Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Material Requirments.exe

Overview

General Information

Sample name:Material Requirments.exe
(renamed file extension from pif to exe)
Original sample name:Material Requirments.pif
Analysis ID:1591545
MD5:3a9da3edc40736cc832eded3c389a661
SHA1:f32f61fb4458696dae4f15d82377163521e4f8b5
SHA256:f2418ca6e602c9470a8b6e32172432726e50b00d6e7a0ee5bd70d0172017d6c3
Infos:

Detection

Remcos, PureLog Stealer
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected Remcos RAT
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Remcos
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected PureLog Stealer
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Creates autostart registry keys with suspicious names
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Yara detected Keylogger Generic
Yara signature match

Classification

  • System is w10x64
  • Material Requirments.exe (PID: 7156 cmdline: "C:\Users\user\Desktop\Material Requirments.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
    • Material Requirments.exe (PID: 1372 cmdline: "C:\Users\user\Desktop\Material Requirments.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
      • remcos.exe (PID: 1248 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
        • remcos.exe (PID: 1276 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
  • remcos.exe (PID: 3116 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
    • remcos.exe (PID: 7120 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
  • remcos.exe (PID: 1680 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
    • remcos.exe (PID: 6620 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
  • remcos.exe (PID: 6752 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
    • remcos.exe (PID: 2436 cmdline: "C:\ProgramData\Remcos\remcos.exe" MD5: 3A9DA3EDC40736CC832EDED3C389A661)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Remcos, RemcosRATRemcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers.Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns.Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user.Remcos is developed by the cybersecurity company BreakingSecurity.
  • APT33
  • The Gorgon Group
  • UAC-0050
https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
{"Host:Port:Password": ["87.120.116.245:2400:1"], "Assigned name": "RemoteHost", "Connect interval": "1", "Install flag": "Enable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Enable", "Install path": "Application path", "Copy file": "remcos.exe", "Startup value": "Disable", "Hide file": "Disable", "Mutex": "Rmc-24L73B", "Keylog flag": "0", "Keylog path": "Application path", "Keylog file": "logs.dat", "Keylog crypt": "Disable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "1", "Take Screenshot option": "Disable", "Take screenshot title": "", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Screenshots", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "remcos"}
SourceRuleDescriptionAuthorStrings
00000007.00000002.2193815642.0000000001397000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_RemcosYara detected Remcos RATJoe Security
    00000003.00000002.2059843569.0000000000FD7000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_RemcosYara detected Remcos RATJoe Security
      0000000B.00000002.2278960559.0000000000E77000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_RemcosYara detected Remcos RATJoe Security
        00000000.00000002.2075574179.0000000007610000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_PureLogStealerYara detected PureLog StealerJoe Security
          00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
            Click to see the 30 entries

            System Summary

            barindex
            Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\ProgramData\Remcos\remcos.exe", EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\Material Requirments.exe, ProcessId: 1372, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Rmc-24L73B
            Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\ProgramData\Remcos\remcos.exe", EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\Material Requirments.exe, ProcessId: 1372, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\Rmc-24L73B

