Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe

Overview

General Information

Sample name:1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe
Analysis ID:1591662
MD5:e55c5a3aa16ed38b9d451601f12527f8
SHA1:138dc85fb2f213537d673720b52a2c56e1bb0a21
SHA256:33d5fb4708217397a18bbea3a1e10c07544bb81e642555ff9ae18ffd67c1e436
Tags:base64-decodedexeuser-abuse_ch
Infos:

Detection

XWorm
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected XWorm
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found potential dummy code loops (likely to delay analysis)
Machine Learning detection for sample
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • cleanup
{"C2 url": ["87.120.116.179"], "Port": 1300, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe"}
SourceRuleDescriptionAuthorStrings
1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeJoeSecurity_XWormYara detected XWormJoe Security
    1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exerat_win_xworm_v3Finds XWorm (version XClient, v3) samples based on characteristic stringsSekoia.io
    • 0x6417:$str01: $VB$Local_Port
    • 0x6408:$str02: $VB$Local_Host
    • 0x670c:$str03: get_Jpeg
    • 0x60c7:$str04: get_ServicePack
    • 0x7156:$str05: Select * from AntivirusProduct
    • 0x7354:$str06: PCRestart
    • 0x7368:$str07: shutdown.exe /f /r /t 0
    • 0x741a:$str08: StopReport
    • 0x73f0:$str09: StopDDos
    • 0x74f2:$str10: sendPlugin
    • 0x769e:$str12: -ExecutionPolicy Bypass -File "
    • 0x77c7:$str13: Content-length: 5235
    1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
    • 0x7a34:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
    • 0x7ad1:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
    • 0x7be6:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
    • 0x76e2:$cnc4: POST / HTTP/1.1
    SourceRuleDescriptionAuthorStrings
    00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_XWormYara detected XWormJoe Security
      00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmpMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
      • 0x7834:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
      • 0x78d1:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
      • 0x79e6:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
      • 0x74e2:$cnc4: POST / HTTP/1.1
      Process Memory Space: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe PID: 2676JoeSecurity_XWormYara detected XWormJoe Security
        SourceRuleDescriptionAuthorStrings
        0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpackJoeSecurity_XWormYara detected XWormJoe Security
          0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpackrat_win_xworm_v3Finds XWorm (version XClient, v3) samples based on characteristic stringsSekoia.io
          • 0x6417:$str01: $VB$Local_Port
          • 0x6408:$str02: $VB$Local_Host
          • 0x670c:$str03: get_Jpeg
          • 0x60c7:$str04: get_ServicePack
          • 0x7156:$str05: Select * from AntivirusProduct
          • 0x7354:$str06: PCRestart
          • 0x7368:$str07: shutdown.exe /f /r /t 0
          • 0x741a:$str08: StopReport
          • 0x73f0:$str09: StopDDos
          • 0x74f2:$str10: sendPlugin
          • 0x769e:$str12: -ExecutionPolicy Bypass -File "
          • 0x77c7:$str13: Content-length: 5235
          0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpackMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
          • 0x7a34:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
          • 0x7ad1:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
          • 0x7be6:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
          • 0x76e2:$cnc4: POST / HTTP/1.1
          No Sigma rule has matched
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2025-01-15T09:13:53.806970+010028531931Malware Command and Control Activity Detected192.168.2.45004087.120.116.1791300TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeAvira: detected
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeMalware Configuration Extractor: Xworm {"C2 url": ["87.120.116.179"], "Port": 1300, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe"}
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeVirustotal: Detection: 70%Perma Link
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeJoe Sandbox ML: detected
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeString decryptor: 87.120.116.179
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeString decryptor: 1300
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeString decryptor: <123456789>
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeString decryptor: <Xwormmm>
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeString decryptor: 14-01-25
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeString decryptor: USB.exe
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2855924 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.4:49890 -> 87.120.116.179:1300
          Source: Network trafficSuricata IDS: 2853193 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.4:50040 -> 87.120.116.179:1300
          Source: Malware configuration extractorURLs: 87.120.116.179
          Source: global trafficTCP traffic: 192.168.2.4:49730 -> 87.120.116.179:1300
          Source: Joe Sandbox ViewIP Address: 87.120.116.179 87.120.116.179
          Source: Joe Sandbox ViewASN Name: UNACS-AS-BG8000BurgasBG UNACS-AS-BG8000BurgasBG
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: unknownTCP traffic detected without corresponding DNS query: 87.120.116.179
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145776967.0000000002801000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

          System Summary

          barindex
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, type: SAMPLEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, type: SAMPLEMatched rule: Detects AsyncRAT Author: ditekSHen
          Source: 0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
          Source: 0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
          Source: 00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeCode function: 0_2_00007FFD9B8A67260_2_00007FFD9B8A6726
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeCode function: 0_2_00007FFD9B8A74D20_2_00007FFD9B8A74D2
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000000.1676018881.000000000056C000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamebarsill.exe4 vs 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeBinary or memory string: OriginalFilenamebarsill.exe4 vs 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, type: SAMPLEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, type: SAMPLEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
          Source: 0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
          Source: 0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
          Source: 00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
          Source: classification engineClassification label: mal100.troj.evad.winEXE@1/0@0/1
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeMutant created: NULL
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeMutant created: \Sessions\1\BaseNamedObjects\CKIfAznTYvqcKR6Q
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeVirustotal: Detection: 70%
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: mscoree.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: version.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: wbemcomn.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: amsi.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: avicap32.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: msvfw32.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32Jump to behavior
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeCode function: 0_2_00007FFD9B8A2A14 push eax; iretd 0_2_00007FFD9B8A2A21
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeCode function: 0_2_00007FFD9B8A29D4 pushad ; retf 0_2_00007FFD9B8A29E1
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

