Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2lX8Z3eydC.dll

Overview

General Information

Sample name:2lX8Z3eydC.dll
renamed because original name is a hash value
Original sample name:f356feea7d644eacf46ec2266b13b456.dll
Analysis ID:1592032
MD5:f356feea7d644eacf46ec2266b13b456
SHA1:f90b66ee791e9ad7d5303057beb7ed1de6f9ae8d
SHA256:63785c337d06fa167b999584d2ed0e47e6e1698a48153b4bc2a41689da5289b1
Tags:dllexeuser-mentality
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Wannacry ransomware
AI detected suspicious sample
Connects to many IPs within the same subnet mask (likely port scanning)
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Uses 32bit PE files
Uses insecure TLS / SSL version for HTTPS connection
Yara signature match

Classification

  • System is w10x64
  • loaddll32.exe (PID: 5644 cmdline: loaddll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 3776 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 3496 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 6404 cmdline: rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
        • mssecsvc.exe (PID: 4328 cmdline: C:\WINDOWS\mssecsvc.exe MD5: 178018208D64CFFD440180008D212F1A)
    • rundll32.exe (PID: 5252 cmdline: rundll32.exe C:\Users\user\Desktop\2lX8Z3eydC.dll,PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 1656 cmdline: rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
      • mssecsvc.exe (PID: 3796 cmdline: C:\WINDOWS\mssecsvc.exe MD5: 178018208D64CFFD440180008D212F1A)
  • mssecsvc.exe (PID: 2012 cmdline: C:\WINDOWS\mssecsvc.exe -m security MD5: 178018208D64CFFD440180008D212F1A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
2lX8Z3eydC.dllJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    2lX8Z3eydC.dllWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x353d0:$x3: tasksche.exe
    • 0x3028:$x7: mssecsvc.exe
    • 0x120ac:$x7: mssecsvc.exe
    • 0x1b3b4:$x7: mssecsvc.exe
    • 0x353a8:$x8: C:\%s\qeriuwjhrf
    • 0x3014:$s1: C:\%s\%s
    • 0x12098:$s1: C:\%s\%s
    • 0x1b39c:$s1: C:\%s\%s
    • 0x353bc:$s1: C:\%s\%s
    • 0x326f0:$s5: \\192.168.56.20\IPC$
    • 0x1fae5:$s6: \\172.16.99.5\IPC$
    • 0xd195:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
    • 0x78da:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
    • 0x5449:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
    • 0x38b0a:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
    • 0x387e4:$op5: C1 EA 1D C1 EE 1E 83 E2 01 83 E6 01 8D 14 56
    • 0x383d0:$op6: 8D 48 FF F7 D1 8D 44 10 FF 23 F1 23 C1
    SourceRuleDescriptionAuthorStrings
    C:\Windows\tasksche.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x2a02:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
    • 0x26dc:$op5: C1 EA 1D C1 EE 1E 83 E2 01 83 E6 01 8D 14 56
    • 0x22c8:$op6: 8D 48 FF F7 D1 8D 44 10 FF 23 F1 23 C1
    C:\Windows\tasksche.exeWin32_Ransomware_WannaCryunknownReversingLabs
    • 0x2016:$main_2: 68 08 02 00 00 33 DB 50 53 FF 15 8C 80 40 00 68 AC F8 40 00 E8 F6 F1 FF FF 59 FF 15 6C 81 40 00 83 38 02 75 53 68 38 F5 40 00 FF 15 68 81 40 00 8B 00 FF 70 04 E8 F0 56 00 00 59 85 C0 59 75 38 ...
    • 0x77ba:$entrypoint_all: 55 8B EC 6A FF 68 88 D4 40 00 68 F4 76 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C4 81 40 00 59 83 0D 4C F9 40 00 FF 83 0D 50 F9 40 ...
    C:\Windows\mssecsvc.exeJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      C:\Windows\mssecsvc.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
      • 0x3136c:$x3: tasksche.exe
      • 0xe048:$x7: mssecsvc.exe
      • 0x17350:$x7: mssecsvc.exe
      • 0x31344:$x8: C:\%s\qeriuwjhrf
      • 0xe034:$s1: C:\%s\%s
      • 0x17338:$s1: C:\%s\%s
      • 0x31358:$s1: C:\%s\%s
      • 0x2e68c:$s5: \\192.168.56.20\IPC$
      • 0x1ba81:$s6: \\172.16.99.5\IPC$
      • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
      • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
      • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
      • 0x34aa6:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
      • 0x34780:$op5: C1 EA 1D C1 EE 1E 83 E2 01 83 E6 01 8D 14 56
      • 0x3436c:$op6: 8D 48 FF F7 D1 8D 44 10 FF 23 F1 23 C1
      C:\Windows\mssecsvc.exeWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
      • 0x1bacc:$s1: __TREEID__PLACEHOLDER__
      • 0x1bb68:$s1: __TREEID__PLACEHOLDER__
      • 0x1c3d4:$s1: __TREEID__PLACEHOLDER__
      • 0x1d439:$s1: __TREEID__PLACEHOLDER__
      • 0x1e4a0:$s1: __TREEID__PLACEHOLDER__
      • 0x1f508:$s1: __TREEID__PLACEHOLDER__
      • 0x20570:$s1: __TREEID__PLACEHOLDER__
      • 0x215d8:$s1: __TREEID__PLACEHOLDER__
      • 0x22640:$s1: __TREEID__PLACEHOLDER__
      • 0x236a8:$s1: __TREEID__PLACEHOLDER__
      • 0x24710:$s1: __TREEID__PLACEHOLDER__
      • 0x25778:$s1: __TREEID__PLACEHOLDER__
      • 0x267e0:$s1: __TREEID__PLACEHOLDER__
      • 0x27848:$s1: __TREEID__PLACEHOLDER__
      • 0x288b0:$s1: __TREEID__PLACEHOLDER__
      • 0x29918:$s1: __TREEID__PLACEHOLDER__
      • 0x2a980:$s1: __TREEID__PLACEHOLDER__
      • 0x2ab94:$s1: __TREEID__PLACEHOLDER__
      • 0x2abf4:$s1: __TREEID__PLACEHOLDER__
      • 0x2e2c4:$s1: __TREEID__PLACEHOLDER__
      • 0x2e340:$s1: __TREEID__PLACEHOLDER__
      Click to see the 1 entries
      SourceRuleDescriptionAuthorStrings
      00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        00000008.00000000.2170224322.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          00000006.00000000.2162227567.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
              0000000A.00000000.2188539151.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
                Click to see the 6 entries
                SourceRuleDescriptionAuthorStrings
                8.2.mssecsvc.exe.1d57084.2.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
                • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
                • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
                8.2.mssecsvc.exe.1d57084.2.raw.unpackWin32_Ransomware_WannaCryunknownReversingLabs
                • 0x8140:$main_3: 83 EC 50 56 57 B9 0E 00 00 00 BE D0 13 43 00 8D 7C 24 08 33 C0 F3 A5 A4 89 44 24 41 89 44 24 45 89 44 24 49 89 44 24 4D 89 44 24 51 66 89 44 24 55 50 50 50 6A 01 50 88 44 24 6B FF 15 34 A1 40 ...
                • 0x8090:$start_service_3: 83 EC 10 68 04 01 00 00 68 60 F7 70 00 6A 00 FF 15 6C A0 40 00 FF 15 2C A1 40 00 83 38 02 7D 09 E8 6B FE FF FF 83 C4 10 C3 57 68 3F 00 0F 00 6A 00 6A 00 FF 15 10 A0 40 00 8B F8 85 FF 74 32 53 ...
                • 0x9a16:$entrypoint_all: 55 8B EC 6A FF 68 A0 A1 40 00 68 A2 9B 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C0 A0 40 00 59 83 0D 94 F8 70 00 FF 83 0D 98 F8 70 ...
                8.2.mssecsvc.exe.22838c8.6.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
                • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
                • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
                8.2.mssecsvc.exe.22838c8.6.raw.unpackWin32_Ransomware_WannaCryunknownReversingLabs
                • 0x8140:$main_3: 83 EC 50 56 57 B9 0E 00 00 00 BE D0 13 43 00 8D 7C 24 08 33 C0 F3 A5 A4 89 44 24 41 89 44 24 45 89 44 24 49 89 44 24 4D 89 44 24 51 66 89 44 24 55 50 50 50 6A 01 50 88 44 24 6B FF 15 34 A1 40 ...
                • 0x8090:$start_service_3: 83 EC 10 68 04 01 00 00 68 60 F7 70 00 6A 00 FF 15 6C A0 40 00 FF 15 2C A1 40 00 83 38 02 7D 09 E8 6B FE FF FF 83 C4 10 C3 57 68 3F 00 0F 00 6A 00 6A 00 FF 15 10 A0 40 00 8B F8 85 FF 74 32 53 ...
                • 0x9a16:$entrypoint_all: 55 8B EC 6A FF 68 A0 A1 40 00 68 A2 9B 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C0 A0 40 00 59 83 0D 94 F8 70 00 FF 83 0D 98 F8 70 ...
                8.2.mssecsvc.exe.22b596c.7.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x2a02:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
                • 0x26dc:$op5: C1 EA 1D C1 EE 1E 83 E2 01 83 E6 01 8D 14 56
                • 0x22c8:$op6: 8D 48 FF F7 D1 8D 44 10 FF 23 F1 23 C1
                Click to see the 77 entries
                No Sigma rule has matched
                No Suricata rule has matched

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: 2lX8Z3eydC.dllAvira: detected
                Source: C:\Windows\mssecsvc.exeAvira: detection malicious, Label: TR/Ransom.Gen
                Source: 2lX8Z3eydC.dllReversingLabs: Detection: 92%
                Source: 2lX8Z3eydC.dllVirustotal: Detection: 90%Perma Link
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.8% probability
                Source: C:\Windows\mssecsvc.exeJoe Sandbox ML: detected
                Source: C:\Windows\tasksche.exeJoe Sandbox ML: detected
                Source: 2lX8Z3eydC.dllJoe Sandbox ML: detected

                Exploits

                barindex
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: 2lX8Z3eydC.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: unknownHTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49943 version: TLS 1.0
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49709 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49806 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50048 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50290 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50557 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50670 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50671 version: TLS 1.2

                Networking

                barindex
                Source: global trafficTCP traffic: Count: 11 IPs: 126.217.0.2,126.217.0.1,126.217.0.72,126.217.0.4,126.217.0.3,126.217.0.10,126.217.0.9,126.217.0.6,126.217.0.5,126.217.0.8,126.217.0.7
                Source: global trafficTCP traffic: Count: 11 IPs: 153.9.75.6,153.9.75.7,153.9.75.60,153.9.75.4,153.9.75.5,153.9.75.8,153.9.75.9,153.9.75.2,153.9.75.3,153.9.75.1,153.9.75.10
                Source: Joe Sandbox ViewJA3 fingerprint: 1138de370e523e824bbca92d049a3777
                Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                Source: unknownHTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49943 version: TLS 1.0
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.72
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.72
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.72
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.72
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.215
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.215
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.215
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.1
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.1
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.215
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.1
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.1
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.1
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.1
                Source: unknownTCP traffic detected without corresponding DNS query: 24.145.43.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 126.217.0.1
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.19
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.19
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.19
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.1
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.19
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.1
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.1
                Source: unknownTCP traffic detected without corresponding DNS query: 32.209.198.1
                Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50557
                Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50670
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50671
                Source: unknownNetwork traffic detected: HTTP traffic on port 50670 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50557 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50048
                Source: unknownNetwork traffic detected: HTTP traffic on port 50290 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50290
                Source: unknownNetwork traffic detected: HTTP traffic on port 50048 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50671 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
                Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
                Source: unknownNetwork traffic detected: HTTP traffic on port 49943 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49709 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49806 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50048 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50290 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50557 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50670 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50671 version: TLS 1.2

                Spam, unwanted Advertisements and Ransom Demands

                barindex
                Source: Yara matchFile source: 2lX8Z3eydC.dll, type: SAMPLE
                Source: Yara matchFile source: 8.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.22838c8.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.1d66104.5.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.1d66104.5.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 6.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 10.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 6.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.2292948.9.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 10.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.1d57084.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.2292948.9.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.228e8e8.8.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 8.2.mssecsvc.exe.1d620a4.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000000.2170224322.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000006.00000000.2162227567.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 0000000A.00000000.2188539151.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 0000000A.00000002.2190736841.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.2811124459.0000000002292000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.2810873658.0000000001D66000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: mssecsvc.exe PID: 4328, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvc.exe PID: 2012, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvc.exe PID: 3796, type: MEMORYSTR
                Source: Yara matchFile source: C:\Windows\mssecsvc.exe, type: DROPPED

                System Summary

                barindex
                Source: 2lX8Z3eydC.dll, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.1d57084.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.1d57084.2.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.22838c8.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.22838c8.6.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.22b596c.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.22b596c.7.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 6.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.22838c8.6.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.22838c8.6.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvc.exe.22838c8.6.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 10.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 6.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.1d89128.4.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.1d89128.4.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.1d66104.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.1d66104.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvc.exe.1d66104.5.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 10.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 6.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 6.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 6.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 10.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.1d89128.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.1d89128.4.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.22b596c.7.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.22b596c.7.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 6.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 10.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 10.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 6.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 6.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 6.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.2292948.9.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.2292948.9.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 10.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 10.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 10.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.1d57084.2.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.1d57084.2.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 8.2.mssecsvc.exe.1d57084.2.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: 8.2.mssecsvc.exe.2292948.9.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.228e8e8.8.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 8.2.mssecsvc.exe.1d620a4.3.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: C:\Windows\mssecsvc.exe, type: DROPPEDMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: C:\Windows\mssecsvc.exe, type: DROPPEDMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: C:\Windows\mssecsvc.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
                Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\WINDOWS\mssecsvc.exeJump to behavior
                Source: C:\Windows\mssecsvc.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: C:\Windows\mssecsvc.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: mssecsvc.exe.3.drStatic PE information: Resource name: R type: PE32 executable (GUI) Intel 80386, for MS Windows
                Source: tasksche.exe.6.drStatic PE information: No import functions for PE file found
                Source: 2lX8Z3eydC.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: 2lX8Z3eydC.dll, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.1d57084.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.1d57084.2.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.22838c8.6.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.22838c8.6.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.22b596c.7.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.22b596c.7.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 6.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.22838c8.6.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.22838c8.6.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvc.exe.22838c8.6.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 10.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 6.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.1d89128.4.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.1d89128.4.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.1d66104.5.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.1d66104.5.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvc.exe.1d66104.5.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.2.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 10.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 6.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 6.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 6.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 10.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.1d89128.4.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.1d89128.4.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.22b596c.7.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.22b596c.7.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 6.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.0.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.0.mssecsvc.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 10.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 10.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 6.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 6.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 6.0.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.2292948.9.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.2292948.9.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 10.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 10.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 10.2.mssecsvc.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.1d57084.2.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.1d57084.2.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 8.2.mssecsvc.exe.1d57084.2.unpack, type: UNPACKEDPEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: 8.2.mssecsvc.exe.2292948.9.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.228e8e8.8.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 8.2.mssecsvc.exe.1d620a4.3.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: C:\Windows\mssecsvc.exe, type: DROPPEDMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: C:\Windows\mssecsvc.exe, type: DROPPEDMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: C:\Windows\mssecsvc.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
                Source: tasksche.exe.6.drStatic PE information: Section: .data ZLIB complexity 1.0013427734375
                Source: classification engineClassification label: mal100.rans.troj.expl.evad.winDLL@18/3@0/100
                Source: C:\Windows\mssecsvc.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                Source: C:\Windows\mssecsvc.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,8_2_00407C40
                Source: C:\Windows\mssecsvc.exeCode function: 6_2_00407CE0 InternetCloseHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessA,FindResourceA,LoadResource,LockResource,SizeofResource,sprintf,sprintf,sprintf,MoveFileExA,CreateFileA,WriteFile,CloseHandle,CreateProcessA,CloseHandle,CloseHandle,6_2_00407CE0
                Source: C:\Windows\mssecsvc.exeCode function: 6_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                Source: C:\Windows\mssecsvc.exeCode function: 6_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,6_2_00408090
                Source: C:\Windows\mssecsvc.exeCode function: 8_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,8_2_00408090
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3776:120:WilError_03
                Source: 2lX8Z3eydC.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\2lX8Z3eydC.dll,PlayGame
                Source: 2lX8Z3eydC.dllReversingLabs: Detection: 92%
                Source: 2lX8Z3eydC.dllVirustotal: Detection: 90%
                Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll"
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\2lX8Z3eydC.dll,PlayGame
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvc.exe C:\WINDOWS\mssecsvc.exe
                Source: unknownProcess created: C:\Windows\mssecsvc.exe C:\WINDOWS\mssecsvc.exe -m security
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",PlayGame
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvc.exe C:\WINDOWS\mssecsvc.exe
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1Jump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\2lX8Z3eydC.dll,PlayGameJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",PlayGameJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1Jump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvc.exe C:\WINDOWS\mssecsvc.exeJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvc.exe C:\WINDOWS\mssecsvc.exeJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
                Source: 2lX8Z3eydC.dllStatic file information: File size 5267459 > 1048576
                Source: 2lX8Z3eydC.dllStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x501000

                Persistence and Installation Behavior

                barindex
                Source: C:\Windows\SysWOW64\rundll32.exeExecutable created and started: C:\WINDOWS\mssecsvc.exeJump to behavior
                Source: C:\Windows\mssecsvc.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\mssecsvc.exeJump to dropped file
                Source: C:\Windows\mssecsvc.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvc.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\mssecsvc.exeJump to dropped file
                Source: C:\Windows\mssecsvc.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvc.exeCode function: 6_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,6_2_00407C40
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvc.exeThread delayed: delay time: 86400000Jump to behavior
                Source: C:\Windows\mssecsvc.exeDropped PE file which has not been started: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvc.exeDropped PE file which has not been started: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvc.exe TID: 4160Thread sleep count: 86 > 30Jump to behavior
                Source: C:\Windows\mssecsvc.exe TID: 4160Thread sleep time: -172000s >= -30000sJump to behavior
                Source: C:\Windows\mssecsvc.exe TID: 6080Thread sleep count: 127 > 30Jump to behavior
                Source: C:\Windows\mssecsvc.exe TID: 6080Thread sleep count: 37 > 30Jump to behavior
                Source: C:\Windows\mssecsvc.exe TID: 4160Thread sleep time: -86400000s >= -30000sJump to behavior
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\loaddll32.exeThread delayed: delay time: 120000Jump to behavior
                Source: C:\Windows\mssecsvc.exeThread delayed: delay time: 86400000Jump to behavior
                Source: mssecsvc.exe, 0000000A.00000002.2191172244.0000000000B08000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllI
                Source: mssecsvc.exe, 00000006.00000002.2181573620.0000000000CEE000.00000004.00000020.00020000.00000000.sdmp, mssecsvc.exe, 00000008.00000002.2810607069.0000000000D5C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1Jump to behavior
                Source: C:\Windows\mssecsvc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                Service Execution
                4
                Windows Service
                4
                Windows Service
                12
                Masquerading
                OS Credential Dumping1
                Network Share Discovery
                Remote ServicesData from Local System2
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/Job1
                DLL Side-Loading
                11
                Process Injection
                21
                Virtualization/Sandbox Evasion
                LSASS Memory1
                Security Software Discovery
                Remote Desktop ProtocolData from Removable Media1
                Application Layer Protocol
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                11
                Process Injection
                Security Account Manager21
                Virtualization/Sandbox Evasion
                SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                Rundll32
                NTDS2
                System Information Discovery
                Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Software Packing
                LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                DLL Side-Loading
                Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 signatures2 2 Behavior Graph ID: 1592032 Sample: 2lX8Z3eydC.dll Startdate: 15/01/2025 Architecture: WINDOWS Score: 100 47 Malicious sample detected (through community Yara rule) 2->47 49 Antivirus / Scanner detection for submitted sample 2->49 51 Multi AV Scanner detection for submitted file 2->51 53 5 other signatures 2->53 8 loaddll32.exe 1 2->8         started        10 mssecsvc.exe 2->10         started        process3 dnsIp4 14 cmd.exe 1 8->14         started        16 rundll32.exe 8->16         started        19 rundll32.exe 1 8->19         started        22 conhost.exe 8->22         started        39 126.217.0.1, 445, 49711, 49713 GIGAINFRASoftbankBBCorpJP Japan 10->39 41 126.217.0.2, 445, 49831, 49832 GIGAINFRASoftbankBBCorpJP Japan 10->41 43 98 other IPs or domains 10->43 55 Connects to many different private IPs via SMB (likely to spread or exploit) 10->55 57 Connects to many different private IPs (likely to spread or exploit) 10->57 signatures5 process6 file7 24 rundll32.exe 14->24         started        45 Drops executables to the windows directory (C:\Windows) and starts them 16->45 26 mssecsvc.exe 1 16->26         started        33 C:\Windows\mssecsvc.exe, PE32 19->33 dropped signatures8 process9 file10 29 mssecsvc.exe 1 24->29         started        35 C:\WINDOWS\qeriuwjhrf (copy), PE32 26->35 dropped process11 file12 37 C:\Windows\tasksche.exe, PE32 29->37 dropped 59 Antivirus detection for dropped file 29->59 61 Machine Learning detection for dropped file 29->61 signatures13