            Stealing of Sensitive Information

            barindex
            Source: Registry Key setAuthor: Joe Security: Data: Details: 66 57 27 95 79 E4 43 60 A3 C1 CC 09 A2 F2 B0 DC C9 0C 47 50 1A D8 96 5A E5 39 C8 E5 77 FA BB 03 2E 29 40 1B B4 6E C5 35 05 56 FF 36 06 0F 9B D4 CE 11 07 FB BA C6 2D C8 B6 8A 17 DB 53 B8 CE 8E EE 46 , EventID: 13, EventType: SetValue, Image: C:\ProgramData\Remcos\remcos.exe, ProcessId: 1276, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Rmc-24L73B\exepath
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-01-15T03:51:41.530192+010020365941Malware Command and Control Activity Detected192.168.2.54970887.120.116.2452400TCP
            2025-01-15T03:51:44.182556+010020365941Malware Command and Control Activity Detected192.168.2.54971187.120.116.2452400TCP
            2025-01-15T03:51:46.821597+010020365941Malware Command and Control Activity Detected192.168.2.54971287.120.116.2452400TCP
            2025-01-15T03:51:49.466137+010020365941Malware Command and Control Activity Detected192.168.2.54971387.120.116.2452400TCP
            2025-01-15T03:51:52.102768+010020365941Malware Command and Control Activity Detected192.168.2.54971487.120.116.2452400TCP
            2025-01-15T03:51:54.764998+010020365941Malware Command and Control Activity Detected192.168.2.54972087.120.116.2452400TCP
            2025-01-15T03:51:57.399678+010020365941Malware Command and Control Activity Detected192.168.2.54973287.120.116.2452400TCP
            2025-01-15T03:52:00.024952+010020365941Malware Command and Control Activity Detected192.168.2.54975387.120.116.2452400TCP
            2025-01-15T03:52:02.668250+010020365941Malware Command and Control Activity Detected192.168.2.54976987.120.116.2452400TCP
            2025-01-15T03:52:05.310210+010020365941Malware Command and Control Activity Detected192.168.2.54978587.120.116.2452400TCP
            2025-01-15T03:52:07.947280+010020365941Malware Command and Control Activity Detected192.168.2.54980487.120.116.2452400TCP
            2025-01-15T03:52:10.619393+010020365941Malware Command and Control Activity Detected192.168.2.54982287.120.116.2452400TCP
            2025-01-15T03:52:13.247360+010020365941Malware Command and Control Activity Detected192.168.2.54983787.120.116.2452400TCP
            2025-01-15T03:52:15.885829+010020365941Malware Command and Control Activity Detected192.168.2.54985687.120.116.2452400TCP
            2025-01-15T03:52:18.606441+010020365941Malware Command and Control Activity Detected192.168.2.54987387.120.116.2452400TCP
            2025-01-15T03:52:21.263352+010020365941Malware Command and Control Activity Detected192.168.2.54989287.120.116.2452400TCP
            2025-01-15T03:52:23.901902+010020365941Malware Command and Control Activity Detected192.168.2.54991087.120.116.2452400TCP
            2025-01-15T03:52:26.521560+010020365941Malware Command and Control Activity Detected192.168.2.54992687.120.116.2452400TCP
            2025-01-15T03:52:29.131855+010020365941Malware Command and Control Activity Detected192.168.2.54994387.120.116.2452400TCP
            2025-01-15T03:52:31.761709+010020365941Malware Command and Control Activity Detected192.168.2.54996187.120.116.2452400TCP
            2025-01-15T03:52:35.322512+010020365941Malware Command and Control Activity Detected192.168.2.54997887.120.116.2452400TCP
            2025-01-15T03:52:37.963143+010020365941Malware Command and Control Activity Detected192.168.2.54999687.120.116.2452400TCP
            2025-01-15T03:52:40.603701+010020365941Malware Command and Control Activity Detected192.168.2.55000387.120.116.2452400TCP
            2025-01-15T03:52:43.248030+010020365941Malware Command and Control Activity Detected192.168.2.55000487.120.116.2452400TCP
            2025-01-15T03:52:45.891446+010020365941Malware Command and Control Activity Detected192.168.2.55000587.120.116.2452400TCP
            2025-01-15T03:52:48.505802+010020365941Malware Command and Control Activity Detected192.168.2.55000687.120.116.2452400TCP
            2025-01-15T03:52:51.733895+010020365941Malware Command and Control Activity Detected192.168.2.55000787.120.116.2452400TCP
            2025-01-15T03:52:54.351096+010020365941Malware Command and Control Activity Detected192.168.2.55000987.120.116.2452400TCP
            2025-01-15T03:52:57.087579+010020365941Malware Command and Control Activity Detected192.168.2.55001087.120.116.2452400TCP
            2025-01-15T03:52:59.733578+010020365941Malware Command and Control Activity Detected192.168.2.55001187.120.116.2452400TCP
            2025-01-15T03:53:02.389514+010020365941Malware Command and Control Activity Detected192.168.2.55001287.120.116.2452400TCP
            2025-01-15T03:53:05.027616+010020365941Malware Command and Control Activity Detected192.168.2.55001387.120.116.2452400TCP
            2025-01-15T03:53:07.654506+010020365941Malware Command and Control Activity Detected192.168.2.55001487.120.116.2452400TCP
            2025-01-15T03:53:10.228093+010020365941Malware Command and Control Activity Detected192.168.2.55001587.120.116.2452400TCP
            2025-01-15T03:53:12.795521+010020365941Malware Command and Control Activity Detected192.168.2.55001687.120.116.2452400TCP
            2025-01-15T03:53:15.339669+010020365941Malware Command and Control Activity Detected192.168.2.55001787.120.116.2452400TCP
            2025-01-15T03:53:17.838848+010020365941Malware Command and Control Activity Detected192.168.2.55001887.120.116.2452400TCP
            2025-01-15T03:53:20.330001+010020365941Malware Command and Control Activity Detected192.168.2.55001987.120.116.2452400TCP
            2025-01-15T03:53:22.765924+010020365941Malware Command and Control Activity Detected192.168.2.55002087.120.116.2452400TCP
            2025-01-15T03:53:25.184710+010020365941Malware Command and Control Activity Detected192.168.2.55002187.120.116.2452400TCP
            2025-01-15T03:53:27.589482+010020365941Malware Command and Control Activity Detected192.168.2.55002287.120.116.2452400TCP
            2025-01-15T03:53:29.966355+010020365941Malware Command and Control Activity Detected192.168.2.55002387.120.116.2452400TCP
            2025-01-15T03:53:32.308965+010020365941Malware Command and Control Activity Detected192.168.2.55002487.120.116.2452400TCP
            2025-01-15T03:53:34.618635+010020365941Malware Command and Control Activity Detected192.168.2.55002587.120.116.2452400TCP
            2025-01-15T03:53:36.919199+010020365941Malware Command and Control Activity Detected192.168.2.55002687.120.116.2452400TCP
            2025-01-15T03:53:39.214435+010020365941Malware Command and Control Activity Detected192.168.2.55002787.120.116.2452400TCP
            2025-01-15T03:53:41.467620+010020365941Malware Command and Control Activity Detected192.168.2.55002887.120.116.2452400TCP
            2025-01-15T03:53:43.700638+010020365941Malware Command and Control Activity Detected192.168.2.55002987.120.116.2452400TCP
            2025-01-15T03:53:45.982919+010020365941Malware Command and Control Activity Detected192.168.2.55003087.120.116.2452400TCP
            2025-01-15T03:53:49.186255+010020365941Malware Command and Control Activity Detected192.168.2.55003187.120.116.2452400TCP
            2025-01-15T03:53:51.394333+010020365941Malware Command and Control Activity Detected192.168.2.55003287.120.116.2452400TCP
            2025-01-15T03:53:53.595153+010020365941Malware Command and Control Activity Detected192.168.2.55003387.120.116.2452400TCP
            2025-01-15T03:53:55.767330+010020365941Malware Command and Control Activity Detected192.168.2.55003487.120.116.2452400TCP
            2025-01-15T03:53:57.909759+010020365941Malware Command and Control Activity Detected192.168.2.55003587.120.116.2452400TCP
            2025-01-15T03:54:00.027576+010020365941Malware Command and Control Activity Detected192.168.2.55003687.120.116.2452400TCP
            2025-01-15T03:54:02.122155+010020365941Malware Command and Control Activity Detected192.168.2.55003787.120.116.2452400TCP
            2025-01-15T03:54:04.239670+010020365941Malware Command and Control Activity Detected192.168.2.55003887.120.116.2452400TCP
            2025-01-15T03:54:06.288974+010020365941Malware Command and Control Activity Detected192.168.2.55003987.120.116.2452400TCP
            2025-01-15T03:54:08.322137+010020365941Malware Command and Control Activity Detected192.168.2.55004087.120.116.2452400TCP
            2025-01-15T03:54:10.356046+010020365941Malware Command and Control Activity Detected192.168.2.55004187.120.116.2452400TCP
            2025-01-15T03:54:12.391702+010020365941Malware Command and Control Activity Detected192.168.2.55004287.120.116.2452400TCP
            2025-01-15T03:54:14.407861+010020365941Malware Command and Control Activity Detected192.168.2.55004387.120.116.2452400TCP
            2025-01-15T03:54:16.389946+010020365941Malware Command and Control Activity Detected192.168.2.55004487.120.116.2452400TCP
            2025-01-15T03:54:18.387505+010020365941Malware Command and Control Activity Detected192.168.2.55004587.120.116.2452400TCP
            2025-01-15T03:54:20.373931+010020365941Malware Command and Control Activity Detected192.168.2.55004687.120.116.2452400TCP
            2025-01-15T03:54:22.357907+010020365941Malware Command and Control Activity Detected192.168.2.55004787.120.116.2452400TCP
            2025-01-15T03:54:24.308993+010020365941Malware Command and Control Activity Detected192.168.2.55004887.120.116.2452400TCP
            2025-01-15T03:54:26.268063+010020365941Malware Command and Control Activity Detected192.168.2.55004987.120.116.2452400TCP
            2025-01-15T03:54:28.206760+010020365941Malware Command and Control Activity Detected192.168.2.55005087.120.116.2452400TCP
            2025-01-15T03:54:30.159007+010020365941Malware Command and Control Activity Detected192.168.2.55005187.120.116.2452400TCP
            2025-01-15T03:54:32.075397+010020365941Malware Command and Control Activity Detected192.168.2.55005287.120.116.2452400TCP
            2025-01-15T03:54:33.982978+010020365941Malware Command and Control Activity Detected192.168.2.55005387.120.116.2452400TCP
            2025-01-15T03:54:35.893550+010020365941Malware Command and Control Activity Detected192.168.2.55005487.120.116.2452400TCP
            2025-01-15T03:54:37.780203+010020365941Malware Command and Control Activity Detected192.168.2.55005587.120.116.2452400TCP
            2025-01-15T03:54:39.763136+010020365941Malware Command and Control Activity Detected192.168.2.55005687.120.116.2452400TCP
            2025-01-15T03:54:41.622806+010020365941Malware Command and Control Activity Detected192.168.2.55005787.120.116.2452400TCP
            2025-01-15T03:54:43.481632+010020365941Malware Command and Control Activity Detected192.168.2.55005887.120.116.2452400TCP
            2025-01-15T03:54:45.327929+010020365941Malware Command and Control Activity Detected192.168.2.55005987.120.116.2452400TCP
            2025-01-15T03:54:47.168931+010020365941Malware Command and Control Activity Detected192.168.2.55006087.120.116.2452400TCP
            2025-01-15T03:54:48.993020+010020365941Malware Command and Control Activity Detected192.168.2.55006187.120.116.2452400TCP
            2025-01-15T03:54:50.825416+010020365941Malware Command and Control Activity Detected192.168.2.55006287.120.116.2452400TCP
            2025-01-15T03:54:52.690343+010020365941Malware Command and Control Activity Detected192.168.2.55006387.120.116.2452400TCP
            2025-01-15T03:54:54.528868+010020365941Malware Command and Control Activity Detected192.168.2.55006487.120.116.2452400TCP
            2025-01-15T03:54:56.399161+010020365941Malware Command and Control Activity Detected192.168.2.55006587.120.116.2452400TCP
            2025-01-15T03:54:58.227952+010020365941Malware Command and Control Activity Detected192.168.2.55006687.120.116.2452400TCP
            2025-01-15T03:55:00.032292+010020365941Malware Command and Control Activity Detected192.168.2.55006787.120.116.2452400TCP
            2025-01-15T03:55:01.831851+010020365941Malware Command and Control Activity Detected192.168.2.55006887.120.116.2452400TCP
            2025-01-15T03:55:03.623843+010020365941Malware Command and Control Activity Detected192.168.2.55006987.120.116.2452400TCP
            2025-01-15T03:55:05.439849+010020365941Malware Command and Control Activity Detected192.168.2.55007087.120.116.2452400TCP
            2025-01-15T03:55:07.213988+010020365941Malware Command and Control Activity Detected192.168.2.55007187.120.116.2452400TCP
            2025-01-15T03:55:09.003871+010020365941Malware Command and Control Activity Detected192.168.2.55007287.120.116.2452400TCP
            2025-01-15T03:55:10.874478+010020365941Malware Command and Control Activity Detected192.168.2.55007387.120.116.2452400TCP
            2025-01-15T03:55:12.639545+010020365941Malware Command and Control Activity Detected192.168.2.55007487.120.116.2452400TCP
            2025-01-15T03:55:14.389716+010020365941Malware Command and Control Activity Detected192.168.2.55007587.120.116.2452400TCP
            2025-01-15T03:55:16.137728+010020365941Malware Command and Control Activity Detected192.168.2.55007687.120.116.2452400TCP
            2025-01-15T03:55:17.870801+010020365941Malware Command and Control Activity Detected192.168.2.55007787.120.116.2452400TCP
            2025-01-15T03:55:19.626174+010020365941Malware Command and Control Activity Detected192.168.2.55007887.120.116.2452400TCP
            2025-01-15T03:55:21.391704+010020365941Malware Command and Control Activity Detected192.168.2.55007987.120.116.2452400TCP
            2025-01-15T03:55:23.122189+010020365941Malware Command and Control Activity Detected192.168.2.55008087.120.116.2452400TCP
            2025-01-15T03:55:24.842043+010020365941Malware Command and Control Activity Detected192.168.2.55008187.120.116.2452400TCP
            2025-01-15T03:55:26.586078+010020365941Malware Command and Control Activity Detected192.168.2.55008287.120.116.2452400TCP
            2025-01-15T03:55:28.309680+010020365941Malware Command and Control Activity Detected192.168.2.55008387.120.116.2452400TCP
            2025-01-15T03:55:30.031959+010020365941Malware Command and Control Activity Detected192.168.2.55008487.120.116.2452400TCP
            2025-01-15T03:55:31.767566+010020365941Malware Command and Control Activity Detected192.168.2.55008587.120.116.2452400TCP
            2025-01-15T03:55:33.487033+010020365941Malware Command and Control Activity Detected192.168.2.55008687.120.116.2452400TCP
            2025-01-15T03:55:35.219590+010020365941Malware Command and Control Activity Detected192.168.2.55008787.120.116.2452400TCP
            2025-01-15T03:55:36.988072+010020365941Malware Command and Control Activity Detected192.168.2.55008887.120.116.2452400TCP
            2025-01-15T03:55:38.763959+010020365941Malware Command and Control Activity Detected192.168.2.55008987.120.116.2452400TCP
            2025-01-15T03:55:40.522010+010020365941Malware Command and Control Activity Detected192.168.2.55009087.120.116.2452400TCP
            2025-01-15T03:55:42.288746+010020365941Malware Command and Control Activity Detected192.168.2.55009187.120.116.2452400TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 00000007.00000002.2193815642.0000000001397000.00000004.00000020.00020000.00000000.sdmpMalware Configuration Extractor: Remcos {"Host:Port:Password": ["87.120.116.245:2400:1"], "Assigned name": "RemoteHost", "Connect interval": "1", "Install flag": "Enable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Enable", "Install path": "Application path", "Copy file": "remcos.exe", "Startup value": "Disable", "Hide file": "Disable", "Mutex": "Rmc-24L73B", "Keylog flag": "0", "Keylog path": "Application path", "Keylog file": "logs.dat", "Keylog crypt": "Disable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "1", "Take Screenshot option": "Disable", "Take screenshot title": "", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Screenshots", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "remcos"}
            Source: C:\ProgramData\Remcos\remcos.exeReversingLabs: Detection: 68%
            Source: C:\ProgramData\Remcos\remcos.exeVirustotal: Detection: 77%Perma Link
            Source: Material Requirments.exeVirustotal: Detection: 77%Perma Link
            Source: Material Requirments.exeReversingLabs: Detection: 68%
            Source: Yara matchFile source: 00000007.00000002.2193815642.0000000001397000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059843569.0000000000FD7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000B.00000002.2278960559.0000000000E77000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000D.00000002.2358460692.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.4498595557.00000000010E8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 1276, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 7120, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 6620, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 2436, type: MEMORYSTR
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: C:\ProgramData\Remcos\remcos.exeJoe Sandbox ML: detected
            Source: Material Requirments.exeJoe Sandbox ML: detected
            Source: Material Requirments.exe, 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: -----BEGIN PUBLIC KEY-----memstr_60890792-4

            Exploits

            barindex
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTR
            Source: Material Requirments.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: Material Requirments.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49712 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49708 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49711 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49713 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49720 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49732 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49714 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49753 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49769 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49785 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49804 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49822 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49837 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49856 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49873 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49892 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49910 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49926 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49943 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49961 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49978 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:49996 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50004 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50007 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50005 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50003 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50009 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50006 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50011 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50015 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50012 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50014 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50010 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50019 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50022 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50023 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50020 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50016 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50018 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50017 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50025 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50021 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50024 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50030 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50028 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50033 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50038 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50031 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50040 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50037 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50029 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50035 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50034 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50036 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50013 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50044 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50039 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50041 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50043 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50026 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50050 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50046 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50051 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50048 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50054 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50032 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50052 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50042 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50049 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50055 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50059 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50045 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50058 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50065 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50067 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50066 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50057 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50072 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50063 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50062 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50061 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50053 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50069 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50027 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50075 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50068 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50071 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50047 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50076 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50070 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50077 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50079 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50056 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50078 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50080 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50083 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50082 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50074 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50064 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50085 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50091 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50086 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50081 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50089 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50073 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50060 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50084 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50087 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50090 -> 87.120.116.245:2400
            Source: Network trafficSuricata IDS: 2036594 - Severity 1 - ET JA3 Hash - Remcos 3.x/4.x TLS Connection : 192.168.2.5:50088 -> 87.120.116.245:2400
            Source: Malware configuration extractorIPs: 87.120.116.245
            Source: global trafficTCP traffic: 192.168.2.5:49708 -> 87.120.116.245:2400
            Source: Joe Sandbox ViewASN Name: UNACS-AS-BG8000BurgasBG UNACS-AS-BG8000BurgasBG
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.245
            Source: Material Requirments.exe, 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, Material Requirments.exe, 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, Material Requirments.exe, 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://geoplugin.net/json.gp/C
            Source: remcos.exe, 00000006.00000002.2197961974.0000000002F19000.00000004.00000800.00020000.00000000.sdmp, remcos.exe, 0000000A.00000002.2284053143.0000000002AF9000.00000004.00000800.00020000.00000000.sdmp, remcos.exe, 0000000C.00000002.2364039060.0000000003129000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.w3.
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTR

            E-Banking Fraud

            barindex
            Source: Yara matchFile source: 00000007.00000002.2193815642.0000000001397000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059843569.0000000000FD7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000B.00000002.2278960559.0000000000E77000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000D.00000002.2358460692.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.4498595557.00000000010E8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 1276, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 7120, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 6620, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 2436, type: MEMORYSTR

            System Summary

            barindex
            Source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Remcos_b296e965 Author: unknown
            Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Remcos_b296e965 Author: unknown
            Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: REMCOS_RAT_variants Author: unknown
            Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) Author: ditekSHen
            Source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Remcos_b296e965 Author: unknown
            Source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTRMatched rule: Windows_Trojan_Remcos_b296e965 Author: unknown
            Source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTRMatched rule: Windows_Trojan_Remcos_b296e965 Author: unknown
            Source: Material Requirments.exe, 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCaptive.dll" vs Material Requirments.exe
            Source: Material Requirments.exe, 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs Material Requirments.exe
            Source: Material Requirments.exe, 00000000.00000002.2075574179.0000000007610000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameCaptive.dll" vs Material Requirments.exe
            Source: Material Requirments.exe, 00000000.00000000.2046337274.0000000000E96000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamebEab.exe@ vs Material Requirments.exe
            Source: Material Requirments.exe, 00000000.00000002.2076374844.00000000080E0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs Material Requirments.exe
            Source: Material Requirments.exe, 00000000.00000002.2058601948.00000000014C0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs Material Requirments.exe
            Source: Material Requirments.exe, 00000000.00000002.2070300215.0000000004309000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCaptive.dll" vs Material Requirments.exe
            Source: Material Requirments.exeBinary or memory string: OriginalFilenamebEab.exe@ vs Material Requirments.exe
            Source: Material Requirments.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23
            Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23
            Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
            Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
            Source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23
            Source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTRMatched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23
            Source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTRMatched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23
            Source: Material Requirments.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: remcos.exe.3.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: classification engineClassification label: mal100.troj.expl.evad.winEXE@16/4@0/1
            Source: C:\Users\user\Desktop\Material Requirments.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Material Requirments.exe.logJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMutant created: NULL
            Source: C:\ProgramData\Remcos\remcos.exeMutant created: \Sessions\1\BaseNamedObjects\Rmc-24L73B
            Source: Material Requirments.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: Material Requirments.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
            Source: C:\Users\user\Desktop\Material Requirments.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: Material Requirments.exeVirustotal: Detection: 77%
            Source: Material Requirments.exeReversingLabs: Detection: 68%
            Source: C:\Users\user\Desktop\Material Requirments.exeFile read: C:\Users\user\Desktop\Material Requirments.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\Material Requirments.exe "C:\Users\user\Desktop\Material Requirments.exe"
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess created: C:\Users\user\Desktop\Material Requirments.exe "C:\Users\user\Desktop\Material Requirments.exe"
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: unknownProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: unknownProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: unknownProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess created: C:\Users\user\Desktop\Material Requirments.exe "C:\Users\user\Desktop\Material Requirments.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe" Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: winmm.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: ntmarta.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: edputil.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: windows.staterepositoryps.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: appresolver.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: bcp47langs.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: slc.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: sppc.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: onecorecommonproxystub.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: version.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wldp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: profapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: amsi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: userenv.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: winmm.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wininet.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: netutils.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: version.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wldp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: profapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: amsi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: userenv.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: winmm.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wininet.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: netutils.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: version.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wldp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: profapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: amsi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: userenv.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: winmm.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wininet.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: netutils.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: version.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wldp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: profapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: amsi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: userenv.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: winmm.dll
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: urlmon.dll
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: wininet.dll
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iertutil.dll
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: srvcli.dll
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: netutils.dll
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: iphlpapi.dll
            Source: C:\ProgramData\Remcos\remcos.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\Desktop\Material Requirments.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Users\user\Desktop\Material Requirments.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
            Source: Material Requirments.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: Material Requirments.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: Material Requirments.exeStatic PE information: section name: .text entropy: 7.831221418025935
            Source: remcos.exe.3.drStatic PE information: section name: .text entropy: 7.831221418025935
            Source: C:\Users\user\Desktop\Material Requirments.exeFile created: C:\ProgramData\Remcos\remcos.exeJump to dropped file
            Source: C:\Users\user\Desktop\Material Requirments.exeFile created: C:\ProgramData\Remcos\remcos.exeJump to dropped file

            Boot Survival

            barindex
            Source: C:\Users\user\Desktop\Material Requirments.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Rmc-24L73BJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Rmc-24L73BJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Rmc-24L73BJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run Rmc-24L73BJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run Rmc-24L73BJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 1248, type: MEMORYSTR
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: 16F0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: 3300000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: 3100000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: 82A0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: 92A0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: 9450000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: A450000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: F20000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 2B10000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 2850000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 73A0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 83A0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 8530000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 9530000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 1320000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 2F10000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 1480000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 7B10000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 8B10000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 8CB0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 9CB0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: CC0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 2AF0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 2920000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 7500000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 8500000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 86A0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 96A0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 1960000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 3120000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 5120000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 7D30000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 8D30000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 8ED0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory allocated: 9ED0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeWindow / User API: threadDelayed 3140Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeWindow / User API: threadDelayed 6806Jump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exe TID: 6348Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 6620Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 1200Thread sleep count: 3140 > 30Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 1200Thread sleep time: -9420000s >= -30000sJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 1200Thread sleep count: 6806 > 30Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 1200Thread sleep time: -20418000s >= -30000sJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 1684Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 4724Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exe TID: 1048Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: remcos.exe, 00000005.00000002.4498595557.00000000010E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllB
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory allocated: page read and write | page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Users\user\Desktop\Material Requirments.exeMemory written: C:\Users\user\Desktop\Material Requirments.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory written: C:\ProgramData\Remcos\remcos.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory written: C:\ProgramData\Remcos\remcos.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMemory written: C:\ProgramData\Remcos\remcos.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess created: C:\Users\user\Desktop\Material Requirments.exe "C:\Users\user\Desktop\Material Requirments.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe" Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeProcess created: C:\ProgramData\Remcos\remcos.exe "C:\ProgramData\Remcos\remcos.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeQueries volume information: C:\Users\user\Desktop\Material Requirments.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\ProgramData\Remcos\remcos.exe VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\ProgramData\Remcos\remcos.exe VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\ProgramData\Remcos\remcos.exe VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\ProgramData\Remcos\remcos.exe VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Material Requirments.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000000.00000002.2075574179.0000000007610000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004309000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000007.00000002.2193815642.0000000001397000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059843569.0000000000FD7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000B.00000002.2278960559.0000000000E77000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000D.00000002.2358460692.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.4498595557.00000000010E8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 1276, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 7120, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 6620, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 2436, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: C:\Users\user\Desktop\Material Requirments.exeMutex created: \Sessions\1\BaseNamedObjects\Rmc-24L73BJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMutex created: \Sessions\1\BaseNamedObjects\Rmc-24L73BJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMutex created: \Sessions\1\BaseNamedObjects\Rmc-24L73BJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMutex created: \Sessions\1\BaseNamedObjects\Rmc-24L73BJump to behavior
            Source: C:\ProgramData\Remcos\remcos.exeMutex created: \Sessions\1\BaseNamedObjects\Rmc-24L73B
            Source: Yara matchFile source: 00000000.00000002.2075574179.0000000007610000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004309000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000007.00000002.2193815642.0000000001397000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059843569.0000000000FD7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000B.00000002.2278960559.0000000000E77000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000D.00000002.2358460692.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.4498595557.00000000010E8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 7156, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: Material Requirments.exe PID: 1372, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 1276, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 7120, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 6620, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: remcos.exe PID: 2436, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation11
            Registry Run Keys / Startup Folder
            111
            Process Injection
            1
            Masquerading
            OS Credential Dumping11
            Security Software Discovery
            Remote Services1
            Archive Collected Data
            1
            Non-Standard Port
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/Job1
            DLL Side-Loading
            11
            Registry Run Keys / Startup Folder
            1
            Disable or Modify Tools
            LSASS Memory31
            Virtualization/Sandbox Evasion
            Remote Desktop ProtocolData from Removable Media1
            Remote Access Software
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            DLL Side-Loading
            31
            Virtualization/Sandbox Evasion
            Security Account Manager1
            Application Window Discovery
            SMB/Windows Admin SharesData from Network Shared Drive1
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook111
            Process Injection
            NTDS1
            File and Directory Discovery
            Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Obfuscated Files or Information
            LSA Secrets12
            System Information Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
            Software Packing
            Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
            DLL Side-Loading
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet
            behaviorgraph top1 signatures2 2 Behavior Graph ID: 1591545 Sample: Material Requirments.pif Startdate: 15/01/2025 Architecture: WINDOWS Score: 100 45 Suricata IDS alerts for network traffic 2->45 47 Found malware configuration 2->47 49 Malicious sample detected (through community Yara rule) 2->49 51 9 other signatures 2->51 8 Material Requirments.exe 3 2->8         started        12 remcos.exe 2 2->12         started        14 remcos.exe 2 2->14         started        16 remcos.exe 2 2->16         started        process3 file4 39 C:\Users\...\Material Requirments.exe.log, ASCII 8->39 dropped 57 Injects a PE file into a foreign processes 8->57 18 Material Requirments.exe 2 4 8->18         started        22 remcos.exe 12->22         started        24 remcos.exe 14->24         started        26 remcos.exe 16->26         started        signatures5 process6 file7 35 C:\ProgramData\Remcos\remcos.exe, PE32 18->35 dropped 37 C:\ProgramData\...\remcos.exe:Zone.Identifier, ASCII 18->37 dropped 53 Detected Remcos RAT 18->53 55 Creates autostart registry keys with suspicious names 18->55 28 remcos.exe 3 18->28         started        signatures8 process9 signatures10 59 Multi AV Scanner detection for dropped file 28->59 61 Machine Learning detection for dropped file 28->61 63 Injects a PE file into a foreign processes 28->63 31 remcos.exe 4 1 28->31         started        process11 dnsIp12 41 87.120.116.245, 2400, 49708, 49711 UNACS-AS-BG8000BurgasBG Bulgaria 31->41 43 Detected Remcos RAT 31->43 signatures13