          Malware Analysis System Evasion

          barindex
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeMemory allocated: EA0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeMemory allocated: 1A800000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWindow / User API: threadDelayed 643Jump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWindow / User API: threadDelayed 9219Jump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe TID: 5924Thread sleep time: -922337203685477s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe TID: 3624Thread sleep count: 643 > 30Jump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe TID: 3624Thread sleep count: 9219 > 30Jump to behavior
          Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4148045906.000000001B750000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dlleP
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess information queried: ProcessInformationJump to behavior

          Anti Debugging

          barindex
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess Stats: CPU usage > 42% for more than 60s
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeProcess token adjusted: DebugJump to behavior
          Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeMemory allocated: page read and write | page guardJump to behavior
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145776967.0000000002B1A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 'PING!<Xwormmm>Program Manager<Xwormmm>0
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145776967.0000000002B1A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145776967.0000000002B1A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: PING!<Xwormmm>Program Manager<Xwormmm>0
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145776967.0000000002B1A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 'PING!<Xwormmm>Program Manager<Xwormmm>0@
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145776967.0000000002B1A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager2
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeQueries volume information: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
          Source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4148045906.000000001B79E000.00000004.00000020.00020000.00000000.sdmp, 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4148045906.000000001B77B000.00000004.00000020.00020000.00000000.sdmp, 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145238038.00000000009C5000.00000004.00000020.00020000.00000000.sdmp, 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4148045906.000000001B750000.00000004.00000020.00020000.00000000.sdmp, 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145238038.00000000009BC000.00000004.00000020.00020000.00000000.sdmp, 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145238038.0000000000A6F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
          Source: C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe PID: 2676, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe.560000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe PID: 2676, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
          Windows Management Instrumentation
          1
          DLL Side-Loading
          1
          Process Injection
          1
          Disable or Modify Tools
          OS Credential Dumping221
          Security Software Discovery
          Remote Services1
          Archive Collected Data
          1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
          DLL Side-Loading
          232
          Virtualization/Sandbox Evasion
          LSASS Memory2
          Process Discovery
          Remote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
          Process Injection
          Security Account Manager232
          Virtualization/Sandbox Evasion
          SMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
          Obfuscated Files or Information
          NTDS1
          Application Window Discovery
          Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
          DLL Side-Loading
          LSA Secrets13
          System Information Discovery
          SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe70%VirustotalBrowse
          1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe100%AviraTR/Spy.Gen
          1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          SourceDetectionScannerLabelLink
          87.120.116.1790%Avira URL Cloudsafe
          No contacted domains info
          NameMaliciousAntivirus DetectionReputation
          87.120.116.179true
          • Avira URL Cloud: safe
          unknown
          NameSourceMaliciousAntivirus DetectionReputation
          http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe, 00000000.00000002.4145776967.0000000002801000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            87.120.116.179
            unknownBulgaria
            25206UNACS-AS-BG8000BurgasBGtrue
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1591662
            Start date and time:2025-01-15 09:10:32 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 6m 18s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:5
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe
            Detection:MAL
            Classification:mal100.troj.evad.winEXE@1/0@0/1
            EGA Information:
            • Successful, ratio: 100%
            HCA Information:
            • Successful, ratio: 98%
            • Number of executed functions: 3
            • Number of non-executed functions: 0
            Cookbook Comments:
            • Found application associated with file extension: .exe
            • Override analysis time to 240000 for current running targets taking high CPU consumption
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
            • Excluded IPs from analysis (whitelisted): 4.245.163.56, 13.107.246.45
            • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenKeyEx calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            TimeTypeDescription
            03:11:25API Interceptor14635907x Sleep call for process: 1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe modified
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            87.120.116.17917364916859ea2c227941e63335bcf02a749f58a3f6d7a5fc5312d32a2ea1c4a4cc26022a4160.dat-decoded.exeGet hashmaliciousXWormBrowse
              17363482243fcf48f1d103ef5a4702c871424ad69b9eb7d3f5e5957f5c4810f2a51fea8e76776.dat-decoded.exeGet hashmaliciousXWormBrowse
                17363364631bc7418009f735fbf6670730f0df5be418dd7fb7bf7e79b36349f3b17d812142896.dat-decoded.exeGet hashmaliciousXWormBrowse
                  173349054689897a42ce4a1face346760a1e1ea6ee459f1c43651627f7c7690c5adf7c1298500.dat-decoded.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                    173347741090e23c9ebd2c4b604c71623763cbce99aec650e3f9e27d35f4f3dcf6f1064415652.dat-decoded.exeGet hashmaliciousXWormBrowse
                      1733477410ba2e5b8e1739578ed6933c4e69d66a81049f523c11599f36b2f5da870a31538a881.dat-decoded.exeGet hashmaliciousXWormBrowse
                        17334774117b7343420a7b9efab7c5b1abd0627c7af1c91f9947163684497ce841bf5f9198533.dat-decoded.exeGet hashmaliciousXWormBrowse
                          17334769266ba75a70859e94894e9fae5c33bba300e2b004c1166d236dc1ab2c8ff5669916631.dat-decoded.exeGet hashmaliciousXWormBrowse
                            No context
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            UNACS-AS-BG8000BurgasBGOrder Drawing.exeGet hashmaliciousRemcos, PureLog StealerBrowse
                            • 87.120.116.245
                            Material Requirments.exeGet hashmaliciousRemcos, PureLog StealerBrowse
                            • 87.120.116.245
                            preliminary drawing.pif.exeGet hashmaliciousRemcos, PureLog StealerBrowse
                            • 87.120.127.120
                            5tCuNr661k.exeGet hashmaliciousRedLineBrowse
                            • 87.120.120.86
                            5tCuNr661k.exeGet hashmaliciousRedLineBrowse
                            • 87.120.120.86
                            shaLnqmyTS.exeGet hashmaliciousRedLineBrowse
                            • 87.120.120.86
                            shaLnqmyTS.exeGet hashmaliciousRedLineBrowse
                            • 87.120.120.86
                            zAGUEDGSTM.exeGet hashmaliciousRedLineBrowse
                            • 87.120.120.86
                            WtZl31OLfA.exeGet hashmaliciousRemcos, GuLoaderBrowse
                            • 87.120.116.187
                            C5Zr4LSzmp.exeGet hashmaliciousRedLineBrowse
                            • 87.120.120.86
                            No context
                            No context
                            No created / dropped files found
                            File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                            Entropy (8bit):5.61029561035472
                            TrID:
                            • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                            • Win32 Executable (generic) a (10002005/4) 49.75%
                            • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                            • Windows Screen Saver (13104/52) 0.07%
                            • Generic Win/DOS Executable (2004/3) 0.01%
                            File name:1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe
                            File size:36'864 bytes
                            MD5:e55c5a3aa16ed38b9d451601f12527f8
                            SHA1:138dc85fb2f213537d673720b52a2c56e1bb0a21
                            SHA256:33d5fb4708217397a18bbea3a1e10c07544bb81e642555ff9ae18ffd67c1e436
                            SHA512:a6cc4101f5c96c1c1caeee4a9559d6dd5a854ad94fa3716ddbb582f551a0efe65ffd38a5949edab28bcdc1bedce1a02fc8770fecdd518389c5ec8690c6418f9a
                            SSDEEP:768:sL13A5Uno9RfHWa2B71eo8icH1bxbFb9EcOMh2iQXvq7G:axA5Uno9JHWXZeNicH1bBFb9EcOMh6c
                            TLSH:1BF24C48BBE04216D9ED6BF5A97372020674EA13D917EB4E4CD486D76F23BC48D013EA
                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+~.g................................. ........@.. ....................................@................................
                            Icon Hash:90cececece8e8eb0
                            Entrypoint:0x40a5ee
                            Entrypoint Section:.text
                            Digitally signed:false
                            Imagebase:0x400000
                            Subsystem:windows gui
                            Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                            Time Stamp:0x67867E2B [Tue Jan 14 15:09:31 2025 UTC]
                            TLS Callbacks:
                            CLR (.Net) Version:
                            OS Version Major:4
                            OS Version Minor:0
                            File Version Major:4
                            File Version Minor:0
                            Subsystem Version Major:4
                            Subsystem Version Minor:0
                            Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                            Instruction
                            jmp dword ptr [00402000h]
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            NameVirtual AddressVirtual Size Is in Section
                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_IMPORT0xa5940x57.text
                            IMAGE_DIRECTORY_ENTRY_RESOURCE0xc0000x4d8.rsrc
                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                            IMAGE_DIRECTORY_ENTRY_BASERELOC0xe0000xc.reloc
                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                            .text0x20000x85f40x8600429e81b8d907e20edb5fdf52b0b36a8bFalse0.49900886194029853data5.746024050874507IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                            .rsrc0xc0000x4d80x6006a547f450a0f60a48827df85c9b55492False0.373046875data3.7131519772371093IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                            .reloc0xe0000xc0x200fd3ac7fbb8a34dc91e775b7c64e87bbcFalse0.044921875data0.08153941234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                            NameRVASizeTypeLanguageCountryZLIB Complexity