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                2lX8Z3eydC.dll92%ReversingLabsWin32.Ransomware.WannaCry
                2lX8Z3eydC.dll90%VirustotalBrowse
                2lX8Z3eydC.dll100%AviraTR/Ransom.Gen
                2lX8Z3eydC.dll100%Joe Sandbox ML
                SourceDetectionScannerLabelLink
                C:\Windows\mssecsvc.exe100%AviraTR/Ransom.Gen
                C:\Windows\mssecsvc.exe100%Joe Sandbox ML
                C:\Windows\tasksche.exe100%Joe Sandbox ML
                No Antivirus matches
                No Antivirus matches
                No Antivirus matches
                No contacted domains info
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                221.250.196.1
                unknownJapan17506UCOMARTERIANetworksCorporationJPfalse
                167.139.11.44
                unknownChina
                4812CHINANET-SH-APChinaTelecomGroupCNfalse
                5.166.179.137
                unknownRussian Federation
                12768ER-TELECOM-ASRUfalse
                32.209.198.19
                unknownUnited States
                46690SNET-FCCUSfalse
                131.24.232.195
                unknownUnited States
                385AFCONC-BLOCK1-ASUSfalse
                128.171.224.1
                unknownUnited States
                6360UNIVHAWAIIUSfalse
                215.114.213.132
                unknownUnited States
                721DNIC-ASBLK-00721-00726USfalse
                64.71.233.8
                unknownUnited States
                27229WEBHOST-ASN1USfalse
                64.71.233.2
                unknownUnited States
                27229WEBHOST-ASN1USfalse
                64.71.233.1
                unknownUnited States
                27229WEBHOST-ASN1USfalse
                215.114.213.1
                unknownUnited States
                721DNIC-ASBLK-00721-00726USfalse
                158.219.90.2
                unknownUnited States
                2274CBOUSfalse
                158.219.90.1
                unknownUnited States
                2274CBOUSfalse
                86.64.193.173
                unknownFrance
                15557LDCOMNETFRfalse
                176.57.93.132
                unknownSlovenia
                3212TELEMACHBroadbandAccessCarrierServicesSIfalse
                183.177.251.218
                unknownJapan2519VECTANTARTERIANetworksCorporationJPfalse
                32.209.198.2
                unknownUnited States
                46690SNET-FCCUSfalse
                32.209.198.1
                unknownUnited States
                46690SNET-FCCUSfalse
                107.234.183.19
                unknownUnited States
                20057ATT-MOBILITY-LLC-AS20057USfalse
                201.222.228.147
                unknownChile
                7418TELEFONICACHILESACLfalse
                153.9.75.60
                unknownUnited States
                13548CHARLESTON-ASUStrue
                126.217.0.2
                unknownJapan17676GIGAINFRASoftbankBBCorpJPtrue
                126.217.0.1
                unknownJapan17676GIGAINFRASoftbankBBCorpJPtrue
                67.15.60.1
                unknownUnited States
                36351SOFTLAYERUSfalse
                126.217.0.4
                unknownJapan17676GIGAINFRASoftbankBBCorpJPtrue
                126.217.0.3
                unknownJapan17676GIGAINFRASoftbankBBCorpJPtrue
                IP
                192.168.2.148
                192.168.2.149
                192.168.2.146
                192.168.2.147
                192.168.2.140
                192.168.2.141
                192.168.2.144
                192.168.2.145
                192.168.2.142
                192.168.2.143
                192.168.2.159
                192.168.2.157
                192.168.2.158
                192.168.2.151
                192.168.2.152
                192.168.2.150
                192.168.2.155
                192.168.2.156
                192.168.2.153
                192.168.2.154
                192.168.2.126
                192.168.2.247
                192.168.2.127
                192.168.2.248
                192.168.2.124
                192.168.2.245
                192.168.2.125
                192.168.2.246
                192.168.2.128
                192.168.2.249
                192.168.2.129
                192.168.2.240
                192.168.2.122
                192.168.2.243
                192.168.2.123
                192.168.2.244
                192.168.2.120
                192.168.2.241
                192.168.2.121
                192.168.2.242
                192.168.2.97
                192.168.2.137
                192.168.2.96
                192.168.2.138
                192.168.2.99
                192.168.2.135
                192.168.2.98
                192.168.2.136
                192.168.2.139
                192.168.2.250
                192.168.2.130
                192.168.2.251
                192.168.2.91
                192.168.2.90
                192.168.2.93
                192.168.2.133
                192.168.2.254
                192.168.2.92
                192.168.2.134
                192.168.2.95
                192.168.2.131
                192.168.2.252
                192.168.2.94
                192.168.2.132
                192.168.2.253
                192.168.2.104
                192.168.2.225
                192.168.2.105
                192.168.2.226
                192.168.2.102
                192.168.2.223
                192.168.2.103
                192.168.2.224
                192.168.2.108
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1592032
                Start date and time:2025-01-15 17:12:07 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 5m 23s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:15
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:2lX8Z3eydC.dll
                renamed because original name is a hash value
                Original Sample Name:f356feea7d644eacf46ec2266b13b456.dll
                Detection:MAL
                Classification:mal100.rans.troj.expl.evad.winDLL@18/3@0/100
                EGA Information:
                • Successful, ratio: 100%
                HCA Information:Failed
                Cookbook Comments:
                • Found application associated with file extension: .dll
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                • Excluded IPs from analysis (whitelisted): 2.23.77.188, 199.232.214.172, 217.20.57.20, 13.107.246.45, 20.109.210.53
                • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtQueryValueKey calls found.
                TimeTypeDescription
                11:13:04API Interceptor1x Sleep call for process: loaddll32.exe modified
                11:13:37API Interceptor112x Sleep call for process: mssecsvc.exe modified
                No context
                No context
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                ER-TELECOM-ASRUhttps://klickskydd.skolverket.org/?url=https%3A%2F%2Fwww.gazeta.ru%2Fpolitics%2Fnews%2F2024%2F12%2F22%2F24684722.shtml&id=71de&rcpt=upplysningstjansten@skolverket.se&tss=1735469857&msgid=b53e7603-c5d3-11ef-8a2e-0050569b0508&html=1&h=ded85c63Get hashmaliciousHTMLPhisherBrowse
                • 81.19.73.31
                https://www.gazeta.ru/politics/news/2024/12/22/24684722.shtmlGet hashmaliciousHTMLPhisherBrowse
                • 81.19.73.31
                https://www.gazeta.ru/politics/news/2024/12/22/24684854.shtmlGet hashmaliciousHTMLPhisherBrowse
                • 81.19.73.31
                mips.nn.elfGet hashmaliciousMirai, OkiruBrowse
                • 46.147.58.102
                ppc.elfGet hashmaliciousUnknownBrowse
                • 46.146.187.169
                jew.arm.elfGet hashmaliciousUnknownBrowse
                • 46.146.25.162
                a9YMw44iQq.exeGet hashmaliciousAsyncRAT, XWormBrowse
                • 5.166.171.54
                la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                • 46.146.25.127
                sh4.elfGet hashmaliciousMirai, MoobotBrowse
                • 46.146.139.233
                sparc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                • 46.146.98.8
                SNET-FCCUSppc.elfGet hashmaliciousUnknownBrowse
                • 32.212.164.124
                momo.mips.elfGet hashmaliciousMiraiBrowse
                • 32.212.164.103
                armv4l.elfGet hashmaliciousMiraiBrowse
                • 32.221.43.196
                splsh4.elfGet hashmaliciousUnknownBrowse
                • 32.211.253.73
                nklm68k.elfGet hashmaliciousUnknownBrowse
                • 32.220.131.224
                loligang.arm.elfGet hashmaliciousMiraiBrowse
                • 32.208.36.201
                la.bot.arm.elfGet hashmaliciousMiraiBrowse
                • 32.223.84.220
                la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                • 32.219.148.67
                x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                • 32.220.253.163
                IGz.x86.elfGet hashmaliciousMiraiBrowse
                • 32.211.102.53
                UCOMARTERIANetworksCorporationJPbot.spc.elfGet hashmaliciousUnknownBrowse
                • 113.32.51.88
                bot.arm5.elfGet hashmaliciousUnknownBrowse
                • 122.211.182.76
                bot.arm7.elfGet hashmaliciousMiraiBrowse
                • 43.238.151.212
                i686.elfGet hashmaliciousMiraiBrowse
                • 59.87.31.27
                arm5.elfGet hashmaliciousMiraiBrowse
                • 43.234.132.32
                xd.mips.elfGet hashmaliciousMiraiBrowse
                • 59.87.13.179
                xd.spc.elfGet hashmaliciousMiraiBrowse
                • 113.36.203.167
                xd.ppc.elfGet hashmaliciousMiraiBrowse
                • 220.151.124.6
                la.bot.x86_64.elfGet hashmaliciousMiraiBrowse
                • 43.237.252.90
                ruXU7wj3X9.dllGet hashmaliciousWannacryBrowse
                • 124.35.234.1
                CHINANET-SH-APChinaTelecomGroupCNbot.x86.elfGet hashmaliciousUnknownBrowse
                • 101.87.175.147
                bot.spc.elfGet hashmaliciousUnknownBrowse
                • 202.101.35.137
                bot.m68k.elfGet hashmaliciousUnknownBrowse
                • 180.152.101.163
                bot.arm.elfGet hashmaliciousUnknownBrowse
                • 114.87.176.14
                i686.elfGet hashmaliciousMiraiBrowse
                • 45.124.125.139
                sh4.elfGet hashmaliciousMiraiBrowse
                • 116.192.8.62
                arm4.elfGet hashmaliciousMiraiBrowse
                • 45.124.125.117
                mpsl.elfGet hashmaliciousMiraiBrowse
                • 222.69.32.67
                178.215.238.129-x86-2025-01-15T04_59_51.elfGet hashmaliciousMiraiBrowse
                • 116.233.80.35
                mips.elfGet hashmaliciousMiraiBrowse
                • 124.75.117.239
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                1138de370e523e824bbca92d049a3777ACH REMITTANCE DOCUMENT 15.01.25.xlsbGet hashmaliciousUnknownBrowse
                • 173.222.162.64
                Personliche Nachricht fur e4060738.pdfGet hashmaliciousUnknownBrowse
                • 173.222.162.64
                https://clickme.thryv.com/ls/click?upn=u001.5dsdCa4YiGVzoib36gWoSPT0wVekqsfeOZRSaz9d28itE0eTxOetbwlGaCx05rQJywXo_UNbDpVWBvKTmUslwem1E0EC2Cp68hMzvjQfllUT9E4DZqDf2uiRmAk3QSMceJiv-2FShXGXSXiT9Fl37dFQYscKLxEMcTJj4tm5gMav6Ov9aRXzCg4yzvno75Wb80hSd5kw8Ua5r4R2pwCFTS4zDFYiEkWB-2BYk1VUWtpkJwb9IQIMAq1SSLT005wiJ2XiGw1jPEr6v61MJQRnC7AeLVtxYgqGlydBoPFbs1IP04-2BxPajuRI3fTsnzWZ9ty3RasYpwuqdrF0E8VoyYkggeeLEm9ENK69uYTCVHWHpxCPkzirQSIkvpt5FNZojg491ibS35IgO0LPU5gnpEaeaUj4-2BZoFUHIAAzMMy-2BYqsZ9F9Ldu1c-3D#XGet hashmaliciousHTMLPhisherBrowse
                • 173.222.162.64
                NLWfV87ouS.dllGet hashmaliciousWannacryBrowse
                • 173.222.162.64
                330tqxXVzm.dllGet hashmaliciousWannacryBrowse
                • 173.222.162.64
                https://asalto-bart.eu/o/dcvGet hashmaliciousUnknownBrowse
                • 173.222.162.64
                https://teiegram-mg.org/Get hashmaliciousUnknownBrowse
                • 173.222.162.64
                https://sreamconmymnltty.com/scerty/bliun/bolopGet hashmaliciousUnknownBrowse
                • 173.222.162.64
                https://reviewpolicysocialreach.vercel.app/help&z/Get hashmaliciousHTMLPhisherBrowse
                • 173.222.162.64
                https://teiegtrm.cc/EN/Get hashmaliciousTelegram PhisherBrowse
                • 173.222.162.64
                3b5074b1b5d032e5620f69f9f700ff0eaASfOObWpW.exeGet hashmaliciousUnknownBrowse
                • 40.113.103.199
                aASfOObWpW.exeGet hashmaliciousUnknownBrowse
                • 40.113.103.199
                Updater.exeGet hashmaliciousUnknownBrowse
                • 40.113.103.199
                Updater.exeGet hashmaliciousUnknownBrowse
                • 40.113.103.199
                Personliche Nachricht fur e4060738.pdfGet hashmaliciousUnknownBrowse
                • 40.113.103.199
                https://pub-2d00d32ff6d84ef6999828eaf509b772.r2.dev/index.html#watson.becky@aidb.orgGet hashmaliciousHTMLPhisherBrowse
                • 40.113.103.199
                Invoice No 1122207 pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                • 40.113.103.199
                http://www.flamingoblv.comGet hashmaliciousUnknownBrowse
                • 40.113.103.199
                NZZ71x6Cyz.dllGet hashmaliciousWannacryBrowse
                • 40.113.103.199
                qqnal04.exeGet hashmaliciousPhemedrone StealerBrowse
                • 40.113.103.199
                No context
                Process:C:\Windows\mssecsvc.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):3514368
                Entropy (8bit):7.9952915977400725
                Encrypted:true
                SSDEEP:98304:QpNcZ/+OawKZO/Q0qHPRJAKvSteNbsBLkVGXX:QncZzajOI0mvA9df
                MD5:135AF9459A23DB081FD7DFA9D085580B
                SHA1:1D288377407581B51127CAC078F4E32FEBC99D96
                SHA-256:9A015A8577A43C76B11DD0E79D12901E03AFD71394AFD046DB699A215B338908
                SHA-512:4836C9506C5C47AA1464155A4E52AA01EF0C61BE5838B962D9729681303B0B983F4E12CCDB14F6D2FEE6FB0AC425645F806AA0148CFF7B3956DF21A6A2F6784E
                Malicious:true
                Reputation:low
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........:..T...T...T..X...T.._...T.'.Z...T..^...T..P...T.g.....T...U...T..._...T.c.R...T.Rich..T.........................PE..L...A..L.................p... 5......w............@...........................5.................................................d.........4..........................................................................................................text....i.......p.................. ..`.rdata..p_.......`..................@..@.data...X........ ..................@....rsrc.....4.......4.................@..@........................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\SysWOW64\rundll32.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):3723264
                Entropy (8bit):7.9689598026856405
                Encrypted:false
                SSDEEP:98304:Z8pNcZ/+OawKZO/Q0qHPRJAKvSteNbsBLkVGXS:Z8ncZzajOI0mvA9dK
                MD5:178018208D64CFFD440180008D212F1A
                SHA1:F9ED18B62C28CD012F91A9137D284EFF44518641
                SHA-256:01200B11BBEB18E5F322CF705296256A07985ED69BF9B78F4E73BD3E7659FB51
                SHA-512:3FD34C807A3AF58E6FC31AFC9214E6BE58064C9C62651F321B7088BDDF48D879FE02CB9DC5DB66E362BD0CDCE47F0E571ED086B0CA017B3595947E151BD005ED
                Malicious:true
                Yara Hits:
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Windows\mssecsvc.exe, Author: Joe Security
                • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvc.exe, Author: Florian Roth (with the help of binar.ly)
                • Rule: WannaCry_Ransomware_Gen, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvc.exe, Author: Florian Roth (based on rule by US CERT)
                • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Windows\mssecsvc.exe, Author: ReversingLabs
                Antivirus:
                • Antivirus: Avira, Detection: 100%
                • Antivirus: Joe Sandbox ML, Detection: 100%
                Reputation:low
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......U<S..]=..]=..]=.jA1..]=.A3..]=.~B7..]=.~B6..]=.~B9..]=..R`..]=..]<.J]=.'{6..]=..[;..]=.Rich.]=.........................PE..L.....L.....................08...................@...........................f......................................................1.T.5..........................................................................................................text.............................. ..`.rdata..............................@..@.data....H0......p..................@....rsrc...T.5...1...5.. ..............@..@........................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\mssecsvc.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):3514368
                Entropy (8bit):7.9952915977400725
                Encrypted:true
                SSDEEP:98304:QpNcZ/+OawKZO/Q0qHPRJAKvSteNbsBLkVGXX:QncZzajOI0mvA9df
                MD5:135AF9459A23DB081FD7DFA9D085580B
                SHA1:1D288377407581B51127CAC078F4E32FEBC99D96
                SHA-256:9A015A8577A43C76B11DD0E79D12901E03AFD71394AFD046DB699A215B338908
                SHA-512:4836C9506C5C47AA1464155A4E52AA01EF0C61BE5838B962D9729681303B0B983F4E12CCDB14F6D2FEE6FB0AC425645F806AA0148CFF7B3956DF21A6A2F6784E
                Malicious:true
                Yara Hits:
                • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\tasksche.exe, Author: Florian Roth (with the help of binar.ly)
                • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Windows\tasksche.exe, Author: ReversingLabs
                Antivirus:
                • Antivirus: Joe Sandbox ML, Detection: 100%
                Reputation:low
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........:..T...T...T..X...T.._...T.'.Z...T..^...T..P...T.g.....T...U...T..._...T.c.R...T.Rich..T.........................PE..L...A..L.................p... 5......w............@...........................5.................................................d.........4..........................................................................................................text....i.......p.................. ..`.rdata..p_.......`..................@..@.data...X........ ..................@....rsrc.....4.......4.................@..@........................................................................................................................................................................................................................................................................................................................................................
                File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Entropy (8bit):6.42288173845038
                TrID:
                • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                • Generic Win/DOS Executable (2004/3) 0.20%
                • DOS Executable Generic (2002/1) 0.20%
                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                File name:2lX8Z3eydC.dll
                File size:5'267'459 bytes
                MD5:f356feea7d644eacf46ec2266b13b456
                SHA1:f90b66ee791e9ad7d5303057beb7ed1de6f9ae8d
                SHA256:63785c337d06fa167b999584d2ed0e47e6e1698a48153b4bc2a41689da5289b1
                SHA512:11cecee6f11f81cbe1f0c1e208f56a5e93e35b57ee28cd9bd35ca518f3580b117716f1a04e7746d7a7dff29d529822d03ea3ca677900f738c651abed714ceb44
                SSDEEP:98304:d8pNcZ/+OawKZO/Q0qHPRJAKvSteNbsBLkVGX:d8ncZzajOI0mvA9d
                TLSH:E8361239FE4F94EEC0B0843CC023A99F11B19E669531AE626DF9CF424E47B56E351A07
                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}.r_9...9...9.......=...9...6.....A.:.......8.......8.......:...Rich9...........................PE..L...QW.Y...........!.......
                Icon Hash:7ae282899bbab082
                Entrypoint:0x100011e9
                Entrypoint Section:.text
                Digitally signed:false
                Imagebase:0x10000000
                Subsystem:windows gui
                Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                DLL Characteristics:
                Time Stamp:0x59145751 [Thu May 11 12:21:37 2017 UTC]
                TLS Callbacks:
                CLR (.Net) Version:
                OS Version Major:4
                OS Version Minor:0
                File Version Major:4
                File Version Minor:0
                Subsystem Version Major:4
                Subsystem Version Minor:0
                Import Hash:2e5708ae5fed0403e8117c645fb23e5b
                Instruction
                push ebp
                mov ebp, esp
                push ebx
                mov ebx, dword ptr [ebp+08h]
                push esi
                mov esi, dword ptr [ebp+0Ch]
                push edi
                mov edi, dword ptr [ebp+10h]
                test esi, esi
                jne 00007FC3C46B4AFBh
                cmp dword ptr [10003140h], 00000000h
                jmp 00007FC3C46B4B18h
                cmp esi, 01h
                je 00007FC3C46B4AF7h
                cmp esi, 02h
                jne 00007FC3C46B4B14h
                mov eax, dword ptr [10003150h]
                test eax, eax
                je 00007FC3C46B4AFBh
                push edi
                push esi
                push ebx
                call eax
                test eax, eax
                je 00007FC3C46B4AFEh
                push edi
                push esi
                push ebx
                call 00007FC3C46B4A0Ah
                test eax, eax
                jne 00007FC3C46B4AF6h
                xor eax, eax
                jmp 00007FC3C46B4B40h
                push edi
                push esi
                push ebx
                call 00007FC3C46B48BCh
                cmp esi, 01h
                mov dword ptr [ebp+0Ch], eax
                jne 00007FC3C46B4AFEh
                test eax, eax
                jne 00007FC3C46B4B29h
                push edi
                push eax
                push ebx
                call 00007FC3C46B49E6h
                test esi, esi
                je 00007FC3C46B4AF7h
                cmp esi, 03h
                jne 00007FC3C46B4B18h
                push edi
                push esi
                push ebx
                call 00007FC3C46B49D5h
                test eax, eax
                jne 00007FC3C46B4AF5h
                and dword ptr [ebp+0Ch], eax
                cmp dword ptr [ebp+0Ch], 00000000h
                je 00007FC3C46B4B03h
                mov eax, dword ptr [10003150h]
                test eax, eax
                je 00007FC3C46B4AFAh
                push edi
                push esi
                push ebx
                call eax
                mov dword ptr [ebp+0Ch], eax
                mov eax, dword ptr [ebp+0Ch]
                pop edi
                pop esi
                pop ebx
                pop ebp
                retn 000Ch
                jmp dword ptr [10002028h]
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                Programming Language:
                • [ C ] VS98 (6.0) build 8168
                • [C++] VS98 (6.0) build 8168
                • [RES] VS98 (6.0) cvtres build 1720
                • [LNK] VS98 (6.0) imp/exp build 8168
                NameVirtual AddressVirtual Size Is in Section
                IMAGE_DIRECTORY_ENTRY_EXPORT0x21900x48.rdata
                IMAGE_DIRECTORY_ENTRY_IMPORT0x203c0x3c.rdata
                IMAGE_DIRECTORY_ENTRY_RESOURCE0x40000x500060.rsrc
                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                IMAGE_DIRECTORY_ENTRY_BASERELOC0x5050000x5c.reloc
                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IAT0x20000x3c.rdata
                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                .text0x10000x28c0x10008de9a2cb31e4c74bd008b871d14bfafcFalse0.13037109375data1.4429971244731552IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                .rdata0x20000x1d80x10003dd394f95ab218593f2bc8eb65184db4False0.072509765625data0.7346018133622799IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .data0x30000x1540x1000fe5022c5b5d015ad38b2b77fc437a5cbFalse0.016845703125Matlab v4 mat-file (little endian) C:\%s\%s, numeric, rows 0, columns 00.085238686413312IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .rsrc0x40000x5000600x501000bea982eda69f31a6f613dd4b3bca64deunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .reloc0x5050000x2ac0x1000620f0b67a91f7f74151bc5be745b7110False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                NameRVASizeTypeLanguageCountryZLIB Complexity
                W0x40600x500000dataEnglishUnited States0.8695516586303711
                DLLImport
                KERNEL32.dllCloseHandle, WriteFile, CreateFileA, SizeofResource, LockResource, LoadResource, FindResourceA, CreateProcessA
                MSVCRT.dllfree, _initterm, malloc, _adjust_fdiv, sprintf
                NameOrdinalAddress
                PlayGame10x10001114
                Language of compilation systemCountry where language is spokenMap
                EnglishUnited States
                TimestampSource PortDest PortSource IPDest IP
                Jan 15, 2025 17:12:56.084516048 CET49674443192.168.2.6173.222.162.64
                Jan 15, 2025 17:12:56.084583044 CET49673443192.168.2.6173.222.162.64
                Jan 15, 2025 17:12:56.397005081 CET49672443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:02.348862886 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:02.348954916 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:02.349071026 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:02.349850893 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:02.349884987 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.185605049 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.185694933 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:03.191005945 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:03.191035986 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.191358089 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.196125984 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:03.196261883 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:03.196274996 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.196499109 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:03.239372015 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.380036116 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.380250931 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:03.380347013 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:03.380570889 CET49709443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:03.380594015 CET4434970940.113.103.199192.168.2.6
                Jan 15, 2025 17:13:04.821094036 CET49710445192.168.2.6126.217.0.72
                Jan 15, 2025 17:13:04.826229095 CET44549710126.217.0.72192.168.2.6
                Jan 15, 2025 17:13:04.826303959 CET49710445192.168.2.6126.217.0.72
                Jan 15, 2025 17:13:04.826344967 CET49710445192.168.2.6126.217.0.72
                Jan 15, 2025 17:13:04.826560020 CET49711445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:04.831279993 CET44549710126.217.0.72192.168.2.6
                Jan 15, 2025 17:13:04.831340075 CET49710445192.168.2.6126.217.0.72
                Jan 15, 2025 17:13:04.831397057 CET44549711126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:04.831461906 CET49711445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:04.831496954 CET49711445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:04.836764097 CET44549711126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:04.836815119 CET49711445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:04.839880943 CET49713445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:04.844880104 CET44549713126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:04.844949961 CET49713445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:04.845031023 CET49713445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:04.849813938 CET44549713126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:05.693804979 CET49673443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:05.694008112 CET49674443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:06.006491899 CET49672443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:06.273981094 CET49731445192.168.2.624.145.43.215
                Jan 15, 2025 17:13:06.279834986 CET4454973124.145.43.215192.168.2.6
                Jan 15, 2025 17:13:06.279926062 CET49731445192.168.2.624.145.43.215
                Jan 15, 2025 17:13:06.279969931 CET49731445192.168.2.624.145.43.215
                Jan 15, 2025 17:13:06.280289888 CET49732445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:06.285487890 CET4454973224.145.43.1192.168.2.6
                Jan 15, 2025 17:13:06.285521030 CET4454973124.145.43.215192.168.2.6
                Jan 15, 2025 17:13:06.285566092 CET49732445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:06.285592079 CET49731445192.168.2.624.145.43.215
                Jan 15, 2025 17:13:06.285608053 CET49732445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:06.286808968 CET49733445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:06.290915966 CET4454973224.145.43.1192.168.2.6
                Jan 15, 2025 17:13:06.290983915 CET49732445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:06.291723967 CET4454973324.145.43.1192.168.2.6
                Jan 15, 2025 17:13:06.291785002 CET49733445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:06.291830063 CET49733445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:06.297785044 CET4454973324.145.43.1192.168.2.6
                Jan 15, 2025 17:13:06.743654013 CET44549713126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:06.743748903 CET49713445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:06.743875027 CET49713445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:06.743875027 CET49713445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:06.748754978 CET44549713126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:06.748785973 CET44549713126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:07.730767012 CET44349706173.222.162.64192.168.2.6
                Jan 15, 2025 17:13:07.730845928 CET49706443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:08.288877010 CET49768445192.168.2.632.209.198.19
                Jan 15, 2025 17:13:08.293668985 CET4454976832.209.198.19192.168.2.6
                Jan 15, 2025 17:13:08.293751955 CET49768445192.168.2.632.209.198.19
                Jan 15, 2025 17:13:08.293780088 CET49768445192.168.2.632.209.198.19
                Jan 15, 2025 17:13:08.293935061 CET49769445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:08.298680067 CET4454976832.209.198.19192.168.2.6
                Jan 15, 2025 17:13:08.298698902 CET4454976932.209.198.1192.168.2.6
                Jan 15, 2025 17:13:08.298738956 CET49768445192.168.2.632.209.198.19
                Jan 15, 2025 17:13:08.298780918 CET49769445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:08.298861980 CET49769445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:08.299933910 CET49770445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:08.303699970 CET4454976932.209.198.1192.168.2.6
                Jan 15, 2025 17:13:08.303750038 CET49769445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:08.304702997 CET4454977032.209.198.1192.168.2.6
                Jan 15, 2025 17:13:08.304770947 CET49770445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:08.304816008 CET49770445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:08.309572935 CET4454977032.209.198.1192.168.2.6
                Jan 15, 2025 17:13:09.756866932 CET49792445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:09.761744976 CET44549792126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:09.761820078 CET49792445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:09.761894941 CET49792445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:09.766746998 CET44549792126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:10.339744091 CET49803445192.168.2.664.71.233.8
                Jan 15, 2025 17:13:10.344603062 CET4454980364.71.233.8192.168.2.6
                Jan 15, 2025 17:13:10.344686031 CET49803445192.168.2.664.71.233.8
                Jan 15, 2025 17:13:10.344854116 CET49803445192.168.2.664.71.233.8
                Jan 15, 2025 17:13:10.345037937 CET49804445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:10.349690914 CET4454980364.71.233.8192.168.2.6
                Jan 15, 2025 17:13:10.349780083 CET49803445192.168.2.664.71.233.8
                Jan 15, 2025 17:13:10.349946976 CET4454980464.71.233.1192.168.2.6
                Jan 15, 2025 17:13:10.350014925 CET49804445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:10.350123882 CET49804445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:10.353636026 CET49805445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:10.354041100 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:10.354082108 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:10.354140043 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:10.354655027 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:10.354669094 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:10.354990005 CET4454980464.71.233.1192.168.2.6
                Jan 15, 2025 17:13:10.355042934 CET49804445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:10.358479023 CET4454980564.71.233.1192.168.2.6
                Jan 15, 2025 17:13:10.358546019 CET49805445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:10.358591080 CET49805445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:10.363528967 CET4454980564.71.233.1192.168.2.6
                Jan 15, 2025 17:13:11.149668932 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.149749994 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:11.151385069 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:11.151396036 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.151660919 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.153393030 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:11.153464079 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:11.153469086 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.153597116 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:11.199348927 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.328634977 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.328763962 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.328852892 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:11.329060078 CET49806443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:11.329077005 CET4434980640.113.103.199192.168.2.6
                Jan 15, 2025 17:13:11.628655910 CET44549792126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:11.628807068 CET49792445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:11.628807068 CET49792445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:11.628865957 CET49792445192.168.2.6126.217.0.1
                Jan 15, 2025 17:13:11.633801937 CET44549792126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:11.633833885 CET44549792126.217.0.1192.168.2.6
                Jan 15, 2025 17:13:11.694835901 CET49831445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:11.700035095 CET44549831126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:11.700205088 CET49831445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:11.700247049 CET49831445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:11.701317072 CET49832445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:11.705513000 CET44549831126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:11.705576897 CET49831445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:11.706264019 CET44549832126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:11.706336975 CET49832445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:11.706387997 CET49832445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:11.711213112 CET44549832126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:12.351366997 CET49844445192.168.2.6153.9.75.60
                Jan 15, 2025 17:13:12.356403112 CET44549844153.9.75.60192.168.2.6
                Jan 15, 2025 17:13:12.356508017 CET49844445192.168.2.6153.9.75.60
                Jan 15, 2025 17:13:12.356542110 CET49844445192.168.2.6153.9.75.60
                Jan 15, 2025 17:13:12.356730938 CET49845445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:12.361556053 CET44549845153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:12.361632109 CET49845445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:12.361670017 CET49845445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:12.361700058 CET44549844153.9.75.60192.168.2.6
                Jan 15, 2025 17:13:12.361754894 CET49844445192.168.2.6153.9.75.60
                Jan 15, 2025 17:13:12.362591982 CET49846445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:12.366647959 CET44549845153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:12.367465973 CET44549846153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:12.367532969 CET49845445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:12.367561102 CET49846445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:12.367630005 CET49846445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:12.372380018 CET44549846153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:13.580918074 CET44549832126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:13.580997944 CET49832445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:13.581058025 CET49832445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:13.581104994 CET49832445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:13.585810900 CET44549832126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:13.585843086 CET44549832126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:13.834203005 CET44549846153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:13.834408045 CET49846445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:13.834408045 CET49846445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:13.834408045 CET49846445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:13.839442968 CET44549846153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:13.839476109 CET44549846153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:14.367086887 CET49879445192.168.2.6176.57.93.132
                Jan 15, 2025 17:13:14.372026920 CET44549879176.57.93.132192.168.2.6
                Jan 15, 2025 17:13:14.372126102 CET49879445192.168.2.6176.57.93.132
                Jan 15, 2025 17:13:14.372164965 CET49879445192.168.2.6176.57.93.132
                Jan 15, 2025 17:13:14.372350931 CET49880445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:14.377161980 CET44549880176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:14.377233982 CET49880445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:14.377264977 CET49880445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:14.378317118 CET49881445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:14.379553080 CET44549879176.57.93.132192.168.2.6
                Jan 15, 2025 17:13:14.383235931 CET44549881176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:14.383327961 CET49881445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:14.383373022 CET49881445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:14.383573055 CET44549880176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:14.384371042 CET44549879176.57.93.132192.168.2.6
                Jan 15, 2025 17:13:14.384445906 CET49879445192.168.2.6176.57.93.132
                Jan 15, 2025 17:13:14.384867907 CET44549880176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:14.384924889 CET49880445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:14.388221979 CET44549881176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:16.381767035 CET49919445192.168.2.6202.166.106.94
                Jan 15, 2025 17:13:16.388134003 CET44549919202.166.106.94192.168.2.6
                Jan 15, 2025 17:13:16.388268948 CET49919445192.168.2.6202.166.106.94
                Jan 15, 2025 17:13:16.388268948 CET49919445192.168.2.6202.166.106.94
                Jan 15, 2025 17:13:16.388392925 CET49920445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:16.394742966 CET44549919202.166.106.94192.168.2.6
                Jan 15, 2025 17:13:16.394753933 CET44549920202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:16.394826889 CET49920445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:16.394876957 CET49919445192.168.2.6202.166.106.94
                Jan 15, 2025 17:13:16.394927025 CET49920445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:16.395142078 CET49921445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:16.401482105 CET44549920202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:16.401493073 CET44549921202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:16.401540995 CET49920445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:16.401690006 CET49921445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:16.401690006 CET49921445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:16.408173084 CET44549921202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:16.584950924 CET49925445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:16.589757919 CET44549925126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:16.589833975 CET49925445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:16.589951038 CET49925445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:16.594763041 CET44549925126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:16.850656033 CET49932445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:16.856889963 CET44549932153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:16.856985092 CET49932445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:16.860258102 CET49932445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:16.866756916 CET44549932153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:17.488599062 CET49706443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:17.488599062 CET49706443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:17.489018917 CET49943443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:17.489072084 CET44349943173.222.162.64192.168.2.6
                Jan 15, 2025 17:13:17.489152908 CET49943443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:17.493511915 CET44349706173.222.162.64192.168.2.6
                Jan 15, 2025 17:13:17.493549109 CET44349706173.222.162.64192.168.2.6
                Jan 15, 2025 17:13:17.493890047 CET49943443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:17.493928909 CET44349943173.222.162.64192.168.2.6
                Jan 15, 2025 17:13:18.109764099 CET44349943173.222.162.64192.168.2.6
                Jan 15, 2025 17:13:18.109841108 CET49943443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:18.339289904 CET44549932153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:18.339363098 CET49932445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:18.339411020 CET49932445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:18.339468002 CET49932445192.168.2.6153.9.75.1
                Jan 15, 2025 17:13:18.344279051 CET44549932153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:18.344295979 CET44549932153.9.75.1192.168.2.6
                Jan 15, 2025 17:13:18.397341013 CET49962445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:18.397567987 CET49963445192.168.2.6158.219.90.184
                Jan 15, 2025 17:13:18.403439045 CET44549962153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:18.403471947 CET44549963158.219.90.184192.168.2.6
                Jan 15, 2025 17:13:18.403516054 CET49962445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:18.403547049 CET49963445192.168.2.6158.219.90.184
                Jan 15, 2025 17:13:18.403552055 CET49962445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:18.403573990 CET49963445192.168.2.6158.219.90.184
                Jan 15, 2025 17:13:18.403704882 CET49964445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:18.403955936 CET49965445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:18.408533096 CET44549964158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:18.408591032 CET49964445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:18.408608913 CET49964445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:18.408677101 CET44549962153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:18.408737898 CET49962445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:18.408791065 CET44549963158.219.90.184192.168.2.6
                Jan 15, 2025 17:13:18.408839941 CET49966445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:18.408850908 CET49963445192.168.2.6158.219.90.184
                Jan 15, 2025 17:13:18.408858061 CET44549965153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:18.408967972 CET49965445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:18.409001112 CET49965445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:18.413654089 CET44549964158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:18.413667917 CET44549966158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:18.413710117 CET49964445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:18.413750887 CET49966445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:18.413778067 CET49966445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:18.413779020 CET44549965153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:18.418528080 CET44549966158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:18.491380930 CET44549925126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:18.491460085 CET49925445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:18.491509914 CET49925445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:18.491581917 CET49925445192.168.2.6126.217.0.2
                Jan 15, 2025 17:13:18.496412039 CET44549925126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:18.496443033 CET44549925126.217.0.2192.168.2.6
                Jan 15, 2025 17:13:18.553958893 CET49970445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:18.558855057 CET44549970126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:18.558932066 CET49970445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:18.559181929 CET49970445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:18.559427023 CET49971445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:18.564016104 CET44549970126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:18.564105034 CET49970445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:18.564232111 CET44549971126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:18.564387083 CET49971445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:18.564445972 CET49971445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:18.569235086 CET44549971126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:19.896214008 CET44549965153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:19.896281958 CET49965445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:19.896334887 CET49965445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:19.896347046 CET49965445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:19.901218891 CET44549965153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:19.901249886 CET44549965153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:20.413238049 CET50004445192.168.2.6166.43.168.52
                Jan 15, 2025 17:13:20.418334961 CET44550004166.43.168.52192.168.2.6
                Jan 15, 2025 17:13:20.418422937 CET50004445192.168.2.6166.43.168.52
                Jan 15, 2025 17:13:20.418483019 CET50004445192.168.2.6166.43.168.52
                Jan 15, 2025 17:13:20.418620110 CET50005445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:20.423687935 CET44550005166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:20.423722029 CET44550004166.43.168.52192.168.2.6
                Jan 15, 2025 17:13:20.423753023 CET50005445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:20.423784018 CET50004445192.168.2.6166.43.168.52
                Jan 15, 2025 17:13:20.423852921 CET50005445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:20.424127102 CET50006445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:20.428940058 CET44550005166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:20.429011106 CET50005445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:20.429044962 CET44550006166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:20.429121017 CET50006445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:20.429157972 CET50006445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:20.434262991 CET44550006166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:20.441262960 CET44549971126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:20.441323996 CET49971445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:20.441364050 CET49971445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:20.441391945 CET49971445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:20.446180105 CET44549971126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:20.446248055 CET44549971126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:22.429709911 CET50041445192.168.2.6128.171.224.244
                Jan 15, 2025 17:13:22.434930086 CET44550041128.171.224.244192.168.2.6
                Jan 15, 2025 17:13:22.436580896 CET50041445192.168.2.6128.171.224.244
                Jan 15, 2025 17:13:22.436580896 CET50041445192.168.2.6128.171.224.244
                Jan 15, 2025 17:13:22.436655998 CET50042445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:22.441693068 CET44550041128.171.224.244192.168.2.6
                Jan 15, 2025 17:13:22.441728115 CET44550042128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:22.441916943 CET50041445192.168.2.6128.171.224.244
                Jan 15, 2025 17:13:22.441940069 CET50042445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:22.441941023 CET50042445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:22.442166090 CET50043445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:22.447124958 CET44550043128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:22.447146893 CET44550042128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:22.447218895 CET50043445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:22.447283030 CET50043445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:22.447355986 CET50042445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:22.452348948 CET44550043128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:22.638716936 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:22.638803005 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:22.638925076 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:22.639520884 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:22.639605045 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:22.897201061 CET50053445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:22.903199911 CET44550053153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:22.903320074 CET50053445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:22.903476000 CET50053445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:22.908997059 CET44550053153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:23.444000959 CET50064445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:23.448990107 CET44550064126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:23.449095011 CET50064445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:23.449163914 CET50064445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:23.453161001 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:23.453253984 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.453996897 CET44550064126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:23.457727909 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.457747936 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:23.458574057 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:23.460297108 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.460341930 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.460359097 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:23.460488081 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.507332087 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:23.661278963 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:23.661761045 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:23.661983013 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.662632942 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.662632942 CET50048443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:23.662700891 CET4435004840.113.103.199192.168.2.6
                Jan 15, 2025 17:13:24.368596077 CET44550053153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:24.372795105 CET50053445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:24.372795105 CET50053445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:24.372899055 CET50053445192.168.2.6153.9.75.2
                Jan 15, 2025 17:13:24.377667904 CET44550053153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:24.377695084 CET44550053153.9.75.2192.168.2.6
                Jan 15, 2025 17:13:24.428493023 CET50081445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:24.433384895 CET44550081153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:24.433494091 CET50081445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:24.433536053 CET50081445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:24.433796883 CET50082445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:24.438596964 CET44550081153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:24.438611984 CET44550082153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:24.438663960 CET50081445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:24.438708067 CET50082445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:24.438708067 CET50082445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:24.443533897 CET44550082153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:24.444236040 CET50083445192.168.2.667.15.60.148
                Jan 15, 2025 17:13:24.449070930 CET4455008367.15.60.148192.168.2.6
                Jan 15, 2025 17:13:24.449136972 CET50083445192.168.2.667.15.60.148
                Jan 15, 2025 17:13:24.449167967 CET50083445192.168.2.667.15.60.148
                Jan 15, 2025 17:13:24.449358940 CET50085445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:24.454071045 CET4455008367.15.60.148192.168.2.6
                Jan 15, 2025 17:13:24.454098940 CET4455008567.15.60.1192.168.2.6
                Jan 15, 2025 17:13:24.454186916 CET50083445192.168.2.667.15.60.148
                Jan 15, 2025 17:13:24.454189062 CET50085445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:24.454363108 CET50085445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:24.454456091 CET50086445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:24.459150076 CET4455008567.15.60.1192.168.2.6
                Jan 15, 2025 17:13:24.459331036 CET50085445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:24.459356070 CET4455008667.15.60.1192.168.2.6
                Jan 15, 2025 17:13:24.459506989 CET50086445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:24.459544897 CET50086445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:24.464282036 CET4455008667.15.60.1192.168.2.6
                Jan 15, 2025 17:13:25.311777115 CET44550064126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:25.311850071 CET50064445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:25.311935902 CET50064445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:25.311937094 CET50064445192.168.2.6126.217.0.3
                Jan 15, 2025 17:13:25.316729069 CET44550064126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:25.316744089 CET44550064126.217.0.3192.168.2.6
                Jan 15, 2025 17:13:25.365878105 CET50103445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:25.370662928 CET44550103126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:25.370724916 CET50103445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:25.370769024 CET50103445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:25.371010065 CET50104445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:25.375545025 CET44550103126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:25.375914097 CET44550103126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:25.375922918 CET44550104126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:25.375957966 CET50103445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:25.376005888 CET50104445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:25.376046896 CET50104445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:25.380779028 CET44550104126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:25.901046038 CET44550082153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:25.901108027 CET50082445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:25.901129961 CET50082445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:25.901170015 CET50082445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:25.906263113 CET44550082153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:25.906275988 CET44550082153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:26.466995001 CET50123445192.168.2.635.167.167.165
                Jan 15, 2025 17:13:26.471884012 CET4455012335.167.167.165192.168.2.6
                Jan 15, 2025 17:13:26.471963882 CET50123445192.168.2.635.167.167.165
                Jan 15, 2025 17:13:26.471990108 CET50123445192.168.2.635.167.167.165
                Jan 15, 2025 17:13:26.472239017 CET50124445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:26.476896048 CET4455012335.167.167.165192.168.2.6
                Jan 15, 2025 17:13:26.476948023 CET50123445192.168.2.635.167.167.165
                Jan 15, 2025 17:13:26.477044106 CET4455012435.167.167.1192.168.2.6
                Jan 15, 2025 17:13:26.477109909 CET50124445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:26.477178097 CET50124445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:26.477399111 CET50125445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:26.482134104 CET4455012435.167.167.1192.168.2.6
                Jan 15, 2025 17:13:26.482191086 CET50124445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:26.482259989 CET4455012535.167.167.1192.168.2.6
                Jan 15, 2025 17:13:26.482325077 CET50125445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:26.482367992 CET50125445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:26.487154961 CET4455012535.167.167.1192.168.2.6
                Jan 15, 2025 17:13:27.255193949 CET44550104126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:27.255400896 CET50104445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:27.255400896 CET50104445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:27.255400896 CET50104445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:27.260288000 CET44550104126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:27.260315895 CET44550104126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:27.685228109 CET4454973324.145.43.1192.168.2.6
                Jan 15, 2025 17:13:27.685415983 CET49733445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:27.685415983 CET49733445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:27.685524940 CET49733445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:27.690269947 CET4454973324.145.43.1192.168.2.6
                Jan 15, 2025 17:13:27.690325022 CET4454973324.145.43.1192.168.2.6
                Jan 15, 2025 17:13:28.475682020 CET50160445192.168.2.6131.24.232.195
                Jan 15, 2025 17:13:28.480561018 CET44550160131.24.232.195192.168.2.6
                Jan 15, 2025 17:13:28.480654955 CET50160445192.168.2.6131.24.232.195
                Jan 15, 2025 17:13:28.480673075 CET50160445192.168.2.6131.24.232.195
                Jan 15, 2025 17:13:28.480822086 CET50161445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:28.485718012 CET44550161131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:28.485749960 CET44550160131.24.232.195192.168.2.6
                Jan 15, 2025 17:13:28.485789061 CET50161445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:28.485815048 CET50160445192.168.2.6131.24.232.195
                Jan 15, 2025 17:13:28.485933065 CET50161445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:28.486212969 CET50162445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:28.490988016 CET44550162131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:28.491054058 CET50162445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:28.491065025 CET50162445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:28.491527081 CET44550161131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:28.493536949 CET44550161131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:28.493601084 CET50161445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:28.496536016 CET44550162131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:28.912867069 CET50171445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:28.917767048 CET44550171153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:28.917871952 CET50171445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:28.917953014 CET50171445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:28.922718048 CET44550171153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:29.665909052 CET4454977032.209.198.1192.168.2.6
                Jan 15, 2025 17:13:29.665987968 CET49770445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:29.666068077 CET49770445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:29.666102886 CET49770445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:29.670900106 CET4454977032.209.198.1192.168.2.6
                Jan 15, 2025 17:13:29.670908928 CET4454977032.209.198.1192.168.2.6
                Jan 15, 2025 17:13:30.256688118 CET50177445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:30.261657000 CET44550177126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:30.261742115 CET50177445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:30.261831045 CET50177445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:30.267096996 CET44550177126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:30.379968882 CET44550171153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:30.380063057 CET50171445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:30.380155087 CET50171445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:30.380155087 CET50171445192.168.2.6153.9.75.3
                Jan 15, 2025 17:13:30.384993076 CET44550171153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:30.385003090 CET44550171153.9.75.3192.168.2.6
                Jan 15, 2025 17:13:30.444168091 CET50181445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:30.449033976 CET44550181153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:30.449115992 CET50181445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:30.449126959 CET50181445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:30.449486017 CET50182445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:30.454372883 CET44550181153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:30.454385042 CET44550182153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:30.454441071 CET50181445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:30.454479933 CET50182445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:30.454549074 CET50182445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:30.459364891 CET44550182153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:30.491166115 CET50183445192.168.2.6107.234.183.19
                Jan 15, 2025 17:13:30.496452093 CET44550183107.234.183.19192.168.2.6
                Jan 15, 2025 17:13:30.496515989 CET50183445192.168.2.6107.234.183.19
                Jan 15, 2025 17:13:30.496617079 CET50183445192.168.2.6107.234.183.19
                Jan 15, 2025 17:13:30.496932983 CET50184445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:30.501785994 CET44550183107.234.183.19192.168.2.6
                Jan 15, 2025 17:13:30.501796007 CET44550184107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:30.501862049 CET50183445192.168.2.6107.234.183.19
                Jan 15, 2025 17:13:30.501921892 CET50184445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:30.501965046 CET50184445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:30.502114058 CET50185445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:30.507165909 CET44550185107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:30.507174015 CET44550184107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:30.507241964 CET50184445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:30.507245064 CET50185445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:30.507291079 CET50185445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:30.512852907 CET44550185107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:30.694170952 CET50188445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:30.699218988 CET4455018824.145.43.1192.168.2.6
                Jan 15, 2025 17:13:30.699321985 CET50188445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:30.699342012 CET50188445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:30.704219103 CET4455018824.145.43.1192.168.2.6
                Jan 15, 2025 17:13:31.743942976 CET4454980564.71.233.1192.168.2.6
                Jan 15, 2025 17:13:31.744019985 CET49805445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:31.744110107 CET49805445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:31.744132996 CET49805445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:31.748919010 CET4454980564.71.233.1192.168.2.6
                Jan 15, 2025 17:13:31.748939991 CET4454980564.71.233.1192.168.2.6
                Jan 15, 2025 17:13:31.913640022 CET44550182153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:31.913714886 CET50182445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:31.913764954 CET50182445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:31.913788080 CET50182445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:31.918576002 CET44550182153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:31.918590069 CET44550182153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:32.130542994 CET44550177126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:32.130625010 CET50177445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:32.130712032 CET50177445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:32.130712032 CET50177445192.168.2.6126.217.0.4
                Jan 15, 2025 17:13:32.137034893 CET44550177126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:32.137065887 CET44550177126.217.0.4192.168.2.6
                Jan 15, 2025 17:13:32.194174051 CET50199445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:32.199063063 CET44550199126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:32.199134111 CET50199445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:32.199151993 CET50199445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:32.199412107 CET50200445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:32.204247952 CET44550200126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:32.204301119 CET50200445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:32.204329014 CET50200445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:32.205382109 CET44550199126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:32.205431938 CET50199445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:32.209134102 CET44550200126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:32.508137941 CET50201445192.168.2.6146.244.82.172
                Jan 15, 2025 17:13:32.513113022 CET44550201146.244.82.172192.168.2.6
                Jan 15, 2025 17:13:32.513196945 CET50201445192.168.2.6146.244.82.172
                Jan 15, 2025 17:13:32.513227940 CET50201445192.168.2.6146.244.82.172
                Jan 15, 2025 17:13:32.513365984 CET50203445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:32.518171072 CET44550203146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:32.518260002 CET50203445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:32.518421888 CET50203445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:32.518783092 CET50204445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:32.519562960 CET44550201146.244.82.172192.168.2.6
                Jan 15, 2025 17:13:32.520019054 CET44550201146.244.82.172192.168.2.6
                Jan 15, 2025 17:13:32.520078897 CET50201445192.168.2.6146.244.82.172
                Jan 15, 2025 17:13:32.523415089 CET44550203146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:32.523475885 CET50203445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:32.523628950 CET44550204146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:32.523719072 CET50204445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:32.523719072 CET50204445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:32.528553009 CET44550204146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:32.678472042 CET50207445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:32.683336020 CET4455020732.209.198.1192.168.2.6
                Jan 15, 2025 17:13:32.683424950 CET50207445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:32.683511972 CET50207445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:32.688251972 CET4455020732.209.198.1192.168.2.6
                Jan 15, 2025 17:13:34.089257956 CET44550200126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:34.089340925 CET50200445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:34.089396000 CET50200445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:34.089396000 CET50200445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:34.094243050 CET44550200126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:34.094250917 CET44550200126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:34.522900105 CET50220445192.168.2.686.67.1.18
                Jan 15, 2025 17:13:34.527767897 CET4455022086.67.1.18192.168.2.6
                Jan 15, 2025 17:13:34.527977943 CET50221445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:34.527975082 CET50220445192.168.2.686.67.1.18
                Jan 15, 2025 17:13:34.527975082 CET50220445192.168.2.686.67.1.18
                Jan 15, 2025 17:13:34.532795906 CET4455022186.67.1.1192.168.2.6
                Jan 15, 2025 17:13:34.532882929 CET50221445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:34.532907009 CET50221445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:34.532977104 CET4455022086.67.1.18192.168.2.6
                Jan 15, 2025 17:13:34.533212900 CET50222445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:34.533279896 CET50220445192.168.2.686.67.1.18
                Jan 15, 2025 17:13:34.537962914 CET4455022186.67.1.1192.168.2.6
                Jan 15, 2025 17:13:34.538006067 CET4455022286.67.1.1192.168.2.6
                Jan 15, 2025 17:13:34.538017035 CET50221445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:34.538095951 CET50222445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:34.538095951 CET50222445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:34.542923927 CET4455022286.67.1.1192.168.2.6
                Jan 15, 2025 17:13:34.756835938 CET50223445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:34.761878014 CET4455022364.71.233.1192.168.2.6
                Jan 15, 2025 17:13:34.762110949 CET50223445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:34.762213945 CET50223445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:34.767079115 CET4455022364.71.233.1192.168.2.6
                Jan 15, 2025 17:13:34.928375006 CET50226445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:34.933226109 CET44550226153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:34.933475971 CET50226445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:34.933475971 CET50226445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:34.938335896 CET44550226153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:35.758567095 CET44549881176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:35.758779049 CET49881445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:35.758779049 CET49881445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:35.758877993 CET49881445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:35.763746977 CET44549881176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:35.763761997 CET44549881176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:36.217322111 CET4455022286.67.1.1192.168.2.6
                Jan 15, 2025 17:13:36.217578888 CET50222445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:36.217580080 CET50222445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:36.217638016 CET50222445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:36.222510099 CET4455022286.67.1.1192.168.2.6
                Jan 15, 2025 17:13:36.222538948 CET4455022286.67.1.1192.168.2.6
                Jan 15, 2025 17:13:36.397653103 CET44550226153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:36.397751093 CET50226445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:36.399643898 CET50226445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:36.399719954 CET50226445192.168.2.6153.9.75.4
                Jan 15, 2025 17:13:36.404643059 CET44550226153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:36.404674053 CET44550226153.9.75.4192.168.2.6
                Jan 15, 2025 17:13:36.459873915 CET50237445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:36.464854002 CET44550237153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:36.464946985 CET50237445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:36.464986086 CET50237445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:36.465332985 CET50238445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:36.469913006 CET44550237153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:36.469988108 CET50237445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:36.470186949 CET44550238153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:36.470244884 CET50238445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:36.470274925 CET50238445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:36.475234032 CET44550238153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:36.538070917 CET50240445192.168.2.6217.163.243.7
                Jan 15, 2025 17:13:36.542872906 CET44550240217.163.243.7192.168.2.6
                Jan 15, 2025 17:13:36.542960882 CET50240445192.168.2.6217.163.243.7
                Jan 15, 2025 17:13:36.543040037 CET50240445192.168.2.6217.163.243.7
                Jan 15, 2025 17:13:36.543239117 CET50241445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:36.547919035 CET44550240217.163.243.7192.168.2.6
                Jan 15, 2025 17:13:36.547974110 CET44550241217.163.243.1192.168.2.6
                Jan 15, 2025 17:13:36.547986984 CET50240445192.168.2.6217.163.243.7
                Jan 15, 2025 17:13:36.548034906 CET50241445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:36.548079967 CET50241445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:36.548345089 CET50242445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:36.553092003 CET44550242217.163.243.1192.168.2.6
                Jan 15, 2025 17:13:36.553105116 CET44550241217.163.243.1192.168.2.6
                Jan 15, 2025 17:13:36.553162098 CET50241445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:36.553181887 CET50242445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:36.557961941 CET44550242217.163.243.1192.168.2.6
                Jan 15, 2025 17:13:37.100377083 CET50245445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:37.105310917 CET44550245126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:37.105407953 CET50245445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:37.105453014 CET50245445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:37.110311985 CET44550245126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:37.265408993 CET44349943173.222.162.64192.168.2.6
                Jan 15, 2025 17:13:37.265486956 CET49943443192.168.2.6173.222.162.64
                Jan 15, 2025 17:13:37.775329113 CET44549921202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:37.775420904 CET49921445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:37.775511026 CET49921445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:37.775511026 CET49921445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:37.780380011 CET44549921202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:37.780395031 CET44549921202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:37.944050074 CET44550238153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:37.944148064 CET50238445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:37.944217920 CET50238445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:37.944217920 CET50238445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:37.949037075 CET44550238153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:37.949167967 CET44550238153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:38.553668976 CET50256445192.168.2.6183.177.251.218
                Jan 15, 2025 17:13:38.558468103 CET44550256183.177.251.218192.168.2.6
                Jan 15, 2025 17:13:38.558537960 CET50256445192.168.2.6183.177.251.218
                Jan 15, 2025 17:13:38.558564901 CET50256445192.168.2.6183.177.251.218
                Jan 15, 2025 17:13:38.558646917 CET50257445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:38.563375950 CET44550257183.177.251.1192.168.2.6
                Jan 15, 2025 17:13:38.563427925 CET50257445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:38.563451052 CET50257445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:38.563827038 CET50258445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:38.563833952 CET44550256183.177.251.218192.168.2.6
                Jan 15, 2025 17:13:38.563888073 CET50256445192.168.2.6183.177.251.218
                Jan 15, 2025 17:13:38.568432093 CET44550257183.177.251.1192.168.2.6
                Jan 15, 2025 17:13:38.568479061 CET50257445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:38.568612099 CET44550258183.177.251.1192.168.2.6
                Jan 15, 2025 17:13:38.568666935 CET50258445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:38.568691969 CET50258445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:38.573539972 CET44550258183.177.251.1192.168.2.6
                Jan 15, 2025 17:13:38.772291899 CET50261445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:38.777210951 CET44550261176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:38.777287960 CET50261445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:38.777342081 CET50261445192.168.2.6176.57.93.1
                Jan 15, 2025 17:13:38.782062054 CET44550261176.57.93.1192.168.2.6
                Jan 15, 2025 17:13:38.975876093 CET44550245126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:38.975951910 CET50245445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:38.975991964 CET50245445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:38.976013899 CET50245445192.168.2.6126.217.0.5
                Jan 15, 2025 17:13:38.980756998 CET44550245126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:38.980771065 CET44550245126.217.0.5192.168.2.6
                Jan 15, 2025 17:13:39.037863016 CET50263445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:39.042722940 CET44550263126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:39.042793989 CET50263445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:39.042836905 CET50263445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:39.043102980 CET50264445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:39.047769070 CET44550263126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:39.047816992 CET50263445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:39.047934055 CET44550264126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:39.048099995 CET50264445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:39.048136950 CET50264445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:39.052879095 CET44550264126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:39.225413084 CET50267445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:39.230302095 CET4455026786.67.1.1192.168.2.6
                Jan 15, 2025 17:13:39.230384111 CET50267445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:39.230423927 CET50267445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:39.235203981 CET4455026786.67.1.1192.168.2.6
                Jan 15, 2025 17:13:39.790224075 CET44549966158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:39.790291071 CET49966445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:39.790369987 CET49966445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:39.790369987 CET49966445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:39.797535896 CET44549966158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:39.797549963 CET44549966158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:40.429258108 CET50275445192.168.2.6187.139.204.103
                Jan 15, 2025 17:13:40.434016943 CET44550275187.139.204.103192.168.2.6
                Jan 15, 2025 17:13:40.434102058 CET50275445192.168.2.6187.139.204.103
                Jan 15, 2025 17:13:40.434253931 CET50275445192.168.2.6187.139.204.103
                Jan 15, 2025 17:13:40.434580088 CET50276445192.168.2.6187.139.204.1
                Jan 15, 2025 17:13:40.439445972 CET44550275187.139.204.103192.168.2.6
                Jan 15, 2025 17:13:40.439456940 CET44550276187.139.204.1192.168.2.6
                Jan 15, 2025 17:13:40.439506054 CET50275445192.168.2.6187.139.204.103
                Jan 15, 2025 17:13:40.439588070 CET50276445192.168.2.6187.139.204.1
                Jan 15, 2025 17:13:40.439671040 CET50276445192.168.2.6187.139.204.1
                Jan 15, 2025 17:13:40.439855099 CET50277445192.168.2.6187.139.204.1
                Jan 15, 2025 17:13:40.444618940 CET44550276187.139.204.1192.168.2.6
                Jan 15, 2025 17:13:40.444629908 CET44550277187.139.204.1192.168.2.6
                Jan 15, 2025 17:13:40.444694042 CET50276445192.168.2.6187.139.204.1
                Jan 15, 2025 17:13:40.444710970 CET50277445192.168.2.6187.139.204.1
                Jan 15, 2025 17:13:40.444724083 CET50277445192.168.2.6187.139.204.1
                Jan 15, 2025 17:13:40.449500084 CET44550277187.139.204.1192.168.2.6
                Jan 15, 2025 17:13:40.787827969 CET50280445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:40.792642117 CET44550280202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:40.792715073 CET50280445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:40.792737961 CET50280445192.168.2.6202.166.106.1
                Jan 15, 2025 17:13:40.797502995 CET44550280202.166.106.1192.168.2.6
                Jan 15, 2025 17:13:40.912431002 CET44550264126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:40.912611008 CET50264445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:40.912611008 CET50264445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:40.912611008 CET50264445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:40.917509079 CET44550264126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:40.917519093 CET44550264126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:40.959794044 CET50282445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:40.964634895 CET44550282153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:40.964705944 CET50282445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:40.964762926 CET50282445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:40.969708920 CET44550282153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:40.983594894 CET4455026786.67.1.1192.168.2.6
                Jan 15, 2025 17:13:40.983675003 CET50267445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:40.983808994 CET50267445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:40.983808994 CET50267445192.168.2.686.67.1.1
                Jan 15, 2025 17:13:40.988627911 CET4455026786.67.1.1192.168.2.6
                Jan 15, 2025 17:13:40.988661051 CET4455026786.67.1.1192.168.2.6
                Jan 15, 2025 17:13:41.037833929 CET50283445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:41.042754889 CET4455028386.67.1.2192.168.2.6
                Jan 15, 2025 17:13:41.042876005 CET50283445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:41.042969942 CET50283445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:41.043302059 CET50284445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:41.048274994 CET4455028486.67.1.2192.168.2.6
                Jan 15, 2025 17:13:41.048285007 CET4455028386.67.1.2192.168.2.6
                Jan 15, 2025 17:13:41.048507929 CET50283445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:41.048583031 CET50284445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:41.053548098 CET4455028486.67.1.2192.168.2.6
                Jan 15, 2025 17:13:41.702022076 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:41.702115059 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:41.702235937 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:41.702817917 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:41.702855110 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:41.804670095 CET44550006166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:41.804833889 CET50006445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:41.804833889 CET50006445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:41.804833889 CET50006445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:41.809690952 CET44550006166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:41.809700012 CET44550006166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:42.178663015 CET50294445192.168.2.65.166.179.137
                Jan 15, 2025 17:13:42.183446884 CET445502945.166.179.137192.168.2.6
                Jan 15, 2025 17:13:42.183536053 CET50294445192.168.2.65.166.179.137
                Jan 15, 2025 17:13:42.183588982 CET50294445192.168.2.65.166.179.137
                Jan 15, 2025 17:13:42.183816910 CET50295445192.168.2.65.166.179.1
                Jan 15, 2025 17:13:42.188467979 CET445502945.166.179.137192.168.2.6
                Jan 15, 2025 17:13:42.188529015 CET50294445192.168.2.65.166.179.137
                Jan 15, 2025 17:13:42.188607931 CET445502955.166.179.1192.168.2.6
                Jan 15, 2025 17:13:42.188678980 CET50295445192.168.2.65.166.179.1
                Jan 15, 2025 17:13:42.188718081 CET50295445192.168.2.65.166.179.1
                Jan 15, 2025 17:13:42.188955069 CET50296445192.168.2.65.166.179.1
                Jan 15, 2025 17:13:42.193622112 CET445502955.166.179.1192.168.2.6
                Jan 15, 2025 17:13:42.193681002 CET50295445192.168.2.65.166.179.1
                Jan 15, 2025 17:13:42.193774939 CET445502965.166.179.1192.168.2.6
                Jan 15, 2025 17:13:42.193885088 CET50296445192.168.2.65.166.179.1
                Jan 15, 2025 17:13:42.193885088 CET50296445192.168.2.65.166.179.1
                Jan 15, 2025 17:13:42.198674917 CET445502965.166.179.1192.168.2.6
                Jan 15, 2025 17:13:42.462109089 CET44550282153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:42.462547064 CET50282445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:42.462594032 CET50282445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:42.462630987 CET50282445192.168.2.6153.9.75.5
                Jan 15, 2025 17:13:42.467403889 CET44550282153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:42.467490911 CET44550282153.9.75.5192.168.2.6
                Jan 15, 2025 17:13:42.493314981 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.493427038 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.495306969 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.495348930 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.495697021 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.497812986 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.497931004 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.497946024 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.498131990 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.522402048 CET50299445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:42.527169943 CET44550299153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:42.527257919 CET50299445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:42.527327061 CET50299445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:42.527693987 CET50300445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:42.532475948 CET44550300153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:42.532552004 CET50300445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:42.532577991 CET50300445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:42.532711983 CET44550299153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:42.532764912 CET50299445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:42.537311077 CET44550300153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:42.543340921 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.690485954 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.692679882 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.692679882 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.692747116 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.692986012 CET4435029040.113.103.199192.168.2.6
                Jan 15, 2025 17:13:42.693069935 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.693069935 CET50290443192.168.2.640.113.103.199
                Jan 15, 2025 17:13:42.696729898 CET4455028486.67.1.2192.168.2.6
                Jan 15, 2025 17:13:42.696980000 CET50284445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:42.696980000 CET50284445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:42.696980953 CET50284445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:42.701893091 CET4455028486.67.1.2192.168.2.6
                Jan 15, 2025 17:13:42.701900959 CET4455028486.67.1.2192.168.2.6
                Jan 15, 2025 17:13:42.803425074 CET50304445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:42.808213949 CET44550304158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:42.808274984 CET50304445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:42.808350086 CET50304445192.168.2.6158.219.90.1
                Jan 15, 2025 17:13:42.813083887 CET44550304158.219.90.1192.168.2.6
                Jan 15, 2025 17:13:43.804908991 CET44550043128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:43.805116892 CET50043445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:43.805147886 CET50043445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:43.805181980 CET50043445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:43.819400072 CET50311445192.168.2.6178.254.121.92
                Jan 15, 2025 17:13:43.928551912 CET50312445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:44.003324032 CET44550043128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:44.003335953 CET44550043128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:44.003365993 CET44550311178.254.121.92192.168.2.6
                Jan 15, 2025 17:13:44.003376007 CET44550312126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:44.003513098 CET50311445192.168.2.6178.254.121.92
                Jan 15, 2025 17:13:44.003671885 CET50311445192.168.2.6178.254.121.92
                Jan 15, 2025 17:13:44.003793955 CET50312445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:44.003894091 CET50313445192.168.2.6178.254.121.1
                Jan 15, 2025 17:13:44.004108906 CET50312445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:44.005091906 CET44550300153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:44.005527973 CET50300445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:44.005547047 CET50300445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:44.005599022 CET50300445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:44.008738995 CET44550313178.254.121.1192.168.2.6
                Jan 15, 2025 17:13:44.008964062 CET44550312126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:44.009051085 CET50313445192.168.2.6178.254.121.1
                Jan 15, 2025 17:13:44.009092093 CET44550311178.254.121.92192.168.2.6
                Jan 15, 2025 17:13:44.009107113 CET50313445192.168.2.6178.254.121.1
                Jan 15, 2025 17:13:44.009155035 CET50311445192.168.2.6178.254.121.92
                Jan 15, 2025 17:13:44.010341883 CET44550300153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:44.010400057 CET44550300153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:44.013959885 CET44550313178.254.121.1192.168.2.6
                Jan 15, 2025 17:13:44.017276049 CET50313445192.168.2.6178.254.121.1
                Jan 15, 2025 17:13:44.020843983 CET50315445192.168.2.6178.254.121.1
                Jan 15, 2025 17:13:44.025840998 CET44550315178.254.121.1192.168.2.6
                Jan 15, 2025 17:13:44.029133081 CET50315445192.168.2.6178.254.121.1
                Jan 15, 2025 17:13:44.029198885 CET50315445192.168.2.6178.254.121.1
                Jan 15, 2025 17:13:44.033931971 CET44550315178.254.121.1192.168.2.6
                Jan 15, 2025 17:13:44.819253922 CET50321445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:44.824187040 CET44550321166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:44.824285984 CET50321445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:44.824285984 CET50321445192.168.2.6166.43.168.1
                Jan 15, 2025 17:13:44.829133987 CET44550321166.43.168.1192.168.2.6
                Jan 15, 2025 17:13:45.350589991 CET50325445192.168.2.6167.139.11.44
                Jan 15, 2025 17:13:45.355535984 CET44550325167.139.11.44192.168.2.6
                Jan 15, 2025 17:13:45.355627060 CET50325445192.168.2.6167.139.11.44
                Jan 15, 2025 17:13:45.355690002 CET50325445192.168.2.6167.139.11.44
                Jan 15, 2025 17:13:45.356123924 CET50326445192.168.2.6167.139.11.1
                Jan 15, 2025 17:13:45.360563040 CET44550325167.139.11.44192.168.2.6
                Jan 15, 2025 17:13:45.360629082 CET50325445192.168.2.6167.139.11.44
                Jan 15, 2025 17:13:45.360960960 CET44550326167.139.11.1192.168.2.6
                Jan 15, 2025 17:13:45.361022949 CET50326445192.168.2.6167.139.11.1
                Jan 15, 2025 17:13:45.361037970 CET50326445192.168.2.6167.139.11.1
                Jan 15, 2025 17:13:45.361310005 CET50327445192.168.2.6167.139.11.1
                Jan 15, 2025 17:13:45.366142035 CET44550327167.139.11.1192.168.2.6
                Jan 15, 2025 17:13:45.366206884 CET50327445192.168.2.6167.139.11.1
                Jan 15, 2025 17:13:45.366238117 CET50327445192.168.2.6167.139.11.1
                Jan 15, 2025 17:13:45.366250038 CET44550326167.139.11.1192.168.2.6
                Jan 15, 2025 17:13:45.366295099 CET50326445192.168.2.6167.139.11.1
                Jan 15, 2025 17:13:45.371073961 CET44550327167.139.11.1192.168.2.6
                Jan 15, 2025 17:13:45.710289001 CET50330445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:45.715112925 CET4455033086.67.1.2192.168.2.6
                Jan 15, 2025 17:13:45.715208054 CET50330445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:45.715277910 CET50330445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:45.720038891 CET4455033086.67.1.2192.168.2.6
                Jan 15, 2025 17:13:45.837024927 CET4455008667.15.60.1192.168.2.6
                Jan 15, 2025 17:13:45.837189913 CET50086445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:45.837189913 CET50086445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:45.837189913 CET50086445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:45.842073917 CET4455008667.15.60.1192.168.2.6
                Jan 15, 2025 17:13:45.842256069 CET4455008667.15.60.1192.168.2.6
                Jan 15, 2025 17:13:45.895879984 CET44550312126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:45.896100998 CET50312445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:45.896100998 CET50312445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:45.896100998 CET50312445192.168.2.6126.217.0.6
                Jan 15, 2025 17:13:45.900963068 CET44550312126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:45.900971889 CET44550312126.217.0.6192.168.2.6
                Jan 15, 2025 17:13:45.959851027 CET50332445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:45.964690924 CET44550332126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:45.964775085 CET50332445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:45.964977980 CET50332445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:45.965431929 CET50333445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:45.969791889 CET44550332126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:45.969862938 CET50332445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:45.970313072 CET44550333126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:45.970393896 CET50333445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:45.970484018 CET50333445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:45.975271940 CET44550333126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:46.773055077 CET50339445192.168.2.6215.114.213.132
                Jan 15, 2025 17:13:46.778028011 CET44550339215.114.213.132192.168.2.6
                Jan 15, 2025 17:13:46.778107882 CET50339445192.168.2.6215.114.213.132
                Jan 15, 2025 17:13:46.778183937 CET50339445192.168.2.6215.114.213.132
                Jan 15, 2025 17:13:46.778338909 CET50340445192.168.2.6215.114.213.1
                Jan 15, 2025 17:13:46.783139944 CET44550339215.114.213.132192.168.2.6
                Jan 15, 2025 17:13:46.783198118 CET44550340215.114.213.1192.168.2.6
                Jan 15, 2025 17:13:46.783200979 CET50339445192.168.2.6215.114.213.132
                Jan 15, 2025 17:13:46.783271074 CET50340445192.168.2.6215.114.213.1
                Jan 15, 2025 17:13:46.783360004 CET50340445192.168.2.6215.114.213.1
                Jan 15, 2025 17:13:46.783704996 CET50341445192.168.2.6215.114.213.1
                Jan 15, 2025 17:13:46.788496017 CET44550340215.114.213.1192.168.2.6
                Jan 15, 2025 17:13:46.788557053 CET50340445192.168.2.6215.114.213.1
                Jan 15, 2025 17:13:46.788635969 CET44550341215.114.213.1192.168.2.6
                Jan 15, 2025 17:13:46.788705111 CET50341445192.168.2.6215.114.213.1
                Jan 15, 2025 17:13:46.788746119 CET50341445192.168.2.6215.114.213.1
                Jan 15, 2025 17:13:46.793520927 CET44550341215.114.213.1192.168.2.6
                Jan 15, 2025 17:13:46.819025993 CET50342445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:46.823939085 CET44550342128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:46.824024916 CET50342445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:46.824069977 CET50342445192.168.2.6128.171.224.1
                Jan 15, 2025 17:13:46.828933954 CET44550342128.171.224.1192.168.2.6
                Jan 15, 2025 17:13:47.006556988 CET50346445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:47.012104988 CET44550346153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:47.012186050 CET50346445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:47.012207031 CET50346445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:47.017123938 CET44550346153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:47.382644892 CET4455033086.67.1.2192.168.2.6
                Jan 15, 2025 17:13:47.382742882 CET50330445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:47.382821083 CET50330445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:47.382821083 CET50330445192.168.2.686.67.1.2
                Jan 15, 2025 17:13:47.387654066 CET4455033086.67.1.2192.168.2.6
                Jan 15, 2025 17:13:47.387682915 CET4455033086.67.1.2192.168.2.6
                Jan 15, 2025 17:13:47.444140911 CET50348445192.168.2.686.67.1.3
                Jan 15, 2025 17:13:47.449134111 CET4455034886.67.1.3192.168.2.6
                Jan 15, 2025 17:13:47.449238062 CET50348445192.168.2.686.67.1.3
                Jan 15, 2025 17:13:47.449274063 CET50348445192.168.2.686.67.1.3
                Jan 15, 2025 17:13:47.449589968 CET50349445192.168.2.686.67.1.3
                Jan 15, 2025 17:13:47.454490900 CET4455034886.67.1.3192.168.2.6
                Jan 15, 2025 17:13:47.454555988 CET50348445192.168.2.686.67.1.3
                Jan 15, 2025 17:13:47.454562902 CET4455034986.67.1.3192.168.2.6
                Jan 15, 2025 17:13:47.454628944 CET50349445192.168.2.686.67.1.3
                Jan 15, 2025 17:13:47.454669952 CET50349445192.168.2.686.67.1.3
                Jan 15, 2025 17:13:47.459491014 CET4455034986.67.1.3192.168.2.6
                Jan 15, 2025 17:13:47.863446951 CET44550333126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:47.863679886 CET50333445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:47.863679886 CET50333445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:47.863679886 CET50333445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:47.868617058 CET44550333126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:47.868632078 CET44550333126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:47.902529001 CET4455012535.167.167.1192.168.2.6
                Jan 15, 2025 17:13:47.902590990 CET50125445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:47.902626991 CET50125445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:47.902676105 CET50125445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:47.907468081 CET4455012535.167.167.1192.168.2.6
                Jan 15, 2025 17:13:47.907497883 CET4455012535.167.167.1192.168.2.6
                Jan 15, 2025 17:13:48.100754023 CET50355445192.168.2.6199.103.224.83
                Jan 15, 2025 17:13:48.105637074 CET44550355199.103.224.83192.168.2.6
                Jan 15, 2025 17:13:48.105722904 CET50355445192.168.2.6199.103.224.83
                Jan 15, 2025 17:13:48.105844975 CET50355445192.168.2.6199.103.224.83
                Jan 15, 2025 17:13:48.106278896 CET50356445192.168.2.6199.103.224.1
                Jan 15, 2025 17:13:48.110842943 CET44550355199.103.224.83192.168.2.6
                Jan 15, 2025 17:13:48.110902071 CET50355445192.168.2.6199.103.224.83
                Jan 15, 2025 17:13:48.111040115 CET44550356199.103.224.1192.168.2.6
                Jan 15, 2025 17:13:48.111092091 CET50356445192.168.2.6199.103.224.1
                Jan 15, 2025 17:13:48.111183882 CET50356445192.168.2.6199.103.224.1
                Jan 15, 2025 17:13:48.111522913 CET50357445192.168.2.6199.103.224.1
                Jan 15, 2025 17:13:48.116328955 CET44550357199.103.224.1192.168.2.6
                Jan 15, 2025 17:13:48.116415024 CET50357445192.168.2.6199.103.224.1
                Jan 15, 2025 17:13:48.116481066 CET50357445192.168.2.6199.103.224.1
                Jan 15, 2025 17:13:48.116802931 CET44550356199.103.224.1192.168.2.6
                Jan 15, 2025 17:13:48.116848946 CET50356445192.168.2.6199.103.224.1
                Jan 15, 2025 17:13:48.121273041 CET44550357199.103.224.1192.168.2.6
                Jan 15, 2025 17:13:48.460752964 CET44550346153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:48.460812092 CET50346445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:48.460840940 CET50346445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:48.460871935 CET50346445192.168.2.6153.9.75.6
                Jan 15, 2025 17:13:48.465662956 CET44550346153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:48.465677977 CET44550346153.9.75.6192.168.2.6
                Jan 15, 2025 17:13:48.522274017 CET50360445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:48.527162075 CET44550360153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:48.527237892 CET50360445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:48.527328014 CET50360445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:48.527627945 CET50361445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:48.532191992 CET44550360153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:48.532248974 CET50360445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:48.532516003 CET44550361153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:48.532694101 CET50361445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:48.532694101 CET50361445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:48.537463903 CET44550361153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:48.850385904 CET50363445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:48.855437040 CET4455036367.15.60.1192.168.2.6
                Jan 15, 2025 17:13:48.855529070 CET50363445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:48.855576038 CET50363445192.168.2.667.15.60.1
                Jan 15, 2025 17:13:48.860316992 CET4455036367.15.60.1192.168.2.6
                Jan 15, 2025 17:13:49.351053953 CET50364445192.168.2.672.24.241.54
                Jan 15, 2025 17:13:49.355870962 CET4455036472.24.241.54192.168.2.6
                Jan 15, 2025 17:13:49.355963945 CET50364445192.168.2.672.24.241.54
                Jan 15, 2025 17:13:49.356008053 CET50364445192.168.2.672.24.241.54
                Jan 15, 2025 17:13:49.356138945 CET50365445192.168.2.672.24.241.1
                Jan 15, 2025 17:13:49.360971928 CET4455036572.24.241.1192.168.2.6
                Jan 15, 2025 17:13:49.360987902 CET4455036472.24.241.54192.168.2.6
                Jan 15, 2025 17:13:49.361097097 CET50365445192.168.2.672.24.241.1
                Jan 15, 2025 17:13:49.361505032 CET50364445192.168.2.672.24.241.54
                Jan 15, 2025 17:13:49.361505032 CET50365445192.168.2.672.24.241.1
                Jan 15, 2025 17:13:49.361524105 CET50366445192.168.2.672.24.241.1
                Jan 15, 2025 17:13:49.366399050 CET4455036572.24.241.1192.168.2.6
                Jan 15, 2025 17:13:49.366422892 CET4455036672.24.241.1192.168.2.6
                Jan 15, 2025 17:13:49.366492987 CET50365445192.168.2.672.24.241.1
                Jan 15, 2025 17:13:49.366528034 CET50366445192.168.2.672.24.241.1
                Jan 15, 2025 17:13:49.366574049 CET50366445192.168.2.672.24.241.1
                Jan 15, 2025 17:13:49.371351957 CET4455036672.24.241.1192.168.2.6
                Jan 15, 2025 17:13:49.851751089 CET44550162131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:49.851824999 CET50162445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:49.851850986 CET50162445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:49.851906061 CET50162445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:49.856683969 CET44550162131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:49.856697083 CET44550162131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:49.989734888 CET44550361153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:49.989844084 CET50361445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:49.989901066 CET50361445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:49.989918947 CET50361445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:49.994774103 CET44550361153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:49.994786978 CET44550361153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:50.507209063 CET50367445192.168.2.644.163.244.22
                Jan 15, 2025 17:13:50.512219906 CET4455036744.163.244.22192.168.2.6
                Jan 15, 2025 17:13:50.512342930 CET50367445192.168.2.644.163.244.22
                Jan 15, 2025 17:13:50.512432098 CET50367445192.168.2.644.163.244.22
                Jan 15, 2025 17:13:50.512763023 CET50368445192.168.2.644.163.244.1
                Jan 15, 2025 17:13:50.517374992 CET4455036744.163.244.22192.168.2.6
                Jan 15, 2025 17:13:50.517451048 CET50367445192.168.2.644.163.244.22
                Jan 15, 2025 17:13:50.517611980 CET4455036844.163.244.1192.168.2.6
                Jan 15, 2025 17:13:50.517680883 CET50368445192.168.2.644.163.244.1
                Jan 15, 2025 17:13:50.517723083 CET50368445192.168.2.644.163.244.1
                Jan 15, 2025 17:13:50.517976999 CET50369445192.168.2.644.163.244.1
                Jan 15, 2025 17:13:50.522743940 CET4455036844.163.244.1192.168.2.6
                Jan 15, 2025 17:13:50.522816896 CET50368445192.168.2.644.163.244.1
                Jan 15, 2025 17:13:50.522856951 CET4455036944.163.244.1192.168.2.6
                Jan 15, 2025 17:13:50.522918940 CET50369445192.168.2.644.163.244.1
                Jan 15, 2025 17:13:50.522954941 CET50369445192.168.2.644.163.244.1
                Jan 15, 2025 17:13:50.527782917 CET4455036944.163.244.1192.168.2.6
                Jan 15, 2025 17:13:50.866034985 CET50370445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:50.870987892 CET44550370126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:50.871083021 CET50370445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:50.871145964 CET50370445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:50.876009941 CET44550370126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:50.913000107 CET50371445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:50.917898893 CET4455037135.167.167.1192.168.2.6
                Jan 15, 2025 17:13:50.917990923 CET50371445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:50.918025970 CET50371445192.168.2.635.167.167.1
                Jan 15, 2025 17:13:50.922776937 CET4455037135.167.167.1192.168.2.6
                Jan 15, 2025 17:13:51.585134983 CET50372445192.168.2.6191.42.119.111
                Jan 15, 2025 17:13:51.589927912 CET44550372191.42.119.111192.168.2.6
                Jan 15, 2025 17:13:51.590014935 CET50372445192.168.2.6191.42.119.111
                Jan 15, 2025 17:13:51.590172052 CET50372445192.168.2.6191.42.119.111
                Jan 15, 2025 17:13:51.590178967 CET50373445192.168.2.6191.42.119.1
                Jan 15, 2025 17:13:51.595103979 CET44550373191.42.119.1192.168.2.6
                Jan 15, 2025 17:13:51.595165014 CET50373445192.168.2.6191.42.119.1
                Jan 15, 2025 17:13:51.595201969 CET50373445192.168.2.6191.42.119.1
                Jan 15, 2025 17:13:51.595274925 CET44550372191.42.119.111192.168.2.6
                Jan 15, 2025 17:13:51.595326900 CET50372445192.168.2.6191.42.119.111
                Jan 15, 2025 17:13:51.595415115 CET50374445192.168.2.6191.42.119.1
                Jan 15, 2025 17:13:51.600116968 CET44550373191.42.119.1192.168.2.6
                Jan 15, 2025 17:13:51.600167036 CET50373445192.168.2.6191.42.119.1
                Jan 15, 2025 17:13:51.600313902 CET44550374191.42.119.1192.168.2.6
                Jan 15, 2025 17:13:51.600486040 CET50374445192.168.2.6191.42.119.1
                Jan 15, 2025 17:13:51.600486994 CET50374445192.168.2.6191.42.119.1
                Jan 15, 2025 17:13:51.605341911 CET44550374191.42.119.1192.168.2.6
                Jan 15, 2025 17:13:51.886933088 CET44550185107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:51.887001038 CET50185445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:51.887049913 CET50185445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:51.887109041 CET50185445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:51.891933918 CET44550185107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:51.891947985 CET44550185107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:52.086174965 CET4455018824.145.43.1192.168.2.6
                Jan 15, 2025 17:13:52.086239100 CET50188445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:52.086288929 CET50188445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:52.086345911 CET50188445192.168.2.624.145.43.1
                Jan 15, 2025 17:13:52.091154099 CET4455018824.145.43.1192.168.2.6
                Jan 15, 2025 17:13:52.091171026 CET4455018824.145.43.1192.168.2.6
                Jan 15, 2025 17:13:52.147567034 CET50375445192.168.2.624.145.43.2
                Jan 15, 2025 17:13:52.152380943 CET4455037524.145.43.2192.168.2.6
                Jan 15, 2025 17:13:52.152568102 CET50375445192.168.2.624.145.43.2
                Jan 15, 2025 17:13:52.152568102 CET50375445192.168.2.624.145.43.2
                Jan 15, 2025 17:13:52.152884007 CET50376445192.168.2.624.145.43.2
                Jan 15, 2025 17:13:52.157691002 CET4455037524.145.43.2192.168.2.6
                Jan 15, 2025 17:13:52.157754898 CET4455037624.145.43.2192.168.2.6
                Jan 15, 2025 17:13:52.157753944 CET50375445192.168.2.624.145.43.2
                Jan 15, 2025 17:13:52.157820940 CET50376445192.168.2.624.145.43.2
                Jan 15, 2025 17:13:52.157861948 CET50376445192.168.2.624.145.43.2
                Jan 15, 2025 17:13:52.162753105 CET4455037624.145.43.2192.168.2.6
                Jan 15, 2025 17:13:52.600877047 CET50377445192.168.2.6221.250.196.145
                Jan 15, 2025 17:13:52.605868101 CET44550377221.250.196.145192.168.2.6
                Jan 15, 2025 17:13:52.606192112 CET50377445192.168.2.6221.250.196.145
                Jan 15, 2025 17:13:52.606192112 CET50377445192.168.2.6221.250.196.145
                Jan 15, 2025 17:13:52.606303930 CET50378445192.168.2.6221.250.196.1
                Jan 15, 2025 17:13:52.611331940 CET44550378221.250.196.1192.168.2.6
                Jan 15, 2025 17:13:52.611393929 CET50378445192.168.2.6221.250.196.1
                Jan 15, 2025 17:13:52.611432076 CET50378445192.168.2.6221.250.196.1
                Jan 15, 2025 17:13:52.611543894 CET44550377221.250.196.145192.168.2.6
                Jan 15, 2025 17:13:52.611773968 CET50379445192.168.2.6221.250.196.1
                Jan 15, 2025 17:13:52.616729021 CET44550379221.250.196.1192.168.2.6
                Jan 15, 2025 17:13:52.616911888 CET50379445192.168.2.6221.250.196.1
                Jan 15, 2025 17:13:52.616913080 CET50379445192.168.2.6221.250.196.1
                Jan 15, 2025 17:13:52.617208004 CET44550377221.250.196.145192.168.2.6
                Jan 15, 2025 17:13:52.617321968 CET44550378221.250.196.1192.168.2.6
                Jan 15, 2025 17:13:52.617371082 CET50378445192.168.2.6221.250.196.1
                Jan 15, 2025 17:13:52.617378950 CET50377445192.168.2.6221.250.196.145
                Jan 15, 2025 17:13:52.621769905 CET44550379221.250.196.1192.168.2.6
                Jan 15, 2025 17:13:52.738945961 CET44550370126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:52.739140034 CET50370445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:52.739140034 CET50370445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:52.740684032 CET50370445192.168.2.6126.217.0.7
                Jan 15, 2025 17:13:52.744077921 CET44550370126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:52.745492935 CET44550370126.217.0.7192.168.2.6
                Jan 15, 2025 17:13:52.803622961 CET50380445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:52.808465004 CET44550380126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:52.808554888 CET50380445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:52.808593988 CET50380445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:52.808955908 CET50381445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:52.813707113 CET44550380126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:52.813766003 CET50380445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:52.813849926 CET44550381126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:52.814003944 CET50381445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:52.814003944 CET50381445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:52.818979025 CET44550381126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:52.866105080 CET50382445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:52.871087074 CET44550382131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:52.871181011 CET50382445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:52.871205091 CET50382445192.168.2.6131.24.232.1
                Jan 15, 2025 17:13:52.876108885 CET44550382131.24.232.1192.168.2.6
                Jan 15, 2025 17:13:52.991167068 CET50383445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:52.996058941 CET44550383153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:52.996150017 CET50383445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:52.996289015 CET50383445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:53.001586914 CET44550383153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:53.538388014 CET50385445192.168.2.6201.222.228.147
                Jan 15, 2025 17:13:53.543401003 CET44550385201.222.228.147192.168.2.6
                Jan 15, 2025 17:13:53.543643951 CET50385445192.168.2.6201.222.228.147
                Jan 15, 2025 17:13:53.543643951 CET50385445192.168.2.6201.222.228.147
                Jan 15, 2025 17:13:53.543760061 CET50386445192.168.2.6201.222.228.1
                Jan 15, 2025 17:13:53.548635960 CET44550386201.222.228.1192.168.2.6
                Jan 15, 2025 17:13:53.548724890 CET50386445192.168.2.6201.222.228.1
                Jan 15, 2025 17:13:53.548726082 CET50386445192.168.2.6201.222.228.1
                Jan 15, 2025 17:13:53.549164057 CET50387445192.168.2.6201.222.228.1
                Jan 15, 2025 17:13:53.550498962 CET44550385201.222.228.147192.168.2.6
                Jan 15, 2025 17:13:53.550708055 CET50385445192.168.2.6201.222.228.147
                Jan 15, 2025 17:13:53.553868055 CET44550386201.222.228.1192.168.2.6
                Jan 15, 2025 17:13:53.553992033 CET50386445192.168.2.6201.222.228.1
                Jan 15, 2025 17:13:53.554106951 CET44550387201.222.228.1192.168.2.6
                Jan 15, 2025 17:13:53.554194927 CET50387445192.168.2.6201.222.228.1
                Jan 15, 2025 17:13:53.554239988 CET50387445192.168.2.6201.222.228.1
                Jan 15, 2025 17:13:53.559027910 CET44550387201.222.228.1192.168.2.6
                Jan 15, 2025 17:13:53.899211884 CET44550204146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:53.899292946 CET50204445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:53.899389029 CET50204445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:53.899389029 CET50204445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:53.904611111 CET44550204146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:53.904652119 CET44550204146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:54.056875944 CET4455020732.209.198.1192.168.2.6
                Jan 15, 2025 17:13:54.056951046 CET50207445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:54.056992054 CET50207445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:54.057050943 CET50207445192.168.2.632.209.198.1
                Jan 15, 2025 17:13:54.063287973 CET4455020732.209.198.1192.168.2.6
                Jan 15, 2025 17:13:54.063302040 CET4455020732.209.198.1192.168.2.6
                Jan 15, 2025 17:13:54.116213083 CET50388445192.168.2.632.209.198.2
                Jan 15, 2025 17:13:54.121074915 CET4455038832.209.198.2192.168.2.6
                Jan 15, 2025 17:13:54.121248960 CET50388445192.168.2.632.209.198.2
                Jan 15, 2025 17:13:54.121330023 CET50388445192.168.2.632.209.198.2
                Jan 15, 2025 17:13:54.121701956 CET50389445192.168.2.632.209.198.2
                Jan 15, 2025 17:13:54.126328945 CET4455038832.209.198.2192.168.2.6
                Jan 15, 2025 17:13:54.126405001 CET50388445192.168.2.632.209.198.2
                Jan 15, 2025 17:13:54.126475096 CET4455038932.209.198.2192.168.2.6
                Jan 15, 2025 17:13:54.126554012 CET50389445192.168.2.632.209.198.2
                Jan 15, 2025 17:13:54.126605034 CET50389445192.168.2.632.209.198.2
                Jan 15, 2025 17:13:54.133239985 CET4455038932.209.198.2192.168.2.6
                Jan 15, 2025 17:13:54.413235903 CET50390445192.168.2.6163.74.34.120
                Jan 15, 2025 17:13:54.418370008 CET44550390163.74.34.120192.168.2.6
                Jan 15, 2025 17:13:54.418493986 CET50390445192.168.2.6163.74.34.120
                Jan 15, 2025 17:13:54.418606043 CET50390445192.168.2.6163.74.34.120
                Jan 15, 2025 17:13:54.418839931 CET50391445192.168.2.6163.74.34.1
                Jan 15, 2025 17:13:54.423566103 CET44550390163.74.34.120192.168.2.6
                Jan 15, 2025 17:13:54.423719883 CET44550391163.74.34.1192.168.2.6
                Jan 15, 2025 17:13:54.423798084 CET44550390163.74.34.120192.168.2.6
                Jan 15, 2025 17:13:54.423799992 CET50391445192.168.2.6163.74.34.1
                Jan 15, 2025 17:13:54.423854113 CET50390445192.168.2.6163.74.34.120
                Jan 15, 2025 17:13:54.423898935 CET50391445192.168.2.6163.74.34.1
                Jan 15, 2025 17:13:54.424247980 CET50392445192.168.2.6163.74.34.1
                Jan 15, 2025 17:13:54.428760052 CET44550391163.74.34.1192.168.2.6
                Jan 15, 2025 17:13:54.428832054 CET50391445192.168.2.6163.74.34.1
                Jan 15, 2025 17:13:54.429099083 CET44550392163.74.34.1192.168.2.6
                Jan 15, 2025 17:13:54.429167986 CET50392445192.168.2.6163.74.34.1
                Jan 15, 2025 17:13:54.429208040 CET50392445192.168.2.6163.74.34.1
                Jan 15, 2025 17:13:54.434138060 CET44550392163.74.34.1192.168.2.6
                Jan 15, 2025 17:13:54.574920893 CET44550383153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:54.574995041 CET50383445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:54.575062990 CET50383445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:54.575166941 CET50383445192.168.2.6153.9.75.7
                Jan 15, 2025 17:13:54.580009937 CET44550383153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:54.580039978 CET44550383153.9.75.7192.168.2.6
                Jan 15, 2025 17:13:54.661775112 CET50393445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:54.666894913 CET44550393153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:54.667114019 CET50393445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:54.667114019 CET50393445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:54.667553902 CET50394445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:54.672158003 CET44550393153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:54.672329903 CET50393445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:54.672425985 CET44550394153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:54.672488928 CET50394445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:54.672519922 CET50394445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:54.677308083 CET44550394153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:54.689687014 CET44550381126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:54.689747095 CET50381445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:54.689860106 CET50381445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:54.689912081 CET50381445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:54.694602966 CET44550381126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:54.694694042 CET44550381126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:54.897252083 CET50395445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:54.902100086 CET44550395107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:54.902213097 CET50395445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:54.902230024 CET50395445192.168.2.6107.234.183.1
                Jan 15, 2025 17:13:54.907001972 CET44550395107.234.183.1192.168.2.6
                Jan 15, 2025 17:13:55.241379976 CET50396445192.168.2.6206.195.253.220
                Jan 15, 2025 17:13:55.246179104 CET44550396206.195.253.220192.168.2.6
                Jan 15, 2025 17:13:55.246260881 CET50396445192.168.2.6206.195.253.220
                Jan 15, 2025 17:13:55.246337891 CET50396445192.168.2.6206.195.253.220
                Jan 15, 2025 17:13:55.246494055 CET50397445192.168.2.6206.195.253.1
                Jan 15, 2025 17:13:55.251235962 CET44550397206.195.253.1192.168.2.6
                Jan 15, 2025 17:13:55.251296043 CET50397445192.168.2.6206.195.253.1
                Jan 15, 2025 17:13:55.251323938 CET50397445192.168.2.6206.195.253.1
                Jan 15, 2025 17:13:55.251523972 CET44550396206.195.253.220192.168.2.6
                Jan 15, 2025 17:13:55.251708031 CET50398445192.168.2.6206.195.253.1
                Jan 15, 2025 17:13:55.256484985 CET44550398206.195.253.1192.168.2.6
                Jan 15, 2025 17:13:55.256540060 CET50398445192.168.2.6206.195.253.1
                Jan 15, 2025 17:13:55.256597042 CET50398445192.168.2.6206.195.253.1
                Jan 15, 2025 17:13:55.259538889 CET44550397206.195.253.1192.168.2.6
                Jan 15, 2025 17:13:55.260538101 CET44550396206.195.253.220192.168.2.6
                Jan 15, 2025 17:13:55.260581017 CET50396445192.168.2.6206.195.253.220
                Jan 15, 2025 17:13:55.260832071 CET44550397206.195.253.1192.168.2.6
                Jan 15, 2025 17:13:55.260874987 CET50397445192.168.2.6206.195.253.1
                Jan 15, 2025 17:13:55.261372089 CET44550398206.195.253.1192.168.2.6
                Jan 15, 2025 17:13:56.006959915 CET50399445192.168.2.686.64.193.173
                Jan 15, 2025 17:13:56.012022018 CET4455039986.64.193.173192.168.2.6
                Jan 15, 2025 17:13:56.012176037 CET50399445192.168.2.686.64.193.173
                Jan 15, 2025 17:13:56.012300014 CET50399445192.168.2.686.64.193.173
                Jan 15, 2025 17:13:56.012310982 CET50400445192.168.2.686.64.193.1
                Jan 15, 2025 17:13:56.017122030 CET4455040086.64.193.1192.168.2.6
                Jan 15, 2025 17:13:56.017211914 CET50400445192.168.2.686.64.193.1
                Jan 15, 2025 17:13:56.017213106 CET50400445192.168.2.686.64.193.1
                Jan 15, 2025 17:13:56.017348051 CET4455039986.64.193.173192.168.2.6
                Jan 15, 2025 17:13:56.017402887 CET50399445192.168.2.686.64.193.173
                Jan 15, 2025 17:13:56.017564058 CET50401445192.168.2.686.64.193.1
                Jan 15, 2025 17:13:56.022212029 CET4455040086.64.193.1192.168.2.6
                Jan 15, 2025 17:13:56.022291899 CET50400445192.168.2.686.64.193.1
                Jan 15, 2025 17:13:56.022352934 CET4455040186.64.193.1192.168.2.6
                Jan 15, 2025 17:13:56.022414923 CET50401445192.168.2.686.64.193.1
                Jan 15, 2025 17:13:56.022449970 CET50401445192.168.2.686.64.193.1
                Jan 15, 2025 17:13:56.027245045 CET4455040186.64.193.1192.168.2.6
                Jan 15, 2025 17:13:56.133447886 CET4455022364.71.233.1192.168.2.6
                Jan 15, 2025 17:13:56.133567095 CET50223445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:56.133647919 CET50223445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:56.133745909 CET50223445192.168.2.664.71.233.1
                Jan 15, 2025 17:13:56.138668060 CET4455022364.71.233.1192.168.2.6
                Jan 15, 2025 17:13:56.138678074 CET4455022364.71.233.1192.168.2.6
                Jan 15, 2025 17:13:56.178791046 CET44550394153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:56.178896904 CET50394445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:56.178909063 CET50394445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:56.178950071 CET50394445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:56.183780909 CET44550394153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:56.183789968 CET44550394153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:56.194463968 CET50402445192.168.2.664.71.233.2
                Jan 15, 2025 17:13:56.199378967 CET4455040264.71.233.2192.168.2.6
                Jan 15, 2025 17:13:56.199487925 CET50402445192.168.2.664.71.233.2
                Jan 15, 2025 17:13:56.199489117 CET50402445192.168.2.664.71.233.2
                Jan 15, 2025 17:13:56.199812889 CET50403445192.168.2.664.71.233.2
                Jan 15, 2025 17:13:56.204454899 CET4455040264.71.233.2192.168.2.6
                Jan 15, 2025 17:13:56.204592943 CET50402445192.168.2.664.71.233.2
                Jan 15, 2025 17:13:56.204629898 CET4455040364.71.233.2192.168.2.6
                Jan 15, 2025 17:13:56.204691887 CET50403445192.168.2.664.71.233.2
                Jan 15, 2025 17:13:56.204736948 CET50403445192.168.2.664.71.233.2
                Jan 15, 2025 17:13:56.209486008 CET4455040364.71.233.2192.168.2.6
                Jan 15, 2025 17:13:56.912950993 CET50405445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:56.917754889 CET44550405146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:56.917862892 CET50405445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:56.917953014 CET50405445192.168.2.6146.244.82.1
                Jan 15, 2025 17:13:56.922772884 CET44550405146.244.82.1192.168.2.6
                Jan 15, 2025 17:13:57.694185019 CET50407445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:57.699116945 CET44550407126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:57.699196100 CET50407445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:57.699233055 CET50407445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:57.704082012 CET44550407126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:57.951608896 CET44550242217.163.243.1192.168.2.6
                Jan 15, 2025 17:13:57.951736927 CET50242445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:57.951797009 CET50242445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:57.951797962 CET50242445192.168.2.6217.163.243.1
                Jan 15, 2025 17:13:57.956612110 CET44550242217.163.243.1192.168.2.6
                Jan 15, 2025 17:13:57.956625938 CET44550242217.163.243.1192.168.2.6
                Jan 15, 2025 17:13:59.194103956 CET50415445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:59.198930025 CET44550415153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:59.199032068 CET50415445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:59.199054956 CET50415445192.168.2.6153.9.75.8
                Jan 15, 2025 17:13:59.203885078 CET44550415153.9.75.8192.168.2.6
                Jan 15, 2025 17:13:59.628976107 CET44550407126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:59.629323959 CET50407445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:59.629323959 CET50407445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:59.629323959 CET50407445192.168.2.6126.217.0.8
                Jan 15, 2025 17:13:59.634248972 CET44550407126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:59.634267092 CET44550407126.217.0.8192.168.2.6
                Jan 15, 2025 17:13:59.694464922 CET50418445192.168.2.6126.217.0.9
                Jan 15, 2025 17:13:59.699289083 CET44550418126.217.0.9192.168.2.6
                Jan 15, 2025 17:13:59.699460030 CET50418445192.168.2.6126.217.0.9
                Jan 15, 2025 17:13:59.699460030 CET50418445192.168.2.6126.217.0.9
                Jan 15, 2025 17:13:59.699846029 CET50419445192.168.2.6126.217.0.9
                Jan 15, 2025 17:13:59.704648018 CET44550418126.217.0.9192.168.2.6
                Jan 15, 2025 17:13:59.704724073 CET44550419126.217.0.9192.168.2.6
                Jan 15, 2025 17:13:59.704782963 CET50419445192.168.2.6126.217.0.9
                Jan 15, 2025 17:13:59.704804897 CET50419445192.168.2.6126.217.0.9
                Jan 15, 2025 17:13:59.704807043 CET50418445192.168.2.6126.217.0.9
                Jan 15, 2025 17:13:59.709625006 CET44550419126.217.0.9192.168.2.6
                Jan 15, 2025 17:13:59.963342905 CET44550258183.177.251.1192.168.2.6
                Jan 15, 2025 17:13:59.963614941 CET50258445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:59.963615894 CET50258445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:59.963615894 CET50258445192.168.2.6183.177.251.1
                Jan 15, 2025 17:13:59.968705893 CET44550258183.177.251.1192.168.2.6
                Jan 15, 2025 17:13:59.968738079 CET44550258183.177.251.1192.168.2.6
                Jan 15, 2025 17:14:00.164554119 CET44550261176.57.93.1192.168.2.6
                Jan 15, 2025 17:14:00.164812088 CET50261445192.168.2.6176.57.93.1
                Jan 15, 2025 17:14:00.164812088 CET50261445192.168.2.6176.57.93.1
                Jan 15, 2025 17:14:00.164915085 CET50261445192.168.2.6176.57.93.1
                Jan 15, 2025 17:14:00.169765949 CET44550261176.57.93.1192.168.2.6
                Jan 15, 2025 17:14:00.169785023 CET44550261176.57.93.1192.168.2.6
                Jan 15, 2025 17:14:00.225740910 CET50423445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:00.230577946 CET44550423176.57.93.2192.168.2.6
                Jan 15, 2025 17:14:00.230674982 CET50423445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:00.230716944 CET50423445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:00.231194019 CET50424445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:00.236001968 CET44550424176.57.93.2192.168.2.6
                Jan 15, 2025 17:14:00.236095905 CET50424445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:00.236134052 CET50424445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:00.239563942 CET44550423176.57.93.2192.168.2.6
                Jan 15, 2025 17:14:00.240874052 CET44550424176.57.93.2192.168.2.6
                Jan 15, 2025 17:14:00.261924028 CET44550423176.57.93.2192.168.2.6
                Jan 15, 2025 17:14:00.262042046 CET50423445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:00.728893042 CET44550415153.9.75.8192.168.2.6
                Jan 15, 2025 17:14:00.729109049 CET50415445192.168.2.6153.9.75.8
                Jan 15, 2025 17:14:00.729110003 CET50415445192.168.2.6153.9.75.8
                Jan 15, 2025 17:14:00.729110003 CET50415445192.168.2.6153.9.75.8
                Jan 15, 2025 17:14:00.734023094 CET44550415153.9.75.8192.168.2.6
                Jan 15, 2025 17:14:00.734039068 CET44550415153.9.75.8192.168.2.6
                Jan 15, 2025 17:14:00.788346052 CET50430445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:00.793344021 CET44550430153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:00.793495893 CET50430445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:00.793570995 CET50430445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:00.793937922 CET50431445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:00.798569918 CET44550430153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:00.798666954 CET50430445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:00.798733950 CET44550431153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:00.798831940 CET50431445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:00.798897982 CET50431445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:00.803675890 CET44550431153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:00.959935904 CET50433445192.168.2.6217.163.243.1
                Jan 15, 2025 17:14:00.964766979 CET44550433217.163.243.1192.168.2.6
                Jan 15, 2025 17:14:00.964848995 CET50433445192.168.2.6217.163.243.1
                Jan 15, 2025 17:14:00.964878082 CET50433445192.168.2.6217.163.243.1
                Jan 15, 2025 17:14:00.969640017 CET44550433217.163.243.1192.168.2.6
                Jan 15, 2025 17:14:01.618029118 CET44550419126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:01.618109941 CET50419445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:01.618146896 CET50419445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:01.618191957 CET50419445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:01.622951031 CET44550419126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:01.622988939 CET44550419126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:01.837286949 CET44550277187.139.204.1192.168.2.6
                Jan 15, 2025 17:14:01.837373972 CET50277445192.168.2.6187.139.204.1
                Jan 15, 2025 17:14:01.837431908 CET50277445192.168.2.6187.139.204.1
                Jan 15, 2025 17:14:01.837493896 CET50277445192.168.2.6187.139.204.1
                Jan 15, 2025 17:14:01.842400074 CET44550277187.139.204.1192.168.2.6
                Jan 15, 2025 17:14:01.842428923 CET44550277187.139.204.1192.168.2.6
                Jan 15, 2025 17:14:02.199691057 CET44550280202.166.106.1192.168.2.6
                Jan 15, 2025 17:14:02.200047970 CET50280445192.168.2.6202.166.106.1
                Jan 15, 2025 17:14:02.208703995 CET50280445192.168.2.6202.166.106.1
                Jan 15, 2025 17:14:02.208735943 CET50280445192.168.2.6202.166.106.1
                Jan 15, 2025 17:14:02.213534117 CET44550280202.166.106.1192.168.2.6
                Jan 15, 2025 17:14:02.213562965 CET44550280202.166.106.1192.168.2.6
                Jan 15, 2025 17:14:02.313057899 CET50447445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:02.514353037 CET44550431153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:02.514422894 CET50431445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:02.514463902 CET50431445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:02.514493942 CET50431445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:02.515408993 CET44550447202.166.106.2192.168.2.6
                Jan 15, 2025 17:14:02.515499115 CET50447445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:02.515547991 CET44550431153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:02.515571117 CET50447445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:02.515588045 CET50431445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:02.519505024 CET44550431153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:02.519532919 CET44550431153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:02.520009041 CET50453445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:02.520490885 CET44550431153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:02.520669937 CET44550447202.166.106.2192.168.2.6
                Jan 15, 2025 17:14:02.520725012 CET50447445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:02.524904966 CET44550453202.166.106.2192.168.2.6
                Jan 15, 2025 17:14:02.524979115 CET50453445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:02.531124115 CET50453445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:02.536056042 CET44550453202.166.106.2192.168.2.6
                Jan 15, 2025 17:14:02.975367069 CET50458445192.168.2.6183.177.251.1
                Jan 15, 2025 17:14:02.980317116 CET44550458183.177.251.1192.168.2.6
                Jan 15, 2025 17:14:02.980549097 CET50458445192.168.2.6183.177.251.1
                Jan 15, 2025 17:14:02.980699062 CET50458445192.168.2.6183.177.251.1
                Jan 15, 2025 17:14:02.985560894 CET44550458183.177.251.1192.168.2.6
                Jan 15, 2025 17:14:03.572737932 CET445502965.166.179.1192.168.2.6
                Jan 15, 2025 17:14:03.572829008 CET50296445192.168.2.65.166.179.1
                Jan 15, 2025 17:14:03.572953939 CET50296445192.168.2.65.166.179.1
                Jan 15, 2025 17:14:03.572990894 CET50296445192.168.2.65.166.179.1
                Jan 15, 2025 17:14:03.577796936 CET445502965.166.179.1192.168.2.6
                Jan 15, 2025 17:14:03.577811003 CET445502965.166.179.1192.168.2.6
                Jan 15, 2025 17:14:04.205792904 CET44550304158.219.90.1192.168.2.6
                Jan 15, 2025 17:14:04.206007004 CET50304445192.168.2.6158.219.90.1
                Jan 15, 2025 17:14:04.206053972 CET50304445192.168.2.6158.219.90.1
                Jan 15, 2025 17:14:04.206089973 CET50304445192.168.2.6158.219.90.1
                Jan 15, 2025 17:14:04.210799932 CET44550304158.219.90.1192.168.2.6
                Jan 15, 2025 17:14:04.210978031 CET44550304158.219.90.1192.168.2.6
                Jan 15, 2025 17:14:04.256953955 CET50483445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:04.261876106 CET44550483158.219.90.2192.168.2.6
                Jan 15, 2025 17:14:04.261965036 CET50483445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:04.262012959 CET50483445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:04.262550116 CET50484445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:04.267409086 CET44550484158.219.90.2192.168.2.6
                Jan 15, 2025 17:14:04.267504930 CET50484445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:04.267504930 CET50484445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:04.267537117 CET44550483158.219.90.2192.168.2.6
                Jan 15, 2025 17:14:04.267977953 CET44550483158.219.90.2192.168.2.6
                Jan 15, 2025 17:14:04.268023014 CET50483445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:04.272440910 CET44550484158.219.90.2192.168.2.6
                Jan 15, 2025 17:14:04.631596088 CET50490445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:04.636460066 CET44550490126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:04.636533022 CET50490445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:04.636559963 CET50490445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:04.641330957 CET44550490126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:04.850382090 CET50499445192.168.2.6187.139.204.1
                Jan 15, 2025 17:14:04.855427980 CET44550499187.139.204.1192.168.2.6
                Jan 15, 2025 17:14:04.855509043 CET50499445192.168.2.6187.139.204.1
                Jan 15, 2025 17:14:04.855545998 CET50499445192.168.2.6187.139.204.1
                Jan 15, 2025 17:14:04.860338926 CET44550499187.139.204.1192.168.2.6
                Jan 15, 2025 17:14:05.399183989 CET44550315178.254.121.1192.168.2.6
                Jan 15, 2025 17:14:05.399277925 CET50315445192.168.2.6178.254.121.1
                Jan 15, 2025 17:14:05.399322033 CET50315445192.168.2.6178.254.121.1
                Jan 15, 2025 17:14:05.399359941 CET50315445192.168.2.6178.254.121.1
                Jan 15, 2025 17:14:05.404310942 CET44550315178.254.121.1192.168.2.6
                Jan 15, 2025 17:14:05.404339075 CET44550315178.254.121.1192.168.2.6
                Jan 15, 2025 17:14:05.522301912 CET50516445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:05.527298927 CET44550516153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:05.527383089 CET50516445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:05.527426004 CET50516445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:05.532269955 CET44550516153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:06.180325985 CET44550321166.43.168.1192.168.2.6
                Jan 15, 2025 17:14:06.180439949 CET50321445192.168.2.6166.43.168.1
                Jan 15, 2025 17:14:06.180440903 CET50321445192.168.2.6166.43.168.1
                Jan 15, 2025 17:14:06.180529118 CET50321445192.168.2.6166.43.168.1
                Jan 15, 2025 17:14:06.185396910 CET44550321166.43.168.1192.168.2.6
                Jan 15, 2025 17:14:06.185425997 CET44550321166.43.168.1192.168.2.6
                Jan 15, 2025 17:14:06.241101980 CET50542445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:06.246089935 CET44550542166.43.168.2192.168.2.6
                Jan 15, 2025 17:14:06.246303082 CET50542445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:06.246303082 CET50542445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:06.246453047 CET50543445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:06.251346111 CET44550543166.43.168.2192.168.2.6
                Jan 15, 2025 17:14:06.251409054 CET50543445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:06.251431942 CET50543445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:06.251646042 CET44550542166.43.168.2192.168.2.6
                Jan 15, 2025 17:14:06.256264925 CET44550543166.43.168.2192.168.2.6
                Jan 15, 2025 17:14:06.258532047 CET44550542166.43.168.2192.168.2.6
                Jan 15, 2025 17:14:06.258610964 CET50542445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:06.466382980 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:06.466474056 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:06.466564894 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:06.467256069 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:06.467295885 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:06.505723000 CET44550490126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:06.505796909 CET50490445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:06.505837917 CET50490445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:06.505837917 CET50490445192.168.2.6126.217.0.9
                Jan 15, 2025 17:14:06.510756016 CET44550490126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:06.510783911 CET44550490126.217.0.9192.168.2.6
                Jan 15, 2025 17:14:06.569282055 CET50560445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:06.574223995 CET44550560126.217.0.10192.168.2.6
                Jan 15, 2025 17:14:06.574297905 CET50560445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:06.574335098 CET50560445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:06.574753046 CET50561445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:06.579292059 CET44550560126.217.0.10192.168.2.6
                Jan 15, 2025 17:14:06.579353094 CET50560445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:06.579623938 CET44550561126.217.0.10192.168.2.6
                Jan 15, 2025 17:14:06.579698086 CET50561445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:06.579742908 CET50561445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:06.584574938 CET44550561126.217.0.10192.168.2.6
                Jan 15, 2025 17:14:06.584841013 CET50563445192.168.2.65.166.179.1
                Jan 15, 2025 17:14:06.589782000 CET445505635.166.179.1192.168.2.6
                Jan 15, 2025 17:14:06.589842081 CET50563445192.168.2.65.166.179.1
                Jan 15, 2025 17:14:06.589859962 CET50563445192.168.2.65.166.179.1
                Jan 15, 2025 17:14:06.594676018 CET445505635.166.179.1192.168.2.6
                Jan 15, 2025 17:14:06.726596117 CET44550327167.139.11.1192.168.2.6
                Jan 15, 2025 17:14:06.726713896 CET50327445192.168.2.6167.139.11.1
                Jan 15, 2025 17:14:06.726932049 CET50327445192.168.2.6167.139.11.1
                Jan 15, 2025 17:14:06.726932049 CET50327445192.168.2.6167.139.11.1
                Jan 15, 2025 17:14:06.731751919 CET44550327167.139.11.1192.168.2.6
                Jan 15, 2025 17:14:06.731761932 CET44550327167.139.11.1192.168.2.6
                Jan 15, 2025 17:14:07.025985003 CET44550516153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:07.026129007 CET50516445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:07.026129007 CET50516445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:07.026129007 CET50516445192.168.2.6153.9.75.9
                Jan 15, 2025 17:14:07.030935049 CET44550516153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:07.030946970 CET44550516153.9.75.9192.168.2.6
                Jan 15, 2025 17:14:07.085072041 CET50598445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:07.089926958 CET44550598153.9.75.10192.168.2.6
                Jan 15, 2025 17:14:07.089984894 CET50598445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:07.090020895 CET50598445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:07.090280056 CET50600445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:07.095060110 CET44550598153.9.75.10192.168.2.6
                Jan 15, 2025 17:14:07.095072985 CET44550600153.9.75.10192.168.2.6
                Jan 15, 2025 17:14:07.095102072 CET50598445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:07.095138073 CET50600445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:07.095181942 CET50600445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:07.099936962 CET44550600153.9.75.10192.168.2.6
                Jan 15, 2025 17:14:07.267821074 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:07.268131971 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:07.269656897 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:07.269715071 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:07.270498991 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:07.272281885 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:07.272281885 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:07.272281885 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:07.272383928 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:07.315341949 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:07.443772078 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:07.443959951 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:07.444199085 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:07.444364071 CET50557443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:07.444406033 CET4435055740.113.103.199192.168.2.6
                Jan 15, 2025 17:14:08.170254946 CET44550341215.114.213.1192.168.2.6
                Jan 15, 2025 17:14:08.170429945 CET50341445192.168.2.6215.114.213.1
                Jan 15, 2025 17:14:08.182214975 CET44550342128.171.224.1192.168.2.6
                Jan 15, 2025 17:14:08.182308912 CET50342445192.168.2.6128.171.224.1
                Jan 15, 2025 17:14:08.456185102 CET44550561126.217.0.10192.168.2.6
                Jan 15, 2025 17:14:08.456275940 CET50561445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:08.497664928 CET50376445192.168.2.624.145.43.2
                Jan 15, 2025 17:14:08.497709990 CET50424445192.168.2.6176.57.93.2
                Jan 15, 2025 17:14:08.497759104 CET50382445192.168.2.6131.24.232.1
                Jan 15, 2025 17:14:08.497792959 CET50363445192.168.2.667.15.60.1
                Jan 15, 2025 17:14:08.497817039 CET50389445192.168.2.632.209.198.2
                Jan 15, 2025 17:14:08.497911930 CET50342445192.168.2.6128.171.224.1
                Jan 15, 2025 17:14:08.497960091 CET50366445192.168.2.672.24.241.1
                Jan 15, 2025 17:14:08.497982025 CET50349445192.168.2.686.67.1.3
                Jan 15, 2025 17:14:08.497982025 CET50341445192.168.2.6215.114.213.1
                Jan 15, 2025 17:14:08.497982025 CET50357445192.168.2.6199.103.224.1
                Jan 15, 2025 17:14:08.498023987 CET50374445192.168.2.6191.42.119.1
                Jan 15, 2025 17:14:08.498045921 CET50379445192.168.2.6221.250.196.1
                Jan 15, 2025 17:14:08.498075008 CET50395445192.168.2.6107.234.183.1
                Jan 15, 2025 17:14:08.498097897 CET50369445192.168.2.644.163.244.1
                Jan 15, 2025 17:14:08.498104095 CET50371445192.168.2.635.167.167.1
                Jan 15, 2025 17:14:08.498125076 CET50392445192.168.2.6163.74.34.1
                Jan 15, 2025 17:14:08.498147011 CET50398445192.168.2.6206.195.253.1
                Jan 15, 2025 17:14:08.498173952 CET50401445192.168.2.686.64.193.1
                Jan 15, 2025 17:14:08.498217106 CET50405445192.168.2.6146.244.82.1
                Jan 15, 2025 17:14:08.498219013 CET50387445192.168.2.6201.222.228.1
                Jan 15, 2025 17:14:08.498241901 CET50561445192.168.2.6126.217.0.10
                Jan 15, 2025 17:14:08.498286963 CET50433445192.168.2.6217.163.243.1
                Jan 15, 2025 17:14:08.498330116 CET50458445192.168.2.6183.177.251.1
                Jan 15, 2025 17:14:08.498336077 CET50403445192.168.2.664.71.233.2
                Jan 15, 2025 17:14:08.498357058 CET50453445192.168.2.6202.166.106.2
                Jan 15, 2025 17:14:08.498367071 CET50499445192.168.2.6187.139.204.1
                Jan 15, 2025 17:14:08.498393059 CET50484445192.168.2.6158.219.90.2
                Jan 15, 2025 17:14:08.498485088 CET50563445192.168.2.65.166.179.1
                Jan 15, 2025 17:14:08.498522997 CET50543445192.168.2.6166.43.168.2
                Jan 15, 2025 17:14:08.498735905 CET50600445192.168.2.6153.9.75.10
                Jan 15, 2025 17:14:31.719113111 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:31.719219923 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:31.719382048 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:31.720134020 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:31.720175028 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.595731974 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.596021891 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:32.599580050 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:32.599602938 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.600105047 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.602221966 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:32.602304935 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:32.602317095 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.602510929 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:32.647342920 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.777264118 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.777448893 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:32.777673006 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:32.777673006 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:33.084652901 CET50670443192.168.2.640.113.103.199
                Jan 15, 2025 17:14:33.084722996 CET4435067040.113.103.199192.168.2.6
                Jan 15, 2025 17:14:35.819552898 CET49703443192.168.2.640.126.32.134
                Jan 15, 2025 17:14:35.825242996 CET4434970340.126.32.134192.168.2.6
                Jan 15, 2025 17:14:35.825438976 CET49703443192.168.2.640.126.32.134
                Jan 15, 2025 17:14:38.209959030 CET49707443192.168.2.640.126.32.134
                Jan 15, 2025 17:14:38.215337992 CET4434970740.126.32.134192.168.2.6
                Jan 15, 2025 17:14:38.215394974 CET49707443192.168.2.640.126.32.134
                Jan 15, 2025 17:15:03.044248104 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.044285059 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:03.044339895 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.044836044 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.044847965 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:03.838601112 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:03.838673115 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.840564013 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.840574026 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:03.841114044 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:03.842817068 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.842901945 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.842906952 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:03.843033075 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:03.887337923 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:04.029014111 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:04.029201984 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:04.029289007 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:04.029347897 CET50671443192.168.2.640.113.103.199
                Jan 15, 2025 17:15:04.029386997 CET4435067140.113.103.199192.168.2.6
                Jan 15, 2025 17:15:08.537110090 CET50672445192.168.2.6137.14.114.148
                Jan 15, 2025 17:15:08.542097092 CET44550672137.14.114.148192.168.2.6
                Jan 15, 2025 17:15:08.542175055 CET50672445192.168.2.6137.14.114.148
                Jan 15, 2025 17:15:08.542217016 CET50672445192.168.2.6137.14.114.148
                Jan 15, 2025 17:15:08.542334080 CET50673445192.168.2.6137.14.114.1
                Jan 15, 2025 17:15:08.547192097 CET44550672137.14.114.148192.168.2.6
                Jan 15, 2025 17:15:08.547213078 CET44550673137.14.114.1192.168.2.6
                Jan 15, 2025 17:15:08.547243118 CET50672445192.168.2.6137.14.114.148
                Jan 15, 2025 17:15:08.547270060 CET50673445192.168.2.6137.14.114.1
                Jan 15, 2025 17:15:08.547305107 CET50673445192.168.2.6137.14.114.1
                Jan 15, 2025 17:15:08.547569990 CET50676445192.168.2.6137.14.114.1
                Jan 15, 2025 17:15:08.552201986 CET44550673137.14.114.1192.168.2.6
                Jan 15, 2025 17:15:08.552248955 CET50673445192.168.2.6137.14.114.1
                Jan 15, 2025 17:15:08.552383900 CET44550676137.14.114.1192.168.2.6
                Jan 15, 2025 17:15:08.552454948 CET50676445192.168.2.6137.14.114.1
                Jan 15, 2025 17:15:08.552531004 CET50676445192.168.2.6137.14.114.1
                Jan 15, 2025 17:15:08.557322979 CET44550676137.14.114.1192.168.2.6
                Session IDSource IPSource PortDestination IPDestination Port
                0192.168.2.64970940.113.103.199443
                TimestampBytes transferredDirectionData
                2025-01-15 16:13:03 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 63 45 32 52 38 4b 6a 44 6e 55 75 72 74 2f 7a 71 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 37 65 64 64 64 37 31 62 62 30 33 33 32 64 66 0d 0a 0d 0a
                Data Ascii: CNT 1 CON 305MS-CV: cE2R8KjDnUurt/zq.1Context: a7eddd71bb0332df
                2025-01-15 16:13:03 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                2025-01-15 16:13:03 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 63 45 32 52 38 4b 6a 44 6e 55 75 72 74 2f 7a 71 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 37 65 64 64 64 37 31 62 62 30 33 33 32 64 66 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 53 6d 73 52 6f 70 43 4a 6d 4b 66 39 63 4b 52 52 76 66 66 32 75 71 67 69 53 6a 6b 50 45 4e 34 52 4d 66 34 4c 76 32 73 39 71 73 36 32 64 30 61 52 6e 4f 2b 49 30 4a 4f 44 79 44 68 38 72 48 33 59 4e 6c 44 41 2f 6e 5a 4f 7a 58 32 4b 73 50 6d 43 30 47 6d 4c 77 59 32 61 43 72 77 71 56 2b 48 55 6e 4f 71 76 42 30 55 6a 77 4a 32 6b 46
                Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: cE2R8KjDnUurt/zq.2Context: a7eddd71bb0332df<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAASmsRopCJmKf9cKRRvff2uqgiSjkPEN4RMf4Lv2s9qs62d0aRnO+I0JODyDh8rH3YNlDA/nZOzX2KsPmC0GmLwY2aCrwqV+HUnOqvB0UjwJ2kF
                2025-01-15 16:13:03 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 63 45 32 52 38 4b 6a 44 6e 55 75 72 74 2f 7a 71 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 37 65 64 64 64 37 31 62 62 30 33 33 32 64 66 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                Data Ascii: BND 3 CON\WNS 0 197MS-CV: cE2R8KjDnUurt/zq.3Context: a7eddd71bb0332df<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                2025-01-15 16:13:03 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                Data Ascii: 202 1 CON 58
                2025-01-15 16:13:03 UTC58INData Raw: 4d 53 2d 43 56 3a 20 2f 63 65 67 63 4b 2f 6a 57 30 47 34 59 37 50 56 77 2f 44 39 39 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                Data Ascii: MS-CV: /cegcK/jW0G4Y7PVw/D99A.0Payload parsing failed.