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            Material Requirments.exe78%VirustotalBrowse
            Material Requirments.exe68%ReversingLabsWin32.Trojan.Remcos
            Material Requirments.exe100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            C:\ProgramData\Remcos\remcos.exe100%Joe Sandbox ML
            C:\ProgramData\Remcos\remcos.exe68%ReversingLabsWin32.Trojan.Remcos
            C:\ProgramData\Remcos\remcos.exe78%VirustotalBrowse
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No contacted domains info
            NameSourceMaliciousAntivirus DetectionReputation
            http://www.w3.remcos.exe, 00000006.00000002.2197961974.0000000002F19000.00000004.00000800.00020000.00000000.sdmp, remcos.exe, 0000000A.00000002.2284053143.0000000002AF9000.00000004.00000800.00020000.00000000.sdmp, remcos.exe, 0000000C.00000002.2364039060.0000000003129000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://geoplugin.net/json.gp/CMaterial Requirments.exe, 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, Material Requirments.exe, 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, Material Requirments.exe, 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                87.120.116.245
                unknownBulgaria
                25206UNACS-AS-BG8000BurgasBGtrue
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1591545
                Start date and time:2025-01-15 03:50:44 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 7m 1s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:15
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:Material Requirments.exe
                (renamed file extension from pif to exe)
                Original Sample Name:Material Requirments.pif
                Detection:MAL
                Classification:mal100.troj.expl.evad.winEXE@16/4@0/1
                Cookbook Comments:
                • Override analysis time to 240000 for current running targets taking high CPU consumption
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 184.28.90.27, 23.1.237.91, 172.202.163.200, 13.107.246.45
                • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                • Report size exceeded maximum capacity and may have missing behavior information.
                • Report size getting too big, too many NtOpenKeyEx calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.
                TimeTypeDescription
                21:51:36API Interceptor1x Sleep call for process: Material Requirments.exe modified
                21:51:38API Interceptor4850469x Sleep call for process: remcos.exe modified
                21:51:40AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Rmc-24L73B "C:\ProgramData\Remcos\remcos.exe"
                21:51:49AutostartRun: HKLM\Software\Microsoft\Windows\CurrentVersion\Run Rmc-24L73B "C:\ProgramData\Remcos\remcos.exe"
                21:51:57AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run Rmc-24L73B "C:\ProgramData\Remcos\remcos.exe"
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                87.120.116.245Material requirements_1.pif.exeGet hashmaliciousRemcosBrowse
                  No context
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  UNACS-AS-BG8000BurgasBGpreliminary drawing.pif.exeGet hashmaliciousRemcos, PureLog StealerBrowse
                  • 87.120.127.120
                  5tCuNr661k.exeGet hashmaliciousRedLineBrowse
                  • 87.120.120.86
                  5tCuNr661k.exeGet hashmaliciousRedLineBrowse
                  • 87.120.120.86
                  shaLnqmyTS.exeGet hashmaliciousRedLineBrowse
                  • 87.120.120.86
                  shaLnqmyTS.exeGet hashmaliciousRedLineBrowse
                  • 87.120.120.86
                  zAGUEDGSTM.exeGet hashmaliciousRedLineBrowse
                  • 87.120.120.86
                  WtZl31OLfA.exeGet hashmaliciousRemcos, GuLoaderBrowse
                  • 87.120.116.187
                  C5Zr4LSzmp.exeGet hashmaliciousRedLineBrowse
                  • 87.120.120.86
                  C5Zr4LSzmp.exeGet hashmaliciousRedLineBrowse
                  • 87.120.120.86
                  2XnMqJW0u1.exeGet hashmaliciousXWormBrowse
                  • 87.120.120.15
                  No context
                  No context
                  Process:C:\Users\user\Desktop\Material Requirments.exe
                  File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                  Category:dropped
                  Size (bytes):1005568
                  Entropy (8bit):7.827484845541161
                  Encrypted:false
                  SSDEEP:24576:rbT8S0ck7b8crshYjBSbIBDESo13E/WFRHVJmSr39RrE:rf8S0cXcrsWtDfoFRVJvNRrE
                  MD5:3A9DA3EDC40736CC832EDED3C389A661
                  SHA1:F32F61FB4458696DAE4F15D82377163521E4F8B5
                  SHA-256:F2418CA6E602C9470A8B6E32172432726E50B00D6E7A0EE5BD70D0172017D6C3
                  SHA-512:A1E2EFE247E78CFB0AD62125C69C44200F6FC094085A570A0AD9A4FF3D0F2025EB9F0AACBE7CD7DCE46A18121C02D46FEC471A3353733A93EC49B6A81D243E95
                  Malicious:true
                  Antivirus:
                  • Antivirus: Joe Sandbox ML, Detection: 100%
                  • Antivirus: ReversingLabs, Detection: 68%
                  • Antivirus: Virustotal, Detection: 78%, Browse
                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...^&.g..............0..,...*.......K... ...`....@.. ....................................`.................................4K..O....`..|'........................................................................... ............... ..H............text....+... ...,.................. ..`.rsrc...|'...`...(..................@..@.reloc...............V..............@..B................hK......H........C...:......%...D~.................................................}......}.....(........}......o.....*..0............{........+..*..0............{........+..*..0..9.........(.........,.r...ps....z.{....o ...o!....o"...t.....+..*....0..9.........(.........,.r...ps....z.{....o#...o!....o"...t.....+..*....0..C.........($...u...........,...+(.o%...u.............,...+..o$...u.....+..*..0..+.........(......,.r+..ps....z..}.....(!....o&....*..0..8.........{.........,...+$.{
                  Process:C:\Users\user\Desktop\Material Requirments.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:modified
                  Size (bytes):26
                  Entropy (8bit):3.95006375643621
                  Encrypted:false
                  SSDEEP:3:ggPYV:rPYV
                  MD5:187F488E27DB4AF347237FE461A079AD
                  SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                  SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                  SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                  Malicious:true
                  Preview:[ZoneTransfer]....ZoneId=0
                  Process:C:\Users\user\Desktop\Material Requirments.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1216
                  Entropy (8bit):5.34331486778365
                  Encrypted:false
                  SSDEEP:24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ
                  MD5:1330C80CAAC9A0FB172F202485E9B1E8
                  SHA1:86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492
                  SHA-256:B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560
                  SHA-512:75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2
                  Malicious:true
                  Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02
                  Process:C:\ProgramData\Remcos\remcos.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1216
                  Entropy (8bit):5.34331486778365
                  Encrypted:false
                  SSDEEP:24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ
                  MD5:1330C80CAAC9A0FB172F202485E9B1E8
                  SHA1:86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492
                  SHA-256:B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560
                  SHA-512:75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2
                  Malicious:false
                  Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02
                  File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                  Entropy (8bit):7.827484845541161
                  TrID:
                  • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                  • Win32 Executable (generic) a (10002005/4) 49.78%
                  • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                  • Generic Win/DOS Executable (2004/3) 0.01%
                  • DOS Executable Generic (2002/1) 0.01%
                  File name:Material Requirments.exe
                  File size:1'005'568 bytes
                  MD5:3a9da3edc40736cc832eded3c389a661
                  SHA1:f32f61fb4458696dae4f15d82377163521e4f8b5
                  SHA256:f2418ca6e602c9470a8b6e32172432726e50b00d6e7a0ee5bd70d0172017d6c3
                  SHA512:a1e2efe247e78cfb0ad62125c69c44200f6fc094085a570a0ad9a4ff3d0f2025eb9f0aacbe7cd7dce46a18121c02d46fec471a3353733a93ec49b6a81d243e95
                  SSDEEP:24576:rbT8S0ck7b8crshYjBSbIBDESo13E/WFRHVJmSr39RrE:rf8S0cXcrsWtDfoFRVJvNRrE
                  TLSH:252512592749ED06C8D20BB098B0E3F826705FD9EA51C3039AFDBEFB7C265967418394
                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...^&.g..............0..,...*.......K... ...`....@.. ....................................`................................
                  Icon Hash:33362c2d36335470
                  Entrypoint:0x4f4b86
                  Entrypoint Section:.text
                  Digitally signed:false
                  Imagebase:0x400000
                  Subsystem:windows gui
                  Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                  DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                  Time Stamp:0x677F265E [Thu Jan 9 01:29:02 2025 UTC]
                  TLS Callbacks:
                  CLR (.Net) Version:
                  OS Version Major:4
                  OS Version Minor:0
                  File Version Major:4
                  File Version Minor:0
                  Subsystem Version Major:4
                  Subsystem Version Minor:0
                  Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                  Instruction
                  jmp dword ptr [00402000h]
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  NameVirtual AddressVirtual Size Is in Section
                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_IMPORT0xf4b340x4f.text
                  IMAGE_DIRECTORY_ENTRY_RESOURCE0xf60000x277c.rsrc
                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                  IMAGE_DIRECTORY_ENTRY_BASERELOC0xfa0000xc.reloc
                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                  .text0x20000xf2b8c0xf2c000a8b8c4bd722d339244aaee111723f05False0.935753049369207data7.831221418025935IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                  .rsrc0xf60000x277c0x28004e9b0506103b0eab1b88df4722769ed0False0.87890625data7.595806949277348IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                  .reloc0xfa0000xc0x200f7cd7afbc98af4aee0e8ddfc076da2a5False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                  NameRVASizeTypeLanguageCountryZLIB Complexity
                  RT_ICON0xf60c80x2356PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9427371213796153
                  RT_GROUP_ICON0xf84300x14data1.05
                  RT_VERSION0xf84540x324data0.43283582089552236
                  DLLImport
                  mscoree.dll_CorExeMain
                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                  2025-01-15T03:51:41.530192+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54970887.120.116.2452400TCP
                  2025-01-15T03:51:44.182556+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54971187.120.116.2452400TCP
                  2025-01-15T03:51:46.821597+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54971287.120.116.2452400TCP
                  2025-01-15T03:51:49.466137+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54971387.120.116.2452400TCP
                  2025-01-15T03:51:52.102768+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54971487.120.116.2452400TCP
                  2025-01-15T03:51:54.764998+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54972087.120.116.2452400TCP
                  2025-01-15T03:51:57.399678+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54973287.120.116.2452400TCP
                  2025-01-15T03:52:00.024952+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54975387.120.116.2452400TCP
                  2025-01-15T03:52:02.668250+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54976987.120.116.2452400TCP
                  2025-01-15T03:52:05.310210+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54978587.120.116.2452400TCP
                  2025-01-15T03:52:07.947280+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54980487.120.116.2452400TCP
                  2025-01-15T03:52:10.619393+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54982287.120.116.2452400TCP
                  2025-01-15T03:52:13.247360+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54983787.120.116.2452400TCP
                  2025-01-15T03:52:15.885829+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54985687.120.116.2452400TCP
                  2025-01-15T03:52:18.606441+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54987387.120.116.2452400TCP
                  2025-01-15T03:52:21.263352+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54989287.120.116.2452400TCP
                  2025-01-15T03:52:23.901902+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54991087.120.116.2452400TCP
                  2025-01-15T03:52:26.521560+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54992687.120.116.2452400TCP
                  2025-01-15T03:52:29.131855+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54994387.120.116.2452400TCP
                  2025-01-15T03:52:31.761709+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54996187.120.116.2452400TCP
                  2025-01-15T03:52:35.322512+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54997887.120.116.2452400TCP
                  2025-01-15T03:52:37.963143+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.54999687.120.116.2452400TCP
                  2025-01-15T03:52:40.603701+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55000387.120.116.2452400TCP
                  2025-01-15T03:52:43.248030+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55000487.120.116.2452400TCP
                  2025-01-15T03:52:45.891446+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55000587.120.116.2452400TCP
                  2025-01-15T03:52:48.505802+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55000687.120.116.2452400TCP
                  2025-01-15T03:52:51.733895+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55000787.120.116.2452400TCP
                  2025-01-15T03:52:54.351096+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55000987.120.116.2452400TCP
                  2025-01-15T03:52:57.087579+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001087.120.116.2452400TCP
                  2025-01-15T03:52:59.733578+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001187.120.116.2452400TCP
                  2025-01-15T03:53:02.389514+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001287.120.116.2452400TCP
                  2025-01-15T03:53:05.027616+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001387.120.116.2452400TCP
                  2025-01-15T03:53:07.654506+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001487.120.116.2452400TCP
                  2025-01-15T03:53:10.228093+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001587.120.116.2452400TCP
                  2025-01-15T03:53:12.795521+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001687.120.116.2452400TCP
                  2025-01-15T03:53:15.339669+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001787.120.116.2452400TCP
                  2025-01-15T03:53:17.838848+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001887.120.116.2452400TCP
                  2025-01-15T03:53:20.330001+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55001987.120.116.2452400TCP
                  2025-01-15T03:53:22.765924+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002087.120.116.2452400TCP
                  2025-01-15T03:53:25.184710+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002187.120.116.2452400TCP
                  2025-01-15T03:53:27.589482+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002287.120.116.2452400TCP
                  2025-01-15T03:53:29.966355+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002387.120.116.2452400TCP
                  2025-01-15T03:53:32.308965+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002487.120.116.2452400TCP
                  2025-01-15T03:53:34.618635+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002587.120.116.2452400TCP
                  2025-01-15T03:53:36.919199+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002687.120.116.2452400TCP
                  2025-01-15T03:53:39.214435+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002787.120.116.2452400TCP
                  2025-01-15T03:53:41.467620+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002887.120.116.2452400TCP
                  2025-01-15T03:53:43.700638+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55002987.120.116.2452400TCP
                  2025-01-15T03:53:45.982919+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003087.120.116.2452400TCP
                  2025-01-15T03:53:49.186255+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003187.120.116.2452400TCP
                  2025-01-15T03:53:51.394333+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003287.120.116.2452400TCP
                  2025-01-15T03:53:53.595153+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003387.120.116.2452400TCP
                  2025-01-15T03:53:55.767330+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003487.120.116.2452400TCP
                  2025-01-15T03:53:57.909759+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003587.120.116.2452400TCP
                  2025-01-15T03:54:00.027576+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003687.120.116.2452400TCP
                  2025-01-15T03:54:02.122155+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003787.120.116.2452400TCP
                  2025-01-15T03:54:04.239670+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003887.120.116.2452400TCP
                  2025-01-15T03:54:06.288974+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55003987.120.116.2452400TCP
                  2025-01-15T03:54:08.322137+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004087.120.116.2452400TCP
                  2025-01-15T03:54:10.356046+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004187.120.116.2452400TCP
                  2025-01-15T03:54:12.391702+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004287.120.116.2452400TCP
                  2025-01-15T03:54:14.407861+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004387.120.116.2452400TCP
                  2025-01-15T03:54:16.389946+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004487.120.116.2452400TCP
                  2025-01-15T03:54:18.387505+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004587.120.116.2452400TCP
                  2025-01-15T03:54:20.373931+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004687.120.116.2452400TCP
                  2025-01-15T03:54:22.357907+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004787.120.116.2452400TCP
                  2025-01-15T03:54:24.308993+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004887.120.116.2452400TCP
                  2025-01-15T03:54:26.268063+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55004987.120.116.2452400TCP
                  2025-01-15T03:54:28.206760+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005087.120.116.2452400TCP
                  2025-01-15T03:54:30.159007+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005187.120.116.2452400TCP
                  2025-01-15T03:54:32.075397+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005287.120.116.2452400TCP
                  2025-01-15T03:54:33.982978+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005387.120.116.2452400TCP
                  2025-01-15T03:54:35.893550+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005487.120.116.2452400TCP
                  2025-01-15T03:54:37.780203+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005587.120.116.2452400TCP
                  2025-01-15T03:54:39.763136+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005687.120.116.2452400TCP
                  2025-01-15T03:54:41.622806+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005787.120.116.2452400TCP
                  2025-01-15T03:54:43.481632+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005887.120.116.2452400TCP
                  2025-01-15T03:54:45.327929+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55005987.120.116.2452400TCP
                  2025-01-15T03:54:47.168931+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006087.120.116.2452400TCP
                  2025-01-15T03:54:48.993020+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006187.120.116.2452400TCP
                  2025-01-15T03:54:50.825416+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006287.120.116.2452400TCP
                  2025-01-15T03:54:52.690343+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006387.120.116.2452400TCP
                  2025-01-15T03:54:54.528868+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006487.120.116.2452400TCP
                  2025-01-15T03:54:56.399161+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006587.120.116.2452400TCP
                  2025-01-15T03:54:58.227952+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006687.120.116.2452400TCP
                  2025-01-15T03:55:00.032292+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006787.120.116.2452400TCP
                  2025-01-15T03:55:01.831851+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006887.120.116.2452400TCP
                  2025-01-15T03:55:03.623843+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55006987.120.116.2452400TCP
                  2025-01-15T03:55:05.439849+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007087.120.116.2452400TCP
                  2025-01-15T03:55:07.213988+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007187.120.116.2452400TCP
                  2025-01-15T03:55:09.003871+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007287.120.116.2452400TCP
                  2025-01-15T03:55:10.874478+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007387.120.116.2452400TCP
                  2025-01-15T03:55:12.639545+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007487.120.116.2452400TCP
                  2025-01-15T03:55:14.389716+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007587.120.116.2452400TCP
                  2025-01-15T03:55:16.137728+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007687.120.116.2452400TCP
                  2025-01-15T03:55:17.870801+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007787.120.116.2452400TCP
                  2025-01-15T03:55:19.626174+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007887.120.116.2452400TCP
                  2025-01-15T03:55:21.391704+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55007987.120.116.2452400TCP
                  2025-01-15T03:55:23.122189+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008087.120.116.2452400TCP
                  2025-01-15T03:55:24.842043+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008187.120.116.2452400TCP
                  2025-01-15T03:55:26.586078+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008287.120.116.2452400TCP
                  2025-01-15T03:55:28.309680+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008387.120.116.2452400TCP
                  2025-01-15T03:55:30.031959+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008487.120.116.2452400TCP
                  2025-01-15T03:55:31.767566+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008587.120.116.2452400TCP
                  2025-01-15T03:55:33.487033+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008687.120.116.2452400TCP
                  2025-01-15T03:55:35.219590+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008787.120.116.2452400TCP
                  2025-01-15T03:55:36.988072+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008887.120.116.2452400TCP
                  2025-01-15T03:55:38.763959+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55008987.120.116.2452400TCP
                  2025-01-15T03:55:40.522010+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55009087.120.116.2452400TCP
                  2025-01-15T03:55:42.288746+01002036594ET JA3 Hash - Remcos 3.x/4.x TLS Connection1192.168.2.55009187.120.116.2452400TCP