                            RT_VERSION0xc0a00x244data0.4689655172413793
                            RT_MANIFEST0xc2e80x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5469387755102041
                            DLLImport
                            mscoree.dll_CorExeMain
                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                            2025-01-15T09:12:43.622709+01002855924ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound1192.168.2.44989087.120.116.1791300TCP
                            2025-01-15T09:13:53.806970+01002853193ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound1192.168.2.45004087.120.116.1791300TCP
                            TimestampSource PortDest PortSource IPDest IP
                            Jan 15, 2025 09:11:27.372426033 CET497301300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:27.378460884 CET13004973087.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:27.378551006 CET497301300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:27.554054022 CET497301300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:27.558979034 CET13004973087.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:28.991770029 CET13004973087.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:28.991851091 CET497301300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:31.126369953 CET497301300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:31.129329920 CET497311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:31.131396055 CET13004973087.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:31.134196997 CET13004973187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:31.134284973 CET497311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:31.166663885 CET497311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:31.171686888 CET13004973187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:32.757523060 CET13004973187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:32.757591963 CET497311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:34.478657007 CET497311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:34.481096029 CET497321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:34.484090090 CET13004973187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:34.486813068 CET13004973287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:34.486881971 CET497321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:34.599781036 CET497321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:34.607364893 CET13004973287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:36.101310968 CET13004973287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:36.101475000 CET497321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:40.102502108 CET497321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:40.105511904 CET497331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:40.107400894 CET13004973287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:40.110323906 CET13004973387.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:40.110393047 CET497331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:40.142272949 CET497331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:40.147046089 CET13004973387.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:41.727771044 CET13004973387.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:41.727833033 CET497331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:43.462066889 CET497331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:43.464976072 CET497391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:43.466957092 CET13004973387.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:43.469855070 CET13004973987.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:43.469968081 CET497391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:43.490180016 CET497391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:43.495085001 CET13004973987.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:45.087687969 CET13004973987.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:45.087785959 CET497391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:46.760505915 CET497391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:46.763087034 CET497411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:46.765521049 CET13004973987.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:46.768079996 CET13004974187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:46.768148899 CET497411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:46.818254948 CET497411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:46.823156118 CET13004974187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:48.400130033 CET13004974187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:48.400332928 CET497411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:51.055583954 CET497411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:51.056344986 CET497421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:51.191715956 CET13004974187.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:51.191735983 CET13004974287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:51.191910028 CET497421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:51.209347010 CET497421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:51.215473890 CET13004974287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:52.836618900 CET13004974287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:52.836757898 CET497421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:55.774369955 CET497421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:55.776415110 CET497431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:55.779469013 CET13004974287.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:55.781332016 CET13004974387.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:55.781414986 CET497431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:55.877687931 CET497431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:11:55.882630110 CET13004974387.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:57.418489933 CET13004974387.120.116.179192.168.2.4
                            Jan 15, 2025 09:11:57.418561935 CET497431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:00.227720022 CET497431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:00.228693962 CET497441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:00.232695103 CET13004974387.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:00.233647108 CET13004974487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:00.233753920 CET497441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:00.248869896 CET497441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:00.253823996 CET13004974487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:01.836678028 CET13004974487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:01.837066889 CET497441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:04.086918116 CET497441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:04.087646961 CET497451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:04.092056036 CET13004974487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:04.092581034 CET13004974587.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:04.092670918 CET497451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:04.108171940 CET497451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:04.113097906 CET13004974587.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:05.712301016 CET13004974587.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:05.715404034 CET497451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:07.211812973 CET497451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:07.213484049 CET497461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:07.216819048 CET13004974587.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:07.218379021 CET13004974687.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:07.218455076 CET497461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:07.235232115 CET497461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:07.240144014 CET13004974687.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:08.857494116 CET13004974687.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:08.857595921 CET497461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:10.055562019 CET497461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:10.056494951 CET497471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:10.060460091 CET13004974687.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:10.061408997 CET13004974787.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:10.061503887 CET497471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:10.077805042 CET497471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:10.082772017 CET13004974787.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:11.663978100 CET13004974787.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:11.664081097 CET497471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:13.024411917 CET497471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:13.025238037 CET497481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:13.029299021 CET13004974787.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:13.030034065 CET13004974887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:13.031343937 CET497481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:13.049294949 CET497481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:13.054116964 CET13004974887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:14.649755001 CET13004974887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:14.650041103 CET497481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:15.711850882 CET497481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:15.712624073 CET497491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:15.716844082 CET13004974887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:15.717519045 CET13004974987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:15.717617989 CET497491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:15.733208895 CET497491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:15.738274097 CET13004974987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:17.321326971 CET13004974987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:17.321402073 CET497491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:17.853326082 CET497491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:17.854227066 CET497501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:17.858289003 CET13004974987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:17.859126091 CET13004975087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:17.859189034 CET497501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:17.875582933 CET497501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:17.880482912 CET13004975087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:19.491477013 CET13004975087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:19.491673946 CET497501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:19.493117094 CET497501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:19.493957996 CET497521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:19.499443054 CET13004975087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:19.499455929 CET13004975287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:19.499528885 CET497521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:19.515995979 CET497521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:19.521194935 CET13004975287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:21.121891022 CET13004975287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:21.122006893 CET497521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:21.930711031 CET497521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:21.931535959 CET497591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:21.938808918 CET13004975287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:21.939742088 CET13004975987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:21.945319891 CET497591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:21.956599951 CET497591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:21.964807987 CET13004975987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:23.555277109 CET13004975987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:23.555721998 CET497591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:23.621656895 CET497591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:23.623259068 CET497701300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:23.626519918 CET13004975987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:23.628412962 CET13004977087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:23.628499985 CET497701300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:23.647238016 CET497701300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:23.652173042 CET13004977087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:25.225086927 CET13004977087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:25.225220919 CET497701300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:25.462804079 CET497701300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:25.464334965 CET497811300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:25.468173027 CET13004977087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:25.469616890 CET13004978187.