                Session IDSource IPSource PortDestination IPDestination Port
                1192.168.2.64980640.113.103.199443
                TimestampBytes transferredDirectionData
                2025-01-15 16:13:11 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 6a 76 6e 36 4b 6e 56 59 4b 45 32 75 2f 2b 37 4a 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 36 30 38 65 33 36 35 38 66 33 31 30 66 33 62 32 0d 0a 0d 0a
                Data Ascii: CNT 1 CON 305MS-CV: jvn6KnVYKE2u/+7J.1Context: 608e3658f310f3b2
                2025-01-15 16:13:11 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                2025-01-15 16:13:11 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 6a 76 6e 36 4b 6e 56 59 4b 45 32 75 2f 2b 37 4a 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 36 30 38 65 33 36 35 38 66 33 31 30 66 33 62 32 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 53 6d 73 52 6f 70 43 4a 6d 4b 66 39 63 4b 52 52 76 66 66 32 75 71 67 69 53 6a 6b 50 45 4e 34 52 4d 66 34 4c 76 32 73 39 71 73 36 32 64 30 61 52 6e 4f 2b 49 30 4a 4f 44 79 44 68 38 72 48 33 59 4e 6c 44 41 2f 6e 5a 4f 7a 58 32 4b 73 50 6d 43 30 47 6d 4c 77 59 32 61 43 72 77 71 56 2b 48 55 6e 4f 71 76 42 30 55 6a 77 4a 32 6b 46
                Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: jvn6KnVYKE2u/+7J.2Context: 608e3658f310f3b2<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAASmsRopCJmKf9cKRRvff2uqgiSjkPEN4RMf4Lv2s9qs62d0aRnO+I0JODyDh8rH3YNlDA/nZOzX2KsPmC0GmLwY2aCrwqV+HUnOqvB0UjwJ2kF
                2025-01-15 16:13:11 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 6a 76 6e 36 4b 6e 56 59 4b 45 32 75 2f 2b 37 4a 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 36 30 38 65 33 36 35 38 66 33 31 30 66 33 62 32 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                Data Ascii: BND 3 CON\WNS 0 197MS-CV: jvn6KnVYKE2u/+7J.3Context: 608e3658f310f3b2<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                2025-01-15 16:13:11 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                Data Ascii: 202 1 CON 58
                2025-01-15 16:13:11 UTC58INData Raw: 4d 53 2d 43 56 3a 20 4d 43 54 66 34 4f 38 66 30 6b 57 70 47 59 46 52 54 75 49 77 74 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                Data Ascii: MS-CV: MCTf4O8f0kWpGYFRTuIwtA.0Payload parsing failed.