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 15, 2025 03:51:39.887624979 CET497082400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:39.892580032 CET24004970887.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:39.892657042 CET497082400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:39.899358034 CET497082400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:39.904122114 CET24004970887.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:41.530045986 CET24004970887.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:41.530191898 CET497082400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:41.554934025 CET497082400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:41.560254097 CET24004970887.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:42.560043097 CET497112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:42.565126896 CET24004971187.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:42.565367937 CET497112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:42.570139885 CET497112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:42.575042009 CET24004971187.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:44.181293964 CET24004971187.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:44.182555914 CET497112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:44.182775021 CET497112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:44.187622070 CET24004971187.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:45.185667992 CET497122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:45.190659046 CET24004971287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:45.190737963 CET497122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:45.195915937 CET497122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:45.200706959 CET24004971287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:46.821413040 CET24004971287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:46.821597099 CET497122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:46.821597099 CET497122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:46.826450109 CET24004971287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:47.826100111 CET497132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:47.831221104 CET24004971387.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:47.831291914 CET497132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:47.835890055 CET497132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:47.840758085 CET24004971387.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:49.466053963 CET24004971387.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:49.466136932 CET497132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:49.466236115 CET497132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:49.470989943 CET24004971387.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:50.483397007 CET497142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:50.488414049 CET24004971487.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:50.488511086 CET497142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:50.496829987 CET497142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:50.501732111 CET24004971487.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:52.102694988 CET24004971487.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:52.102767944 CET497142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:52.102854967 CET497142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:52.107649088 CET24004971487.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:53.111651897 CET497202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:53.117710114 CET24004972087.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:53.117805958 CET497202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:53.123282909 CET497202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:53.128835917 CET24004972087.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:54.764748096 CET24004972087.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:54.764997959 CET497202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:54.764997959 CET497202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:54.769989014 CET24004972087.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:55.779043913 CET497322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:55.784090042 CET24004973287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:55.784193993 CET497322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:55.791858912 CET497322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:55.796725035 CET24004973287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:57.399617910 CET24004973287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:57.399677992 CET497322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:57.399749994 CET497322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:57.404449940 CET24004973287.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:58.403886080 CET497532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:58.408792973 CET24004975387.120.116.245192.168.2.5
                  Jan 15, 2025 03:51:58.408869982 CET497532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:58.412343025 CET497532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:51:58.417123079 CET24004975387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:00.024869919 CET24004975387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:00.024951935 CET497532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:00.025029898 CET497532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:00.029870033 CET24004975387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:01.029887915 CET497692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:01.034849882 CET24004976987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:01.034965038 CET497692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:01.039299011 CET497692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:01.044096947 CET24004976987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:02.667424917 CET24004976987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:02.668250084 CET497692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:02.668416023 CET497692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:02.674016953 CET24004976987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:03.671350956 CET497852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:03.676202059 CET24004978587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:03.676417112 CET497852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:03.681301117 CET497852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:03.686070919 CET24004978587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:05.309688091 CET24004978587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:05.310209990 CET497852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:05.310209990 CET497852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:05.315083027 CET24004978587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:06.326056004 CET498042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:06.330931902 CET24004980487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:06.331048012 CET498042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:06.335052013 CET498042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:06.339904070 CET24004980487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:07.947192907 CET24004980487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:07.947279930 CET498042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:07.948820114 CET498042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:07.953602076 CET24004980487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:08.967828989 CET498222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:08.972650051 CET24004982287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:08.972714901 CET498222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:08.976775885 CET498222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:08.981614113 CET24004982287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:10.619218111 CET24004982287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:10.619393110 CET498222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:10.619393110 CET498222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:10.627999067 CET24004982287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:11.622724056 CET498372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:11.627589941 CET24004983787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:11.627657890 CET498372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:11.631586075 CET498372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:11.636346102 CET24004983787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:13.244355917 CET24004983787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:13.247359991 CET498372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:13.255080938 CET498372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:13.259893894 CET24004983787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:14.263339996 CET498562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:14.268332005 CET24004985687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:14.268399000 CET498562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:14.272384882 CET498562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:14.277324915 CET24004985687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:15.885735989 CET24004985687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:15.885828972 CET498562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:15.885883093 CET498562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:15.890737057 CET24004985687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:16.966275930 CET498732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:16.971118927 CET24004987387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:16.971199036 CET498732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:16.975138903 CET498732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:16.979989052 CET24004987387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:18.603794098 CET24004987387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:18.606441021 CET498732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:18.606592894 CET498732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:18.611397982 CET24004987387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:19.622417927 CET498922400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:19.627326965 CET24004989287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:19.627407074 CET498922400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:19.630639076 CET498922400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:19.635481119 CET24004989287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:21.263272047 CET24004989287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:21.263351917 CET498922400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:21.263662100 CET498922400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:21.268484116 CET24004989287.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:22.278687954 CET499102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:22.283591986 CET24004991087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:22.283673048 CET499102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:22.287241936 CET499102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:22.291996956 CET24004991087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:23.901809931 CET24004991087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:23.901901960 CET499102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:23.901997089 CET499102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:23.906793118 CET24004991087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:24.903568983 CET499262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:24.908570051 CET24004992687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:24.908643961 CET499262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:24.912511110 CET499262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:24.917602062 CET24004992687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:26.521491051 CET24004992687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:26.521559954 CET499262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:26.521635056 CET499262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:26.526464939 CET24004992687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:27.528621912 CET499432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:27.533487082 CET24004994387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:27.533576965 CET499432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:27.537159920 CET499432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:27.542006016 CET24004994387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:29.131794930 CET24004994387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:29.131855011 CET499432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:29.131922960 CET499432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:29.136720896 CET24004994387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:30.138175964 CET499612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:30.143028975 CET24004996187.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:30.143105984 CET499612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:30.147356033 CET499612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:30.152187109 CET24004996187.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:31.761476994 CET24004996187.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:31.761708975 CET499612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:31.761708975 CET499612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:31.766854048 CET24004996187.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:32.763113976 CET499782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:33.620208025 CET24004997887.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:33.620331049 CET499782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:33.624475956 CET499782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:33.630202055 CET24004997887.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:35.322442055 CET24004997887.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:35.322511911 CET499782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:35.322583914 CET499782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:35.327405930 CET24004997887.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:36.325546026 CET499962400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:36.330434084 CET24004999687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:36.330585957 CET499962400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:36.334835052 CET499962400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:36.339610100 CET24004999687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:37.962990046 CET24004999687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:37.963143110 CET499962400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:37.963233948 CET499962400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:37.968120098 CET24004999687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:38.966269016 CET500032400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:38.971194029 CET24005000387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:38.971427917 CET500032400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:38.974608898 CET500032400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:38.979393005 CET24005000387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:40.603384018 CET24005000387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:40.603701115 CET500032400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:40.603701115 CET500032400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:40.608613968 CET24005000387.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:41.608619928 CET500042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:41.613780022 CET24005000487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:41.613917112 CET500042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:41.629578114 CET500042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:41.634504080 CET24005000487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:43.247955084 CET24005000487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:43.248029947 CET500042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:43.248105049 CET500042400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:43.252911091 CET24005000487.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:44.263294935 CET500052400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:44.268371105 CET24005000587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:44.268480062 CET500052400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:44.272213936 CET500052400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:44.277033091 CET24005000587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:45.885869980 CET24005000587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:45.891446114 CET500052400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:45.891529083 CET500052400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:45.896416903 CET24005000587.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:46.903889894 CET500062400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:46.908830881 CET24005000687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:46.909070015 CET500062400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:46.912787914 CET500062400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:46.917603970 CET24005000687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:48.505738020 CET24005000687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:48.505801916 CET500062400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:48.505881071 CET500062400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:48.510631084 CET24005000687.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:49.513115883 CET500072400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:49.518166065 CET24005000787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:49.519454002 CET500072400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:49.522996902 CET500072400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:49.533293962 CET24005000787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:51.733686924 CET24005000787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:51.733819008 CET24005000787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:51.733895063 CET500072400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:51.733895063 CET500072400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:51.733895063 CET500072400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:51.733930111 CET24005000787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:51.733978033 CET500072400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:51.742316961 CET24005000787.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:52.747641087 CET500092400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:52.752504110 CET24005000987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:52.752669096 CET500092400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:52.755925894 CET500092400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:52.760741949 CET24005000987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:54.350965977 CET24005000987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:54.351095915 CET500092400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:54.351095915 CET500092400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:54.355946064 CET24005000987.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:55.356990099 CET500102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:55.361897945 CET24005001087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:55.361988068 CET500102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:55.367078066 CET500102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:55.371887922 CET24005001087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:57.086702108 CET24005001087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:57.087579012 CET500102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:57.087579012 CET500102400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:57.092649937 CET24005001087.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:58.100378036 CET500112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:58.105489016 CET24005001187.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:58.111521006 CET500112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:58.114799023 CET500112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:58.119801998 CET24005001187.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:59.732496977 CET24005001187.120.116.245192.168.2.5
                  Jan 15, 2025 03:52:59.733577967 CET500112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:59.733577967 CET500112400192.168.2.587.120.116.245
                  Jan 15, 2025 03:52:59.738574028 CET24005001187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:00.748502016 CET500122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:00.753472090 CET24005001287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:00.753551960 CET500122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:00.760159016 CET500122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:00.765002966 CET24005001287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:02.389414072 CET24005001287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:02.389513969 CET500122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:02.389558077 CET500122400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:02.394473076 CET24005001287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:03.414877892 CET500132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:03.419929028 CET24005001387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:03.420044899 CET500132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:03.448537111 CET500132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:03.453552008 CET24005001387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:05.024549961 CET24005001387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:05.027616024 CET500132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:05.027667046 CET500132400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:05.032614946 CET24005001387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:06.028801918 CET500142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:06.033941984 CET24005001487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:06.035521984 CET500142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:06.038803101 CET500142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:06.043692112 CET24005001487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:07.653199911 CET24005001487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:07.654505968 CET500142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:07.654577971 CET500142400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:07.660968065 CET24005001487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:08.622721910 CET500152400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:08.627871990 CET24005001587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:08.627950907 CET500152400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:08.631299019 CET500152400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:08.636167049 CET24005001587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:10.227699995 CET24005001587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:10.228092909 CET500152400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:10.228138924 CET500152400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:10.232928991 CET24005001587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:11.169373035 CET500162400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:11.174628019 CET24005001687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:11.175515890 CET500162400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:11.179758072 CET500162400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:11.184741020 CET24005001687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:12.792376041 CET24005001687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:12.795521021 CET500162400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:12.795567036 CET500162400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:12.800451994 CET24005001687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:13.700833082 CET500172400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:13.705948114 CET24005001787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:13.706154108 CET500172400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:13.709333897 CET500172400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:13.716331959 CET24005001787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:15.338824987 CET24005001787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:15.339668989 CET500172400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:15.339669943 CET500172400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:15.345407009 CET24005001787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:16.216301918 CET500182400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:16.221323013 CET24005001887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:16.221390009 CET500182400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:16.224464893 CET500182400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:16.229247093 CET24005001887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:17.838774920 CET24005001887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:17.838848114 CET500182400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:17.838917017 CET500182400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:17.843724966 CET24005001887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:18.685039997 CET500192400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:18.689964056 CET24005001987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:18.690488100 