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:25.469840050 CET497811300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:25.496517897 CET497811300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:25.501558065 CET13004978187.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:27.086467981 CET13004978187.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:27.086534023 CET497811300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:27.086916924 CET497811300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:27.087747097 CET497921300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:27.091722965 CET13004978187.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:27.092490911 CET13004979287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:27.092567921 CET497921300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:27.108274937 CET497921300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:27.113025904 CET13004979287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:28.692400932 CET13004979287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:28.694753885 CET497921300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:28.696317911 CET497921300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:28.698059082 CET498031300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:28.701400042 CET13004979287.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:28.702874899 CET13004980387.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:28.702976942 CET498031300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:28.737596035 CET498031300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:28.742733002 CET13004980387.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:30.325632095 CET13004980387.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:30.326153994 CET498031300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:30.326242924 CET498031300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:30.328021049 CET498141300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:30.331126928 CET13004980387.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:30.332969904 CET13004981487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:30.333093882 CET498141300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:30.347276926 CET498141300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:30.352200985 CET13004981487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:31.965558052 CET13004981487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:31.965619087 CET498141300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:35.789272070 CET498141300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:35.793149948 CET498491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:35.794249058 CET13004981487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:35.798152924 CET13004984987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:35.798230886 CET498491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:36.517352104 CET498491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:36.522150040 CET13004984987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:37.398272038 CET13004984987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:37.398371935 CET498491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:41.950855970 CET498491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:41.955705881 CET13004984987.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:42.010380030 CET498901300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:42.016522884 CET13004989087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:42.016619921 CET498901300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:42.654637098 CET498901300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:42.659574032 CET13004989087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:43.622709036 CET498901300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:43.627727032 CET13004989087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:43.635324955 CET13004989087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:43.635379076 CET498901300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.727534056 CET498901300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.728871107 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.732486010 CET13004989087.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:47.733700991 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:47.733809948 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.772983074 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.777801991 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:47.790491104 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.795373917 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:47.806421041 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.811196089 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:47.821744919 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.827415943 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:47.977875948 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:47.982773066 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:49.317513943 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:49.320544958 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:53.089401007 CET499281300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:53.089401960 CET499641300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:53.094532013 CET13004992887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:53.094577074 CET13004996487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:53.095474958 CET499641300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:53.241395950 CET499641300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:53.246440887 CET13004996487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:54.712706089 CET13004996487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:54.713529110 CET499641300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:58.321788073 CET499641300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:58.324400902 CET499981300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:58.328712940 CET13004996487.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:58.331233025 CET13004999887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:58.331293106 CET499981300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:58.368153095 CET499981300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:58.373022079 CET13004999887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:58.416203022 CET499981300192.168.2.487.120.116.179
                            Jan 15, 2025 09:12:58.421117067 CET13004999887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:59.931384087 CET13004999887.120.116.179192.168.2.4
                            Jan 15, 2025 09:12:59.931444883 CET499981300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:03.587595940 CET499981300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:03.590637922 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:03.592523098 CET13004999887.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:03.595489025 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:03.595551968 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:03.963692904 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:03.968868017 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:04.009154081 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:04.014167070 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:04.134047031 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:04.139098883 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:04.149833918 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:04.154644966 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:04.165210962 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:04.170073986 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:05.228374958 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:05.231388092 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:09.165225029 CET500311300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:09.169452906 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:09.170222044 CET13005003187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:09.174474955 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:09.174679995 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:09.510845900 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:09.515654087 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:09.590082884 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:09.595005989 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.024661064 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.029604912 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.040281057 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.045097113 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.071686983 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.076580048 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.102854013 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.107781887 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.149866104 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.154782057 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.196680069 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.201777935 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.274775028 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.279818058 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.368717909 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.373833895 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.477782011 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:10.482846022 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.810404062 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:10.810484886 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:15.528569937 CET500321300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:15.533646107 CET13005003287.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:15.598206997 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:15.603218079 CET13005003387.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:15.603301048 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:15.707066059 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:15.711927891 CET13005003387.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:15.899887085 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:15.904994965 CET13005003387.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:16.071846008 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:16.077069044 CET13005003387.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:16.118916988 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:16.124059916 CET13005003387.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:17.214648008 CET13005003387.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:17.214946985 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:21.165808916 CET500331300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:21.166963100 CET500341300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:21.170793056 CET13005003387.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:21.171989918 CET13005003487.