                Session IDSource IPSource PortDestination IPDestination Port
                2192.168.2.65004840.113.103.199443
                TimestampBytes transferredDirectionData
                2025-01-15 16:13:23 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 39 56 45 77 50 52 31 2f 58 55 57 46 6f 54 5a 63 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 63 32 35 33 39 38 61 39 32 66 65 61 39 37 34 32 0d 0a 0d 0a
                Data Ascii: CNT 1 CON 305MS-CV: 9VEwPR1/XUWFoTZc.1Context: c25398a92fea9742
                2025-01-15 16:13:23 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                2025-01-15 16:13:23 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 39 56 45 77 50 52 31 2f 58 55 57 46 6f 54 5a 63 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 63 32 35 33 39 38 61 39 32 66 65 61 39 37 34 32 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 53 6d 73 52 6f 70 43 4a 6d 4b 66 39 63 4b 52 52 76 66 66 32 75 71 67 69 53 6a 6b 50 45 4e 34 52 4d 66 34 4c 76 32 73 39 71 73 36 32 64 30 61 52 6e 4f 2b 49 30 4a 4f 44 79 44 68 38 72 48 33 59 4e 6c 44 41 2f 6e 5a 4f 7a 58 32 4b 73 50 6d 43 30 47 6d 4c 77 59 32 61 43 72 77 71 56 2b 48 55 6e 4f 71 76 42 30 55 6a 77 4a 32 6b 46
                Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: 9VEwPR1/XUWFoTZc.2Context: c25398a92fea9742<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAASmsRopCJmKf9cKRRvff2uqgiSjkPEN4RMf4Lv2s9qs62d0aRnO+I0JODyDh8rH3YNlDA/nZOzX2KsPmC0GmLwY2aCrwqV+HUnOqvB0UjwJ2kF
                2025-01-15 16:13:23 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 39 56 45 77 50 52 31 2f 58 55 57 46 6f 54 5a 63 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 63 32 35 33 39 38 61 39 32 66 65 61 39 37 34 32 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                Data Ascii: BND 3 CON\WNS 0 197MS-CV: 9VEwPR1/XUWFoTZc.3Context: c25398a92fea9742<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                2025-01-15 16:13:23 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                Data Ascii: 202 1 CON 58
                2025-01-15 16:13:23 UTC58INData Raw: 4d 53 2d 43 56 3a 20 6c 32 7a 35 69 36 49 4f 55 45 6d 59 31 48 36 4d 62 34 34 45 64 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                Data Ascii: MS-CV: l2z5i6IOUEmY1H6Mb44Edg.0Payload parsing failed.