CET500192400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:18.693586111 CET500192400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:18.698381901 CET24005001987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:20.327106953 CET24005001987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:20.330001116 CET500192400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:20.330001116 CET500192400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:20.335220098 CET24005001987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:21.154042959 CET500202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:21.159142971 CET24005002087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:21.159223080 CET500202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:21.163883924 CET500202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:21.168759108 CET24005002087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:22.765851021 CET24005002087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:22.765923977 CET500202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:22.765964031 CET500202400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:22.772063017 CET24005002087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:23.560164928 CET500212400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:23.565356970 CET24005002187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:23.565490961 CET500212400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:23.569354057 CET500212400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:23.574234962 CET24005002187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:25.184643984 CET24005002187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:25.184710026 CET500212400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:25.184915066 CET500212400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:25.189663887 CET24005002187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:25.950820923 CET500222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:25.955919027 CET24005002287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:25.956110001 CET500222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:25.965629101 CET500222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:25.970499039 CET24005002287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:27.589265108 CET24005002287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:27.589482069 CET500222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:27.592761993 CET500222400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:27.597706079 CET24005002287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:28.341316938 CET500232400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:28.346225023 CET24005002387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:28.346411943 CET500232400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:28.350202084 CET500232400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:28.355027914 CET24005002387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:29.966259956 CET24005002387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:29.966355085 CET500232400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:29.966443062 CET500232400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:29.971286058 CET24005002387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:30.685044050 CET500242400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:30.690155983 CET24005002487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:30.695563078 CET500242400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:30.699059963 CET500242400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:30.703840971 CET24005002487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:32.308895111 CET24005002487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:32.308964968 CET500242400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:32.309161901 CET500242400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:32.313967943 CET24005002487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:33.013463974 CET500252400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:33.018280029 CET24005002587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:33.018342018 CET500252400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:33.023926020 CET500252400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:33.028846025 CET24005002587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:34.618515015 CET24005002587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:34.618634939 CET500252400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:34.618634939 CET500252400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:34.623383999 CET24005002587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:35.300780058 CET500262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:35.305953026 CET24005002687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:35.306039095 CET500262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:35.309088945 CET500262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:35.314146042 CET24005002687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:36.916996956 CET24005002687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:36.919198990 CET500262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:36.919248104 CET500262400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:36.924133062 CET24005002687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:37.575823069 CET500272400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:37.580775023 CET24005002787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:37.580861092 CET500272400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:37.584383965 CET500272400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:37.589226961 CET24005002787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:39.214379072 CET24005002787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:39.214435101 CET500272400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:39.214485884 CET500272400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:39.219327927 CET24005002787.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:39.841360092 CET500282400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:39.847568035 CET24005002887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:39.847645998 CET500282400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:39.852896929 CET500282400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:39.859141111 CET24005002887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:41.465137959 CET24005002887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:41.467619896 CET500282400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:41.467619896 CET500282400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:41.472485065 CET24005002887.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:42.075768948 CET500292400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:42.080869913 CET24005002987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:42.080946922 CET500292400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:42.086708069 CET500292400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:42.091598988 CET24005002987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:43.700540066 CET24005002987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:43.700638056 CET500292400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:43.700679064 CET500292400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:43.705543995 CET24005002987.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:44.294456005 CET500302400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:44.299465895 CET24005003087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:44.299601078 CET500302400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:44.302773952 CET500302400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:44.307693958 CET24005003087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:45.982296944 CET24005003087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:45.982918978 CET500302400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:45.982969999 CET500302400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:45.987905979 CET24005003087.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:46.560084105 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:46.565035105 CET24005003187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:46.565677881 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:46.569010973 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:46.573832989 CET24005003187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:49.186177015 CET24005003187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:49.186254978 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.186332941 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.187513113 CET24005003187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:49.187572956 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.187736988 CET24005003187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:49.187771082 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.187937975 CET24005003187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:49.191391945 CET24005003187.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:49.191437960 CET500312400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.732072115 CET500322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.737052917 CET24005003287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:49.737193108 CET500322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.742924929 CET500322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:49.747857094 CET24005003287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:51.394232988 CET24005003287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:51.394332886 CET500322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:51.394332886 CET500322400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:51.403403997 CET24005003287.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:51.935236931 CET500332400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:51.940677881 CET24005003387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:51.943650007 CET500332400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:51.947011948 CET500332400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:51.951822996 CET24005003387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:53.595062017 CET24005003387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:53.595153093 CET500332400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:53.595223904 CET500332400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:53.600364923 CET24005003387.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:54.107130051 CET500342400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:54.112708092 CET24005003487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:54.112858057 CET500342400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:54.116178989 CET500342400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:54.121772051 CET24005003487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:55.767235041 CET24005003487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:55.767329931 CET500342400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:55.767376900 CET500342400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:55.772139072 CET24005003487.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:56.263555050 CET500352400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:56.268882990 CET24005003587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:56.268960953 CET500352400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:56.299731970 CET500352400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:56.304677010 CET24005003587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:57.907871008 CET24005003587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:57.909759045 CET500352400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:57.909759045 CET500352400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:57.914881945 CET24005003587.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:58.389343023 CET500362400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:58.395651102 CET24005003687.120.116.245192.168.2.5
                  Jan 15, 2025 03:53:58.395735025 CET500362400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:58.399771929 CET500362400192.168.2.587.120.116.245
                  Jan 15, 2025 03:53:58.405868053 CET24005003687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:00.027517080 CET24005003687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:00.027575970 CET500362400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:00.027631998 CET500362400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:00.032394886 CET24005003687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:00.497616053 CET500372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:00.502434969 CET24005003787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:00.502552986 CET500372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:00.505917072 CET500372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:00.510704041 CET24005003787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:02.121262074 CET24005003787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:02.122154951 CET500372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:02.122154951 CET500372400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:02.127099037 CET24005003787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:02.575753927 CET500382400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:02.580761909 CET24005003887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:02.582309961 CET500382400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:02.585442066 CET500382400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:02.590312958 CET24005003887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:04.235830069 CET24005003887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:04.239670038 CET500382400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:04.239820957 CET500382400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:04.244604111 CET24005003887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:04.669507980 CET500392400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:04.674559116 CET24005003987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:04.674783945 CET500392400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:04.677746058 CET500392400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:04.682559967 CET24005003987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:06.288856030 CET24005003987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:06.288974047 CET500392400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:06.289057016 CET500392400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:06.293843031 CET24005003987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:06.716336012 CET500402400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:06.721374989 CET24005004087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:06.723459005 CET500402400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:06.726536989 CET500402400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:06.731379986 CET24005004087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:08.321971893 CET24005004087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:08.322137117 CET500402400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:08.322138071 CET500402400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:08.328243971 CET24005004087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:08.732110977 CET500412400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:08.737550020 CET24005004187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:08.739687920 CET500412400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:08.742873907 CET500412400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:08.748142958 CET24005004187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:10.355803967 CET24005004187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:10.356045961 CET500412400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:10.356045961 CET500412400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:10.360858917 CET24005004187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:10.747776031 CET500422400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:10.752770901 CET24005004287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:10.752875090 CET500422400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:10.756283045 CET500422400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:10.761192083 CET24005004287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:12.391575098 CET24005004287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:12.391701937 CET500422400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:12.391792059 CET500422400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:12.396647930 CET24005004287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:12.779082060 CET500432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:12.784079075 CET24005004387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:12.787702084 CET500432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:12.790811062 CET500432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:12.795653105 CET24005004387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:14.404499054 CET24005004387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:14.407860994 CET500432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:14.407860994 CET500432400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:14.412813902 CET24005004387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:14.778969049 CET500442400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:14.784018040 CET24005004487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:14.784125090 CET500442400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:14.787795067 CET500442400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:14.792612076 CET24005004487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:16.386915922 CET24005004487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:16.389945984 CET500442400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:16.389945984 CET500442400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:16.394963026 CET24005004487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:16.747782946 CET500452400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:16.753058910 CET24005004587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:16.753189087 CET500452400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:16.757654905 CET500452400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:16.762584925 CET24005004587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:18.387382030 CET24005004587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:18.387505054 CET500452400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:18.387506008 CET500452400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:18.392456055 CET24005004587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:18.732280970 CET500462400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:18.737237930 CET24005004687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:18.737325907 CET500462400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:18.740653992 CET500462400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:18.745511055 CET24005004687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:20.373851061 CET24005004687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:20.373930931 CET500462400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:20.373975039 CET500462400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:20.379355907 CET24005004687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:20.716590881 CET500472400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:20.721813917 CET24005004787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:20.721913099 CET500472400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:20.725615025 CET500472400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:20.730515957 CET24005004787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:22.357832909 CET24005004787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:22.357907057 CET500472400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:22.357949972 CET500472400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:22.362857103 CET24005004787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:22.685194969 CET500482400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:22.690181017 CET24005004887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:22.690296888 CET500482400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:22.693368912 CET500482400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:22.698165894 CET24005004887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:24.308871031 CET24005004887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:24.308993101 CET500482400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:24.309086084 CET500482400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:24.314014912 CET24005004887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:24.622760057 CET500492400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:24.627739906 CET24005004987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:24.627844095 CET500492400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:24.631268024 CET500492400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:24.636033058 CET24005004987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:26.267839909 CET24005004987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:26.268063068 CET500492400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:26.268063068 CET500492400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:26.273015022 CET24005004987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:26.575980902 CET500502400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:26.580981970 CET24005005087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:26.581059933 CET500502400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:26.584379911 CET500502400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:26.589261055 CET24005005087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:28.202774048 CET24005005087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:28.206759930 CET500502400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:28.206799984 CET500502400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:28.212609053 CET24005005087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:28.521972895 CET500512400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:28.527053118 CET24005005187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:28.529779911 CET500512400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:28.532515049 CET500512400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:28.537370920 CET24005005187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:30.158761024 CET24005005187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:30.159007072 CET500512400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:30.159091949 CET500512400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:30.163970947 CET24005005187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:30.451181889 CET500522400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:30.456335068 CET24005005287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:30.456413031 CET500522400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:30.459131002 CET500522400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:30.464034081 CET24005005287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:32.075325966 CET24005005287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:32.075397015 CET500522400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:32.075489998 CET500522400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:32.080204964 CET24005005287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:32.357075930 CET500532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:32.362011909 CET24005005387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:32.362086058 CET500532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:32.365323067 CET500532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:32.370141029 CET24005005387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:33.982827902 CET24005005387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:33.982978106 CET500532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:33.985513926 CET500532400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:33.990245104 CET24005005387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:34.247692108 CET500542400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:34.252532005 CET24005005487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:34.252597094 CET500542400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:34.257028103 CET500542400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:34.261838913 CET24005005487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:35.893475056 CET24005005487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:35.893549919 CET500542400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:35.893696070 CET500542400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:35.898463964 CET24005005487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:36.154032946 CET500552400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:36.159101009 CET24005005587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:36.159195900 CET500552400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:36.162338018 CET500552400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:36.167211056 CET24005005587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:37.780138016 CET24005005587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:37.780203104 CET500552400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:37.780292034 CET500552400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:37.785137892 CET24005005587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:38.028949976 CET500562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:38.033977985 CET24005005687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:38.034056902 CET500562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:38.037231922 CET500562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:38.042032957 CET24005005687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:39.763019085 CET24005005687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:39.763135910 CET500562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:39.763278961 CET500562400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:39.768104076 CET24005005687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:39.997901917 CET500572400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:40.002899885 CET24005005787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:40.002996922 CET500572400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:40.027204990 CET500572400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:40.032192945 CET24005005787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:41.622622013 CET24005005787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:41.622806072 CET500572400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:41.622848034 CET500572400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:41.627795935 CET24005005787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:41.857528925 CET500582400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:41.862818956 CET24005005887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:41.862903118 CET500582400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:41.867451906 CET500582400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:41.872369051 CET24005005887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:43.481548071 CET24005005887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:43.481631994 CET500582400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:43.481728077 CET500582400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:43.486515999 CET24005005887.