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:21.172059059 CET500341300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:21.676728010 CET500341300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:21.681693077 CET13005003487.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:22.009017944 CET500341300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:22.014447927 CET13005003487.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:22.795185089 CET13005003487.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:22.795608044 CET500341300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:27.041676998 CET500341300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:27.043875933 CET500351300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:27.046571970 CET13005003487.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:27.048691988 CET13005003587.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:27.048778057 CET500351300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:27.128488064 CET500351300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:27.133514881 CET13005003587.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:28.667704105 CET13005003587.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:28.668138027 CET500351300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:32.446404934 CET500351300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:32.448735952 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:32.451380014 CET13005003587.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:32.453620911 CET13005003687.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:32.453680992 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:32.483774900 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:32.488663912 CET13005003687.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:32.508966923 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:32.513839006 CET13005003687.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:32.587188005 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:32.592155933 CET13005003687.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:33.153486967 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:33.158356905 CET13005003687.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:34.074103117 CET13005003687.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:34.074158907 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.633907080 CET500361300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.638801098 CET13005003687.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.639056921 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.643958092 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.644025087 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.701888084 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.706998110 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.712184906 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.717081070 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.790556908 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.795558929 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.899947882 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.905227900 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.931267023 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.936439991 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.946702003 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.951617956 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:37.962522984 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:37.967444897 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:38.118571043 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:38.124499083 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:38.134293079 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:38.139246941 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:38.166065931 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:38.171192884 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:38.196597099 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:38.201925993 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:39.262011051 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:39.265594959 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:43.213042021 CET500371300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:43.213043928 CET500381300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:43.217875004 CET13005003787.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:43.217896938 CET13005003887.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:43.221673965 CET500381300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:43.295964956 CET500381300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:43.300812960 CET13005003887.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:44.818599939 CET13005003887.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:44.825542927 CET500381300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.415252924 CET500381300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.417439938 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.420192957 CET13005003887.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:48.422350883 CET13005003987.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:48.422472954 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.454458952 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.459347010 CET13005003987.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:48.571595907 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.576392889 CET13005003987.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:48.587323904 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.592088938 CET13005003987.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:48.602776051 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:48.607629061 CET13005003987.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:50.045017004 CET13005003987.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:50.045120001 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.743345022 CET500391300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.745790005 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.748260975 CET13005003987.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.750577927 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.750627041 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.784024000 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.788794041 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.806969881 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.811800957 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.931050062 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.937516928 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.946527004 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.951355934 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.962106943 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.966900110 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.977891922 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.993199110 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:53.993627071 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:53.998424053 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:55.373446941 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:55.379534960 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:59.008913994 CET500401300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:59.013931990 CET13005004087.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:59.019378901 CET500411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:59.024282932 CET13005004187.120.116.179192.168.2.4
                            Jan 15, 2025 09:13:59.024502993 CET500411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:59.100131035 CET500411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:13:59.105037928 CET13005004187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:00.656188011 CET13005004187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:00.656259060 CET500411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:04.337244987 CET500411300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:04.340270042 CET500421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:04.342097044 CET13005004187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:04.345119953 CET13005004287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:04.345177889 CET500421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:04.377809048 CET500421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:04.382575989 CET13005004287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:05.915486097 CET500421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:05.920267105 CET13005004287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:05.964879036 CET13005004287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:05.964930058 CET500421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:09.451441050 CET500421300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:09.453535080 CET500431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:09.456248045 CET13005004287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:09.458405972 CET13005004387.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:09.459345102 CET500431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:09.553527117 CET500431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:09.558377028 CET13005004387.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:11.097469091 CET13005004387.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:11.097616911 CET500431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:14.572071075 CET500431300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:14.574270010 CET500441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:14.576958895 CET13005004387.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:14.579134941 CET13005004487.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:14.579188108 CET500441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:14.622627974 CET500441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:14.627712965 CET13005004487.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:14.650012970 CET500441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:14.655163050 CET13005004487.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:16.215631008 CET13005004487.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:16.215718985 CET500441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:19.884226084 CET500441300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:19.886231899 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:19.889121056 CET13005004487.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:19.891092062 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:19.891155958 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:19.926075935 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:19.930946112 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:20.009244919 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:20.014203072 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:20.040551901 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:20.045588017 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:20.149877071 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:20.155119896 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:20.165575027 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:20.170368910 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:20.196850061 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:20.201797962 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:20.212332964 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:20.217251062 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:21.510719061 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:21.513628960 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:25.246085882 CET500461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:25.246088982 CET500451300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:25.251101017 CET13005004687.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:25.251219034 CET500461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:25.251251936 CET13005004587.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:25.397547007 CET500461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:25.402715921 CET13005004687.