                Session IDSource IPSource PortDestination IPDestination Port
                3192.168.2.65029040.113.103.199443
                TimestampBytes transferredDirectionData
                2025-01-15 16:13:42 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 66 69 43 4d 42 47 47 4c 70 6b 6d 2f 45 4a 4e 59 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 37 35 39 34 38 31 33 63 36 34 33 39 62 64 66 0d 0a 0d 0a
                Data Ascii: CNT 1 CON 305MS-CV: fiCMBGGLpkm/EJNY.1Context: 27594813c6439bdf
                2025-01-15 16:13:42 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                2025-01-15 16:13:42 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 66 69 43 4d 42 47 47 4c 70 6b 6d 2f 45 4a 4e 59 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 37 35 39 34 38 31 33 63 36 34 33 39 62 64 66 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 53 6d 73 52 6f 70 43 4a 6d 4b 66 39 63 4b 52 52 76 66 66 32 75 71 67 69 53 6a 6b 50 45 4e 34 52 4d 66 34 4c 76 32 73 39 71 73 36 32 64 30 61 52 6e 4f 2b 49 30 4a 4f 44 79 44 68 38 72 48 33 59 4e 6c 44 41 2f 6e 5a 4f 7a 58 32 4b 73 50 6d 43 30 47 6d 4c 77 59 32 61 43 72 77 71 56 2b 48 55 6e 4f 71 76 42 30 55 6a 77 4a 32 6b 46
                Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: fiCMBGGLpkm/EJNY.2Context: 27594813c6439bdf<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAASmsRopCJmKf9cKRRvff2uqgiSjkPEN4RMf4Lv2s9qs62d0aRnO+I0JODyDh8rH3YNlDA/nZOzX2KsPmC0GmLwY2aCrwqV+HUnOqvB0UjwJ2kF
                2025-01-15 16:13:42 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 66 69 43 4d 42 47 47 4c 70 6b 6d 2f 45 4a 4e 59 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 37 35 39 34 38 31 33 63 36 34 33 39 62 64 66 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                Data Ascii: BND 3 CON\WNS 0 197MS-CV: fiCMBGGLpkm/EJNY.3Context: 27594813c6439bdf<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                2025-01-15 16:13:42 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                Data Ascii: 202 1 CON 58
                2025-01-15 16:13:42 UTC58INData Raw: 4d 53 2d 43 56 3a 20 47 35 74 48 49 67 73 31 5a 30 75 6e 78 77 46 4f 35 65 46 57 4f 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                Data Ascii: MS-CV: G5tHIgs1Z0unxwFO5eFWOw.0Payload parsing failed.


