01/2025
                                        Path:C:\Windows\SysWOW64\rundll32.exe
                                        Wow64 process (32bit):true
                                        Commandline:rundll32.exe C:\Users\user\Desktop\NLWfV87ouS.dll,PlayGame
                                        Imagebase:0xa10000
                                        File size:61'440 bytes
                                        MD5 hash:889B99C52A60DD49227C5E485A016679
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Target ID:4
                                        Start time:20:58:46
                                        Start date:14/01/2025
                                        Path:C:\Windows\SysWOW64\rundll32.exe
                                        Wow64 process (32bit):true
                                        Commandline:rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",#1
                                        Imagebase:0xa10000
                                        File size:61'440 bytes
                                        MD5 hash:889B99C52A60DD49227C5E485A016679
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Target ID:6
                                        Start time:20:58:46
                                        Start date:14/01/2025
                                        Path:C:\Windows\mssecsvr.exe
                                        Wow64 process (32bit):true
                                        Commandline:C:\WINDOWS\mssecsvr.exe
                                        Imagebase:0x400000
                                        File size:2'281'472 bytes
                                        MD5 hash:6F25163220B24FB054B144BE9F82C096
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000006.00000000.2171769143.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000006.00000002.2209019561.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Windows\mssecsvr.exe, Author: Joe Security
                                        • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvr.exe, Author: Florian Roth (with the help of binar.ly)
                                        • Rule: WannaCry_Ransomware_Gen, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvr.exe, Author: Florian Roth (based on rule by US CERT)
                                        Antivirus matches:
                                        • Detection: 100%, Avira
                                        • Detection: 100%, Joe Sandbox ML
                                        • Detection: 100%, ReversingLabs
                                        Reputation:low
                                        Has exited:true

                                        Target ID:8
                                        Start time:20:58:49
                                        Start date:14/01/2025
                                        Path:C:\Windows\mssecsvr.exe
                                        Wow64 process (32bit):true
                                        Commandline:C:\WINDOWS\mssecsvr.exe -m security
                                        Imagebase:0x400000
                                        File size:2'281'472 bytes
                                        MD5 hash:6F25163220B24FB054B144BE9F82C096
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000000.2195861336.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2849584166.0000000001E5E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2849831934.0000000002381000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        Reputation:low
                                        Has exited:true

                                        Target ID:9
                                        Start time:20:58:49
                                        Start date:14/01/2025
                                        Path:C:\Windows\SysWOW64\rundll32.exe
                                        Wow64 process (32bit):true
                                        Commandline:rundll32.exe "C:\Users\user\Desktop\NLWfV87ouS.dll",PlayGame
                                        Imagebase:0xa10000
                                        File size:61'440 bytes
                                        MD5 hash:889B99C52A60DD49227C5E485A016679
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Target ID:10
                                        Start time:20:58:49
                                        Start date:14/01/2025
                                        Path:C:\Windows\mssecsvr.exe
                                        Wow64 process (32bit):true
                                        Commandline:C:\WINDOWS\mssecsvr.exe
                                        Imagebase:0x400000
                                        File size:2'281'472 bytes
                                        MD5 hash:6F25163220B24FB054B144BE9F82C096
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 0000000A.00000002.2213069023.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 0000000A.00000000.2199520983.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                        Reputation:low
                                        Has exited:true

                                        Reset < >

                                          Execution Graph

                                          Execution Coverage:71.7%
                                          Dynamic/Decrypted Code Coverage:0%
                                          Signature Coverage:63.2%
                                          Total number of Nodes:38
                                          Total number of Limit Nodes:9
                                          execution_graph 63 409a16 __set_app_type __p__fmode __p__commode 64 409a85 63->64 65 409a99 64->65 66 409a8d __setusermatherr 64->66 75 409b8c _controlfp 65->75 66->65 68 409a9e _initterm __getmainargs _initterm 69 409af2 GetStartupInfoA 68->69 71 409b26 GetModuleHandleA 69->71 76 408140 InternetOpenA InternetOpenUrlA 71->76 75->68 77 4081a7 InternetCloseHandle InternetCloseHandle 76->77 80 408090 GetModuleFileNameA __p___argc 77->80 79 4081b2 exit _XcptFilter 81 4080b0 80->81 82 4080b9 OpenSCManagerA 80->82 91 407f20 81->91 83 408101 StartServiceCtrlDispatcherA 82->83 84 4080cf OpenServiceA 82->84 83->79 86 4080fc CloseServiceHandle 84->86 87 4080ee 84->87 86->83 96 407fa0 ChangeServiceConfig2A 87->96 90 4080f6 CloseServiceHandle 90->86 108 407c40 sprintf OpenSCManagerA 91->108 93 407f25 97 407ce0 GetModuleHandleW 93->97 96->90 98 407d01 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 97->98 99 407f08 97->99 98->99 100 407d49 98->100 99->79 100->99 101 407d69 FindResourceA 100->101 101->99 102 407d84 LoadResource 101->102 102->99 103 407d94 LockResource 102->103 103->99 104 407da7 SizeofResource 103->104 104->99 105 407db9 sprintf sprintf MoveFileExA CreateFileA 104->105 105->99 106 407e54 WriteFile CloseHandle CreateProcessA 105->106 106->99 107 407ef2 CloseHandle CloseHandle 106->107 107->99 109 407c74 CreateServiceA 108->109 110 407cca 108->110 111 407cbb CloseServiceHandle 109->111 112 407cad StartServiceA CloseServiceHandle 109->112 110->93 111->93 112->111