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:25.416037083 CET500461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:25.420993090 CET13005004687.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:26.852793932 CET13005004687.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:26.852864027 CET500461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.431322098 CET500461300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.433958054 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.436289072 CET13005004687.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:30.438792944 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:30.438847065 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.478857994 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.483864069 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:30.509377956 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.514410019 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:30.524734020 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.529565096 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:30.571938038 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.576816082 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:30.587471008 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:30.592339039 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:32.075443983 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:32.075537920 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:35.628585100 CET500471300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:35.631489992 CET500481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:35.633541107 CET13005004787.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:35.636425018 CET13005004887.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:35.640127897 CET500481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:35.772634029 CET500481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:35.777564049 CET13005004887.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:37.262543917 CET13005004887.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:37.267666101 CET500481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:40.899627924 CET500481300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:40.901622057 CET500491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:40.904521942 CET13005004887.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:40.906512022 CET13005004987.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:40.906608105 CET500491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:40.993453979 CET500491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:41.003720999 CET13005004987.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:41.181613922 CET500491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:41.186614990 CET13005004987.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:42.526614904 CET13005004987.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:42.526691914 CET500491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.587189913 CET500491300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.589759111 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.592358112 CET13005004987.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:46.594676018 CET13005005087.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:46.594733953 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.624795914 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.629736900 CET13005005087.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:46.634140968 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.639015913 CET13005005087.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:46.649909019 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.654690027 CET13005005087.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:46.665425062 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:46.670316935 CET13005005087.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:48.198998928 CET13005005087.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:48.199062109 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:51.665616989 CET500501300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:51.669635057 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:51.670603037 CET13005005087.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:51.674573898 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:51.674757957 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:52.027767897 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:52.032778978 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:52.259303093 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:52.264374018 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:52.274844885 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:52.279740095 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:52.290482044 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:52.295346022 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:52.353164911 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:52.358098984 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:53.327795029 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:53.328502893 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:57.417649984 CET500511300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:57.417678118 CET500521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:57.423029900 CET13005005187.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:57.423063993 CET13005005287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:57.423213005 CET500521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:57.633774042 CET500521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:14:57.638775110 CET13005005287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:59.058588982 CET13005005287.120.116.179192.168.2.4
                            Jan 15, 2025 09:14:59.061748028 CET500521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:02.665721893 CET500521300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:02.669795990 CET500531300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:02.670763016 CET13005005287.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:02.674724102 CET13005005387.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:02.674787045 CET500531300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:02.942900896 CET500531300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:02.948539972 CET13005005387.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:04.309691906 CET13005005387.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:04.309753895 CET500531300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:08.509079933 CET500531300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:08.510853052 CET500541300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:08.514225960 CET13005005387.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:08.515783072 CET13005005487.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:08.515839100 CET500541300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:08.546190977 CET500541300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:08.551194906 CET13005005487.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:10.118868113 CET13005005487.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:10.118935108 CET500541300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:13.557837009 CET500541300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:13.566327095 CET13005005487.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:13.624083996 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:13.632549047 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:13.633188009 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:13.889065981 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:13.894709110 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:14.009272099 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:14.014209032 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:14.087404966 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:14.092749119 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:14.166090012 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:14.170964956 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:14.196923018 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:14.201792955 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:14.212555885 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:14.217406034 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:14.243714094 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:14.248610020 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:15.248158932 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:15.248402119 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:19.263015985 CET500551300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:19.268578053 CET13005005587.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:19.279263020 CET500561300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:19.284738064 CET13005005687.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:19.285535097 CET500561300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:19.629690886 CET500561300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:19.635418892 CET13005005687.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:19.713120937 CET500561300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:19.718296051 CET13005005687.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:20.887458086 CET13005005687.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:20.888365030 CET500561300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:24.809166908 CET500561300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:24.811681032 CET500571300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:24.814116955 CET13005005687.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:24.816596031 CET13005005787.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:24.816664934 CET500571300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:24.901710033 CET500571300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:24.906640053 CET13005005787.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:26.435930014 CET13005005787.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:26.436027050 CET500571300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.165416956 CET500571300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.167146921 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.170470953 CET13005005787.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:30.172113895 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:30.172179937 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.202174902 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.207076073 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:30.431210041 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.436106920 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:30.446728945 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.451787949 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:30.478005886 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.482943058 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:30.509265900 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:30.514208078 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:31.212764025 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:31.217854023 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:31.830063105 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:31.836990118 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:36.212246895 CET500581300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:36.212825060 CET500591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:36.217237949 CET13005005887.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:36.217700005 CET13005005987.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:36.217766047 CET500591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:36.245088100 CET500591300192.168.2.487.120.116.179
                            Jan 15, 2025 09:15:36.250811100 CET13005005987.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:37.824892044 CET13005005987.120.116.179192.168.2.4
                            Jan 15, 2025 09:15:37.832911968 CET500591300192.168.2.487.120.116.179