                Session IDSource IPSource PortDestination IPDestination Port
                4192.168.2.65055740.113.103.199443
                TimestampBytes transferredDirectionData
                2025-01-15 16:14:07 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 4e 6c 2b 34 4e 4b 6e 55 59 30 65 42 69 6b 57 55 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 38 34 31 35 66 31 39 63 61 33 63 36 39 34 36 0d 0a 0d 0a
                Data Ascii: CNT 1 CON 305MS-CV: Nl+4NKnUY0eBikWU.1Context: 38415f19ca3c6946
                2025-01-15 16:14:07 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                2025-01-15 16:14:07 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 4e 6c 2b 34 4e 4b 6e 55 59 30 65 42 69 6b 57 55 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 38 34 31 35 66 31 39 63 61 33 63 36 39 34 36 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 53 6d 73 52 6f 70 43 4a 6d 4b 66 39 63 4b 52 52 76 66 66 32 75 71 67 69 53 6a 6b 50 45 4e 34 52 4d 66 34 4c 76 32 73 39 71 73 36 32 64 30 61 52 6e 4f 2b 49 30 4a 4f 44 79 44 68 38 72 48 33 59 4e 6c 44 41 2f 6e 5a 4f 7a 58 32 4b 73 50 6d 43 30 47 6d 4c 77 59 32 61 43 72 77 71 56 2b 48 55 6e 4f 71 76 42 30 55 6a 77 4a 32 6b 46
                Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: Nl+4NKnUY0eBikWU.2Context: 38415f19ca3c6946<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAASmsRopCJmKf9cKRRvff2uqgiSjkPEN4RMf4Lv2s9qs62d0aRnO+I0JODyDh8rH3YNlDA/nZOzX2KsPmC0GmLwY2aCrwqV+HUnOqvB0UjwJ2kF
                2025-01-15 16:14:07 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 4e 6c 2b 34 4e 4b 6e 55 59 30 65 42 69 6b 57 55 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 38 34 31 35 66 31 39 63 61 33 63 36 39 34 36 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                Data Ascii: BND 3 CON\WNS 0 197MS-CV: Nl+4NKnUY0eBikWU.3Context: 38415f19ca3c6946<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                2025-01-15 16:14:07 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                Data Ascii: 202 1 CON 58
                2025-01-15 16:14:07 UTC58INData Raw: 4d 53 2d 43 56 3a 20 51 5a 46 44 49 62 55 44 6f 30 43 35 41 41 4a 45 45 70 4d 79 55 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                Data Ascii: MS-CV: QZFDIbUDo0C5AAJEEpMyUA.0Payload parsing failed.