                                          Callgraph

                                          Control-flow Graph

                                          APIs
                                          • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F7F0EF0,?,00000000), ref: 00407CEF
                                          • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                          • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                          • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                          • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                          • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                          • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                          • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                          • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                          • sprintf.MSVCRT ref: 00407E01
                                          • sprintf.MSVCRT ref: 00407E18
                                          • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                          • CreateFileA.KERNELBASE(?,40000000,00000000,00000000,00000002,00000004,00000000), ref: 00407E43
                                          • WriteFile.KERNELBASE(00000000,?,00000000,?,00000000), ref: 00407E61
                                          • CloseHandle.KERNELBASE(00000000), ref: 00407E68
                                          • CreateProcessA.KERNELBASE ref: 00407EE8
                                          • CloseHandle.KERNEL32(00000000), ref: 00407EF7
                                          • CloseHandle.KERNEL32(08000000), ref: 00407F02
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.2208982673.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000006.00000002.2208967105.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209003050.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209059971.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209149463.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AddressHandleProcResource$CloseFile$Createsprintf$FindLoadLockModuleMoveProcessSizeofWrite
                                          • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                          • API String ID: 4281112323-1507730452
                                          • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                          • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                          • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                          • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                          Control-flow Graph

                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.2208982673.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000006.00000002.2208967105.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209003050.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209059971.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209149463.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                          • String ID:
                                          • API String ID: 801014965-0
                                          • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                          • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                          • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                          • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59

                                          Control-flow Graph

                                          APIs
                                          • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                          • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                          • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                          • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                            • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                            • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                          Strings
                                          • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.2208982673.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000006.00000002.2208967105.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209003050.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209059971.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209149463.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                          • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                          • API String ID: 774561529-2614457033
                                          • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                          • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                          • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                          • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                          Control-flow Graph

                                          APIs
                                          • sprintf.MSVCRT ref: 00407C56
                                          • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                          • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F7F0EF0,00000000), ref: 00407C9B
                                          • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.2208982673.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000006.00000002.2208967105.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209003050.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209059971.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209149463.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                          • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                          • API String ID: 3340711343-2450984573
                                          • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                          • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                          • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                          • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                          Control-flow Graph

                                          APIs
                                          • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                          • __p___argc.MSVCRT ref: 004080A5
                                          • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                          • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F7F0EF0,00000000,?,004081B2), ref: 004080DC
                                          • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                          • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                          • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.2208982673.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000006.00000002.2208967105.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209003050.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209019561.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209059971.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000006.00000002.2209149463.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                          • String ID: mssecsvc2.1
                                          • API String ID: 4274534310-2839763450
                                          • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                          • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                          • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                          • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                          Execution Graph

                                          Execution Coverage:34.8%
                                          Dynamic/Decrypted Code Coverage:0%
                                          Signature Coverage:0%
                                          Total number of Nodes:36
                                          Total number of Limit Nodes:2

                                          Callgraph

                                          Control-flow Graph

                                          APIs
                                          • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                          • __p___argc.MSVCRT ref: 004080A5
                                          • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                          • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F7F0EF0,00000000,?,004081B2), ref: 004080DC
                                          • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                          • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                          • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2848770341.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2848755748.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848786545.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848851957.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848866187.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848962196.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                          • String ID: mssecsvc2.1
                                          • API String ID: 4274534310-2839763450
                                          • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                          • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                          • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                          • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                          Control-flow Graph

                                          APIs
                                          • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                          • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                          • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                          • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                            • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                            • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                          Strings
                                          • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2848770341.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2848755748.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848786545.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848851957.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848866187.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848962196.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                          • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                          • API String ID: 774561529-2614457033
                                          • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                          • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                          • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                          • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                          Control-flow Graph

                                          APIs
                                          • sprintf.MSVCRT ref: 00407C56
                                          • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                          • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F7F0EF0,00000000), ref: 00407C9B
                                          • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2848770341.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2848755748.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848786545.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848851957.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848866187.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848962196.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                          • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                          • API String ID: 3340711343-2450984573
                                          • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                          • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                          • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                          • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 15 407ce0-407cfb GetModuleHandleW 16 407d01-407d43 GetProcAddress * 4 15->16 17 407f08-407f14 15->17 16->17 18 407d49-407d4f 16->18 18->17 19 407d55-407d5b 18->19 19->17 20 407d61-407d63 19->20 20->17 21 407d69-407d7e FindResourceA 20->21 21->17 22 407d84-407d8e LoadResource 21->22 22->17 23 407d94-407da1 LockResource 22->23 23->17 24 407da7-407db3 SizeofResource 23->24 24->17 25 407db9-407e4e sprintf * 2 MoveFileExA 24->25 25->17 27 407e54-407ef0 25->27 27->17 31 407ef2-407f01 27->31 31->17
                                          APIs
                                          • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F7F0EF0,?,00000000), ref: 00407CEF
                                          • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                          • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                          • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                          • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                          • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                          • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                          • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                          • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                          • sprintf.MSVCRT ref: 00407E01
                                          • sprintf.MSVCRT ref: 00407E18
                                          • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2848770341.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2848755748.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848786545.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848851957.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848866187.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848962196.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AddressProcResource$sprintf$FileFindHandleLoadLockModuleMoveSizeof
                                          • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                          • API String ID: 4072214828-1507730452
                                          • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                          • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                          • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                          • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                          Control-flow Graph

                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2848770341.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2848755748.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848786545.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848801495.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848837892.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848851957.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848866187.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                          • Associated: 00000008.00000002.2848962196.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_mssecsvr.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                          • String ID:
                                          • API String ID: 801014965-0
                                          • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                          • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                          • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                          • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59