                            Click to jump to process

                            Click to jump to process

                            Click to dive into process behavior distribution

                            Target ID:0
                            Start time:03:11:22
                            Start date:15/01/2025
                            Path:C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Users\user\Desktop\1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac1388894.dat-decoded.exe"
                            Imagebase:0x560000
                            File size:36'864 bytes
                            MD5 hash:E55C5A3AA16ED38B9D451601F12527F8
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Yara matches:
                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: 00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                            • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: 00000000.00000000.1675986502.0000000000562000.00000002.00000001.01000000.00000003.sdmp, Author: ditekSHen
                            Reputation:low
                            Has exited:false

                            Reset < >

                              Execution Graph

                              Execution Coverage:20.3%
                              Dynamic/Decrypted Code Coverage:100%
                              Signature Coverage:0%
                              Total number of Nodes:3
                              Total number of Limit Nodes:0
                              execution_graph 3411 7ffd9b8a1bf8 3412 7ffd9b8a1c01 SetWindowsHookExW 3411->3412 3414 7ffd9b8a1cd1 3412->3414

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 30 7ffd9b8a6726-7ffd9b8a6733 31 7ffd9b8a6735-7ffd9b8a673d 30->31 32 7ffd9b8a673e-7ffd9b8a6807 30->32 31->32 36 7ffd9b8a6809-7ffd9b8a6812 32->36 37 7ffd9b8a6873 32->37 36->37 39 7ffd9b8a6814-7ffd9b8a6820 36->39 38 7ffd9b8a6875-7ffd9b8a689a 37->38 46 7ffd9b8a6906 38->46 47 7ffd9b8a689c-7ffd9b8a68a5 38->47 40 7ffd9b8a6859-7ffd9b8a6871 39->40 41 7ffd9b8a6822-7ffd9b8a6834 39->41 40->38 42 7ffd9b8a6836 41->42 43 7ffd9b8a6838-7ffd9b8a684b 41->43 42->43 43->43 45 7ffd9b8a684d-7ffd9b8a6855 43->45 45->40 48 7ffd9b8a6908-7ffd9b8a69b0 46->48 47->46 49 7ffd9b8a68a7-7ffd9b8a68b3 47->49 60 7ffd9b8a6a1e 48->60 61 7ffd9b8a69b2-7ffd9b8a69bc 48->61 50 7ffd9b8a68b5-7ffd9b8a68c7 49->50 51 7ffd9b8a68ec-7ffd9b8a6904 49->51 53 7ffd9b8a68c9 50->53 54 7ffd9b8a68cb-7ffd9b8a68de 50->54 51->48 53->54 54->54 56 7ffd9b8a68e0-7ffd9b8a68e8 54->56 56->51 62 7ffd9b8a6a20-7ffd9b8a6a49 60->62 61->60 63 7ffd9b8a69be-7ffd9b8a69cb 61->63 69 7ffd9b8a6a4b-7ffd9b8a6a56 62->69 70 7ffd9b8a6ab3 62->70 64 7ffd9b8a69cd-7ffd9b8a69df 63->64 65 7ffd9b8a6a04-7ffd9b8a6a1c 63->65 67 7ffd9b8a69e1 64->67 68 7ffd9b8a69e3-7ffd9b8a69f6 64->68 65->62 67->68 68->68 71 7ffd9b8a69f8-7ffd9b8a6a00 68->71 69->70 72 7ffd9b8a6a58-7ffd9b8a6a66 69->72 73 7ffd9b8a6ab5-7ffd9b8a6b46 70->73 71->65 74 7ffd9b8a6a68-7ffd9b8a6a7a 72->74 75 7ffd9b8a6a9f-7ffd9b8a6ab1 72->75 81 7ffd9b8a6b4c-7ffd9b8a6b5b 73->81 76 7ffd9b8a6a7c 74->76 77 7ffd9b8a6a7e-7ffd9b8a6a91 74->77 75->73 76->77 77->77 79 7ffd9b8a6a93-7ffd9b8a6a9b 77->79 79->75 82 7ffd9b8a6b5d 81->82 83 7ffd9b8a6b63-7ffd9b8a6bc8 call 7ffd9b8a6be4 81->83 82->83 90 7ffd9b8a6bca 83->90 91 7ffd9b8a6bcf-7ffd9b8a6be3 83->91 90->91
                              Memory Dump Source
                              • Source File: 00000000.00000002.4149638068.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ffd9b8a0000_1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: c6633061daf9e1dd4fdc6a1b05dfc4f07d3191543cb28b16872bcb337d804d14
                              • Instruction ID: 19a20560a361c85f3dce29a3cccbcfc23f7570aada45f485287f230df342d1d7
                              • Opcode Fuzzy Hash: c6633061daf9e1dd4fdc6a1b05dfc4f07d3191543cb28b16872bcb337d804d14
                              • Instruction Fuzzy Hash: 1BF1D970A0DA8D8FEBA8DF28C8557E977E1FF58310F04426ED84DC7295DB34A9458B81