                Session IDSource IPSource PortDestination IPDestination Port
                5192.168.2.65067040.113.103.199443
                TimestampBytes transferredDirectionData
                2025-01-15 16:14:32 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 71 6b 6f 6e 75 4e 7a 7a 66 45 57 74 76 2f 72 6e 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 36 39 39 32 61 63 65 34 37 36 61 39 34 34 35 65 0d 0a 0d 0a
                Data Ascii: CNT 1 CON 305MS-CV: qkonuNzzfEWtv/rn.1Context: 6992ace476a9445e
                2025-01-15 16:14:32 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                2025-01-15 16:14:32 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 71 6b 6f 6e 75 4e 7a 7a 66 45 57 74 76 2f 72 6e 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 36 39 39 32 61 63 65 34 37 36 61 39 34 34 35 65 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 53 6d 73 52 6f 70 43 4a 6d 4b 66 39 63 4b 52 52 76 66 66 32 75 71 67 69 53 6a 6b 50 45 4e 34 52 4d 66 34 4c 76 32 73 39 71 73 36 32 64 30 61 52 6e 4f 2b 49 30 4a 4f 44 79 44 68 38 72 48 33 59 4e 6c 44 41 2f 6e 5a 4f 7a 58 32 4b 73 50 6d 43 30 47 6d 4c 77 59 32 61 43 72 77 71 56 2b 48 55 6e 4f 71 76 42 30 55 6a 77 4a 32 6b 46
                Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: qkonuNzzfEWtv/rn.2Context: 6992ace476a9445e<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAASmsRopCJmKf9cKRRvff2uqgiSjkPEN4RMf4Lv2s9qs62d0aRnO+I0JODyDh8rH3YNlDA/nZOzX2KsPmC0GmLwY2aCrwqV+HUnOqvB0UjwJ2kF
                2025-01-15 16:14:32 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 71 6b 6f 6e 75 4e 7a 7a 66 45 57 74 76 2f 72 6e 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 36 39 39 32 61 63 65 34 37 36 61 39 34 34 35 65 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                Data Ascii: BND 3 CON\WNS 0 197MS-CV: qkonuNzzfEWtv/rn.3Context: 6992ace476a9445e<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                2025-01-15 16:14:32 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                Data Ascii: 202 1 CON 58
                2025-01-15 16:14:32 UTC58INData Raw: 4d 53 2d 43 56 3a 20 6e 45 31 77 7a 6d 43 74 2b 45 6d 78 34 4b 4e 65 42 74 78 59 34 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                Data Ascii: MS-CV: nE1wzmCt+Emx4KNeBtxY4g.0Payload parsing failed.