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:43.701050043 CET500592400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:43.706279039 CET24005005987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:43.706572056 CET500592400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:43.711221933 CET500592400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:43.716084003 CET24005005987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:45.326790094 CET24005005987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:45.327929020 CET500592400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:45.327929020 CET500592400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:45.332947969 CET24005005987.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:45.544681072 CET500602400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:45.549720049 CET24005006087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:45.551800966 CET500602400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:45.583885908 CET500602400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:45.588820934 CET24005006087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:47.168848991 CET24005006087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:47.168931007 CET500602400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:47.168988943 CET500602400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:47.173877001 CET24005006087.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:47.388330936 CET500612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:47.393177986 CET24005006187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:47.395811081 CET500612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:47.398612976 CET500612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:47.403495073 CET24005006187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:48.992875099 CET24005006187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:48.993020058 CET500612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:48.993072987 CET500612400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:48.998028040 CET24005006187.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:49.201406956 CET500622400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:49.206449032 CET24005006287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:49.206540108 CET500622400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:49.209678888 CET500622400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:49.214576006 CET24005006287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:50.825323105 CET24005006287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:50.825416088 CET500622400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:50.825562954 CET500622400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:50.830405951 CET24005006287.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:51.038552999 CET500632400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:51.043641090 CET24005006387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:51.043813944 CET500632400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:51.085232973 CET500632400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:51.090101004 CET24005006387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:52.690262079 CET24005006387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:52.690342903 CET500632400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:52.690411091 CET500632400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:52.695288897 CET24005006387.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:52.888410091 CET500642400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:52.893672943 CET24005006487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:52.895823956 CET500642400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:52.900378942 CET500642400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:52.905347109 CET24005006487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:54.528774977 CET24005006487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:54.528867960 CET500642400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:54.528961897 CET500642400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:54.533875942 CET24005006487.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:54.716695070 CET500652400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:54.721872091 CET24005006587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:54.722026110 CET500652400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:54.724905014 CET500652400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:54.729724884 CET24005006587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:56.399091005 CET24005006587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:56.399161100 CET500652400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:56.399204969 CET500652400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:56.404109955 CET24005006587.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:56.605515003 CET500662400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:56.610723019 CET24005006687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:56.610852003 CET500662400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:56.624476910 CET500662400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:56.629551888 CET24005006687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:58.227781057 CET24005006687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:58.227952003 CET500662400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:58.227952003 CET500662400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:58.233057022 CET24005006687.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:58.404203892 CET500672400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:58.410361052 CET24005006787.120.116.245192.168.2.5
                  Jan 15, 2025 03:54:58.410438061 CET500672400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:58.413337946 CET500672400192.168.2.587.120.116.245
                  Jan 15, 2025 03:54:58.418263912 CET24005006787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:00.032193899 CET24005006787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:00.032291889 CET500672400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:00.032350063 CET500672400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:00.037277937 CET24005006787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:00.200984001 CET500682400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:00.206115007 CET24005006887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:00.206223965 CET500682400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:00.209028006 CET500682400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:00.214072943 CET24005006887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:01.827883005 CET24005006887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:01.831851006 CET500682400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:01.832036018 CET500682400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:01.836822987 CET24005006887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:01.999722004 CET500692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:02.004717112 CET24005006987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:02.004808903 CET500692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:02.041430950 CET500692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:02.046505928 CET24005006987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:03.622179985 CET24005006987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:03.623842955 CET500692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:03.623894930 CET500692400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:03.628665924 CET24005006987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:03.779160023 CET500702400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:03.785923958 CET24005007087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:03.787853956 CET500702400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:03.791026115 CET500702400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:03.797780991 CET24005007087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:05.437798023 CET24005007087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:05.439848900 CET500702400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:05.439909935 CET500702400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:05.444716930 CET24005007087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:05.591481924 CET500712400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:05.596373081 CET24005007187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:05.599836111 CET500712400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:05.603212118 CET500712400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:05.608033895 CET24005007187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:07.212317944 CET24005007187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:07.213988066 CET500712400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:07.213988066 CET500712400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:07.218887091 CET24005007187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:07.357434988 CET500722400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:07.362371922 CET24005007287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:07.366002083 CET500722400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:07.369039059 CET500722400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:07.373780012 CET24005007287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:09.001050949 CET24005007287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:09.003870964 CET500722400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:09.003923893 CET500722400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:09.009092093 CET24005007287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:09.154021025 CET500732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:09.158968925 CET24005007387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:09.159895897 CET500732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:09.162662029 CET500732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:09.167471886 CET24005007387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:10.874296904 CET24005007387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:10.874478102 CET500732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:10.874568939 CET500732400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:10.879697084 CET24005007387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:11.013472080 CET500742400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:11.019763947 CET24005007487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:11.019877911 CET500742400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:11.024640083 CET500742400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:11.030613899 CET24005007487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:12.639420986 CET24005007487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:12.639544964 CET500742400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:12.639635086 CET500742400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:12.644498110 CET24005007487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:12.779350996 CET500752400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:12.784466028 CET24005007587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:12.784571886 CET500752400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:12.788007021 CET500752400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:12.792833090 CET24005007587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:14.389496088 CET24005007587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:14.389715910 CET500752400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:14.389811993 CET500752400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:14.394599915 CET24005007587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:14.513362885 CET500762400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:14.518836021 CET24005007687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:14.518958092 CET500762400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:14.524168015 CET500762400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:14.530190945 CET24005007687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:16.137581110 CET24005007687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:16.137727976 CET500762400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:16.137797117 CET500762400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:16.142611980 CET24005007687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:16.263614893 CET500772400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:16.268656015 CET24005007787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:16.268767118 CET500772400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:16.273442984 CET500772400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:16.278198957 CET24005007787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:17.869096994 CET24005007787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:17.870800972 CET500772400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:17.870871067 CET500772400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:17.875617027 CET24005007787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:17.998106003 CET500782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:18.003195047 CET24005007887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:18.003326893 CET500782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:18.006145954 CET500782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:18.011264086 CET24005007887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:19.622822046 CET24005007887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:19.626173973 CET500782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:19.626174927 CET500782400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:19.631177902 CET24005007887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:19.748030901 CET500792400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:19.753706932 CET24005007987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:19.754786968 CET500792400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:19.758531094 CET500792400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:19.763411045 CET24005007987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:21.391096115 CET24005007987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:21.391704082 CET500792400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:21.391813040 CET500792400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:21.397861958 CET24005007987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:21.513592958 CET500802400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:21.518620968 CET24005008087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:21.524002075 CET500802400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:21.527396917 CET500802400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:21.532255888 CET24005008087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:23.120637894 CET24005008087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:23.122189045 CET500802400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:23.122189045 CET500802400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:23.127031088 CET24005008087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:23.232224941 CET500812400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:23.237108946 CET24005008187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:23.237247944 CET500812400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:23.241126060 CET500812400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:23.245954990 CET24005008187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:24.841757059 CET24005008187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:24.842042923 CET500812400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:24.842042923 CET500812400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:24.847394943 CET24005008187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:24.951096058 CET500822400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:24.959372044 CET24005008287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:24.959948063 CET500822400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:24.963222980 CET500822400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:24.971354008 CET24005008287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:26.582779884 CET24005008287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:26.586077929 CET500822400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:26.586078882 CET500822400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:26.593146086 CET24005008287.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:26.685417891 CET500832400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:26.690844059 CET24005008387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:26.691948891 CET500832400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:26.694700003 CET500832400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:26.699640989 CET24005008387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:28.309597015 CET24005008387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:28.309679985 CET500832400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:28.309765100 CET500832400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:28.315850973 CET24005008387.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:28.404099941 CET500842400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:28.409734011 CET24005008487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:28.409969091 CET500842400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:28.414505005 CET500842400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:28.419281960 CET24005008487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:30.030894995 CET24005008487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:30.031959057 CET500842400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:30.032002926 CET500842400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:30.038157940 CET24005008487.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:30.124927998 CET500852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:30.129956961 CET24005008587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:30.130044937 CET500852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:30.134696007 CET500852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:30.140866995 CET24005008587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:31.767455101 CET24005008587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:31.767565966 CET500852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:31.767769098 CET500852400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:31.772578001 CET24005008587.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:31.857196093 CET500862400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:31.862921953 CET24005008687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:31.863042116 CET500862400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:31.867083073 CET500862400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:31.871897936 CET24005008687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:33.484049082 CET24005008687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:33.487032890 CET500862400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:33.487032890 CET500862400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:33.491924047 CET24005008687.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:33.582772017 CET500872400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:33.587733030 CET24005008787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:33.591948986 CET500872400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:33.594775915 CET500872400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:33.599524975 CET24005008787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:35.219496965 CET24005008787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:35.219589949 CET500872400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:35.219635963 CET500872400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:35.224566936 CET24005008787.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:35.310647964 CET500882400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:35.315835953 CET24005008887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:35.315963030 CET500882400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:35.322700024 CET500882400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:35.327791929 CET24005008887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:36.984747887 CET24005008887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:36.988071918 CET500882400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:36.988071918 CET500882400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:36.993027925 CET24005008887.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:37.075953007 CET500892400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:37.083456039 CET24005008987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:37.083561897 CET500892400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:37.086358070 CET500892400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:37.093367100 CET24005008987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:38.763859034 CET24005008987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:38.763958931 CET500892400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:38.764059067 CET500892400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:38.768958092 CET24005008987.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:38.841721058 CET500902400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:38.847469091 CET24005009087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:38.847569942 CET500902400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:38.850686073 CET500902400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:38.855540991 CET24005009087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:40.519629955 CET24005009087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:40.522010088 CET500902400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:40.522097111 CET500902400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:40.526983976 CET24005009087.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:40.607125044 CET500912400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:40.612328053 CET24005009187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:40.612405062 CET500912400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:40.615199089 CET500912400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:40.620228052 CET24005009187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:42.288414955 CET24005009187.120.116.245192.168.2.5
                  Jan 15, 2025 03:55:42.288746119 CET500912400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:42.288746119 CET500912400192.168.2.587.120.116.245
                  Jan 15, 2025 03:55:42.293729067 CET24005009187.120.116.245192.168.2.5