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 92 7ffd9b8a74d2-7ffd9b8a74df 93 7ffd9b8a74ea-7ffd9b8a75b7 92->93 94 7ffd9b8a74e1-7ffd9b8a74e9 92->94 98 7ffd9b8a75b9-7ffd9b8a75c2 93->98 99 7ffd9b8a7623 93->99 94->93 98->99 100 7ffd9b8a75c4-7ffd9b8a75d0 98->100 101 7ffd9b8a7625-7ffd9b8a764a 99->101 102 7ffd9b8a7609-7ffd9b8a7621 100->102 103 7ffd9b8a75d2-7ffd9b8a75e4 100->103 108 7ffd9b8a76b6 101->108 109 7ffd9b8a764c-7ffd9b8a7655 101->109 102->101 104 7ffd9b8a75e6 103->104 105 7ffd9b8a75e8-7ffd9b8a75fb 103->105 104->105 105->105 107 7ffd9b8a75fd-7ffd9b8a7605 105->107 107->102 110 7ffd9b8a76b8-7ffd9b8a76dd 108->110 109->108 111 7ffd9b8a7657-7ffd9b8a7663 109->111 118 7ffd9b8a774b 110->118 119 7ffd9b8a76df-7ffd9b8a76e9 110->119 112 7ffd9b8a7665-7ffd9b8a7677 111->112 113 7ffd9b8a769c-7ffd9b8a76b4 111->113 115 7ffd9b8a7679 112->115 116 7ffd9b8a767b-7ffd9b8a768e 112->116 113->110 115->116 116->116 117 7ffd9b8a7690-7ffd9b8a7698 116->117 117->113 121 7ffd9b8a774d-7ffd9b8a777b 118->121 119->118 120 7ffd9b8a76eb-7ffd9b8a76f8 119->120 122 7ffd9b8a76fa-7ffd9b8a770c 120->122 123 7ffd9b8a7731-7ffd9b8a7749 120->123 127 7ffd9b8a77eb 121->127 128 7ffd9b8a777d-7ffd9b8a7788 121->128 125 7ffd9b8a770e 122->125 126 7ffd9b8a7710-7ffd9b8a7723 122->126 123->121 125->126 126->126 129 7ffd9b8a7725-7ffd9b8a772d 126->129 131 7ffd9b8a77ed-7ffd9b8a78c5 127->131 128->127 130 7ffd9b8a778a-7ffd9b8a7798 128->130 129->123 132 7ffd9b8a779a-7ffd9b8a77ac 130->132 133 7ffd9b8a77d1-7ffd9b8a77e9 130->133 141 7ffd9b8a78cb-7ffd9b8a78da 131->141 134 7ffd9b8a77ae 132->134 135 7ffd9b8a77b0-7ffd9b8a77c3 132->135 133->131 134->135 135->135 137 7ffd9b8a77c5-7ffd9b8a77cd 135->137 137->133 142 7ffd9b8a78dc 141->142 143 7ffd9b8a78e2-7ffd9b8a7944 call 7ffd9b8a7960 141->143 142->143 150 7ffd9b8a7946 143->150 151 7ffd9b8a794b-7ffd9b8a795f 143->151 150->151
                              Memory Dump Source
                              • Source File: 00000000.00000002.4149638068.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ffd9b8a0000_1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: be268f4941d996031a60b71d84c68872280a0b85b0914c7773235bbc35c251bb
                              • Instruction ID: 4ea47b73e7adf49eb76a4bd48e35225b939949c7655f030f9a42e452a4e021cb
                              • Opcode Fuzzy Hash: be268f4941d996031a60b71d84c68872280a0b85b0914c7773235bbc35c251bb
                              • Instruction Fuzzy Hash: DDE1C530A09A8D8FEBA8DF28C8657E977D1FF58310F14426ED84DC72A5DF74A9418781

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000000.00000002.4149638068.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ffd9b8a0000_1736928425effdd3d663e7ae08ee64667d92e2866d7996db3d213458dc5837f6c732ac.jbxd
                              Similarity
                              • API ID: HookWindows
                              • String ID:
                              • API String ID: 2559412058-0
                              • Opcode ID: c46939344a0a64b884d874f9d7b74469e2b766d89859db487ff307cda3ed5242
                              • Instruction ID: a78337e7cffbf1a101f511d47b8a0cb276ef1c60e4367180261b453303ed9585
                              • Opcode Fuzzy Hash: c46939344a0a64b884d874f9d7b74469e2b766d89859db487ff307cda3ed5242
                              • Instruction Fuzzy Hash: AF411630A0CA5D4FDB1CEB6C98166F97BE1EF5A321F00427ED049C3292DE64A852C7C1