                  Click to jump to process

                  Click to jump to process

                  Click to dive into process behavior distribution

                  Click to jump to process

                  Target ID:0
                  Start time:21:51:35
                  Start date:14/01/2025
                  Path:C:\Users\user\Desktop\Material Requirments.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Users\user\Desktop\Material Requirments.exe"
                  Imagebase:0xda0000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 00000000.00000002.2075574179.0000000007610000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: Windows_Trojan_Remcos_b296e965, Description: unknown, Source: 00000000.00000002.2070300215.0000000004E69000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                  • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 00000000.00000002.2070300215.0000000004309000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: Windows_Trojan_Remcos_b296e965, Description: unknown, Source: 00000000.00000002.2070300215.0000000004348000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                  Reputation:low
                  Has exited:true

                  Target ID:3
                  Start time:21:51:36
                  Start date:14/01/2025
                  Path:C:\Users\user\Desktop\Material Requirments.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Users\user\Desktop\Material Requirments.exe"
                  Imagebase:0xa40000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 00000003.00000002.2059843569.0000000000FD7000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: Windows_Trojan_Remcos_b296e965, Description: unknown, Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                  • Rule: REMCOS_RAT_variants, Description: unknown, Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                  • Rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM, Description: Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003), Source: 00000003.00000002.2059348662.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                  Reputation:low
                  Has exited:true

                  Target ID:4
                  Start time:21:51:37
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0x4b0000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Antivirus matches:
                  • Detection: 100%, Joe Sandbox ML
                  • Detection: 68%, ReversingLabs
                  • Detection: 78%, Virustotal, Browse
                  Reputation:low
                  Has exited:true

                  Target ID:5
                  Start time:21:51:38
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0x960000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 00000005.00000002.4498595557.00000000010E8000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                  Reputation:low
                  Has exited:false

                  Target ID:6
                  Start time:21:51:49
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0xb10000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  Target ID:7
                  Start time:21:51:50
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0xb70000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 00000007.00000002.2193815642.0000000001397000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                  Reputation:low
                  Has exited:true

                  Target ID:10
                  Start time:21:51:57
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0x7ff632ac0000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  Target ID:11
                  Start time:21:51:58
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0x850000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 0000000B.00000002.2278960559.0000000000E77000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                  Reputation:low
                  Has exited:true

                  Target ID:12
                  Start time:21:52:05
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0xd60000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  Target ID:13
                  Start time:21:52:06
                  Start date:14/01/2025
                  Path:C:\ProgramData\Remcos\remcos.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\ProgramData\Remcos\remcos.exe"
                  Imagebase:0x710000
                  File size:1'005'568 bytes
                  MD5 hash:3A9DA3EDC40736CC832EDED3C389A661
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 0000000D.00000002.2358460692.0000000000EB7000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                  Reputation:low
                  Has exited:true

                  No disassembly