                Session IDSource IPSource PortDestination IPDestination Port
                6192.168.2.65067140.113.103.199443
                TimestampBytes transferredDirectionData
                2025-01-15 16:15:03 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 42 37 66 67 75 71 72 50 44 45 53 66 71 76 55 44 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 65 65 38 62 36 34 38 38 33 65 38 61 33 35 31 38 0d 0a 0d 0a
                Data Ascii: CNT 1 CON 305MS-CV: B7fguqrPDESfqvUD.1Context: ee8b64883e8a3518
                2025-01-15 16:15:03 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                2025-01-15 16:15:03 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 42 37 66 67 75 71 72 50 44 45 53 66 71 76 55 44 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 65 65 38 62 36 34 38 38 33 65 38 61 33 35 31 38 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 53 6d 73 52 6f 70 43 4a 6d 4b 66 39 63 4b 52 52 76 66 66 32 75 71 67 69 53 6a 6b 50 45 4e 34 52 4d 66 34 4c 76 32 73 39 71 73 36 32 64 30 61 52 6e 4f 2b 49 30 4a 4f 44 79 44 68 38 72 48 33 59 4e 6c 44 41 2f 6e 5a 4f 7a 58 32 4b 73 50 6d 43 30 47 6d 4c 77 59 32 61 43 72 77 71 56 2b 48 55 6e 4f 71 76 42 30 55 6a 77 4a 32 6b 46
                Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: B7fguqrPDESfqvUD.2Context: ee8b64883e8a3518<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAASmsRopCJmKf9cKRRvff2uqgiSjkPEN4RMf4Lv2s9qs62d0aRnO+I0JODyDh8rH3YNlDA/nZOzX2KsPmC0GmLwY2aCrwqV+HUnOqvB0UjwJ2kF
                2025-01-15 16:15:03 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 42 37 66 67 75 71 72 50 44 45 53 66 71 76 55 44 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 65 65 38 62 36 34 38 38 33 65 38 61 33 35 31 38 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                Data Ascii: BND 3 CON\WNS 0 197MS-CV: B7fguqrPDESfqvUD.3Context: ee8b64883e8a3518<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                2025-01-15 16:15:04 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                Data Ascii: 202 1 CON 58
                2025-01-15 16:15:04 UTC58INData Raw: 4d 53 2d 43 56 3a 20 4b 5a 4f 4e 30 31 58 67 36 30 53 52 54 47 4a 79 44 59 34 64 42 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                Data Ascii: MS-CV: KZON01Xg60SRTGJyDY4dBA.0Payload parsing failed.


                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Click to jump to process

                Target ID:0
                Start time:11:13:01
                Start date:15/01/2025
                Path:C:\Windows\System32\loaddll32.exe
                Wow64 process (32bit):true
                Commandline:loaddll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll"
                Imagebase:0xff0000
                File size:126'464 bytes
                MD5 hash:51E6071F9CBA48E79F10C84515AAE618
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:1
                Start time:11:13:01
                Start date:15/01/2025
                Path:C:\Windows\System32\conhost.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:0x7ff66e660000
                File size:862'208 bytes
                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:2
                Start time:11:13:01
                Start date:15/01/2025
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):true
                Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1
                Imagebase:0x1c0000
                File size:236'544 bytes
                MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:3
                Start time:11:13:01
                Start date:15/01/2025
                Path:C:\Windows\SysWOW64\rundll32.exe
                Wow64 process (32bit):true
                Commandline:rundll32.exe C:\Users\user\Desktop\2lX8Z3eydC.dll,PlayGame
                Imagebase:0x730000
                File size:61'440 bytes
                MD5 hash:889B99C52A60DD49227C5E485A016679
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:5
                Start time:11:13:01
                Start date:15/01/2025
                Path:C:\Windows\SysWOW64\rundll32.exe
                Wow64 process (32bit):true
                Commandline:rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",#1
                Imagebase:0x730000
                File size:61'440 bytes
                MD5 hash:889B99C52A60DD49227C5E485A016679
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:6
                Start time:11:13:02
                Start date:15/01/2025
                Path:C:\Windows\mssecsvc.exe
                Wow64 process (32bit):true
                Commandline:C:\WINDOWS\mssecsvc.exe
                Imagebase:0x400000
                File size:3'723'264 bytes
                MD5 hash:178018208D64CFFD440180008D212F1A
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Yara matches:
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000006.00000000.2162227567.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Windows\mssecsvc.exe, Author: Joe Security
                • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvc.exe, Author: Florian Roth (with the help of binar.ly)
                • Rule: WannaCry_Ransomware_Gen, Description: Detects WannaCry Ransomware, Source: C:\Windows\mssecsvc.exe, Author: Florian Roth (based on rule by US CERT)
                • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Windows\mssecsvc.exe, Author: ReversingLabs
                Antivirus matches:
                • Detection: 100%, Avira
                • Detection: 100%, Joe Sandbox ML
                Reputation:low
                Has exited:true

                Target ID:8
                Start time:11:13:03
                Start date:15/01/2025
                Path:C:\Windows\mssecsvc.exe
                Wow64 process (32bit):true
                Commandline:C:\WINDOWS\mssecsvc.exe -m security
                Imagebase:0x400000
                File size:3'723'264 bytes
                MD5 hash:178018208D64CFFD440180008D212F1A
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Yara matches:
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000000.2170224322.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2811124459.0000000002292000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000008.00000002.2810873658.0000000001D66000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                Reputation:low
                Has exited:true

                Target ID:9
                Start time:11:13:04
                Start date:15/01/2025
                Path:C:\Windows\SysWOW64\rundll32.exe
                Wow64 process (32bit):true
                Commandline:rundll32.exe "C:\Users\user\Desktop\2lX8Z3eydC.dll",PlayGame
                Imagebase:0x730000
                File size:61'440 bytes
                MD5 hash:889B99C52A60DD49227C5E485A016679
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:10
                Start time:11:13:04
                Start date:15/01/2025
                Path:C:\Windows\mssecsvc.exe
                Wow64 process (32bit):true
                Commandline:C:\WINDOWS\mssecsvc.exe
                Imagebase:0x400000
                File size:3'723'264 bytes
                MD5 hash:178018208D64CFFD440180008D212F1A
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Yara matches:
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 0000000A.00000000.2188539151.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 0000000A.00000002.2190736841.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                Reputation:low
                Has exited:true

                Reset < >

                  Execution Graph

                  Execution Coverage:77.5%
                  Dynamic/Decrypted Code Coverage:0%
                  Signature Coverage:63.2%
                  Total number of Nodes:38
                  Total number of Limit Nodes:2
                  execution_graph 63 409a16 __set_app_type __p__fmode __p__commode 64 409a85 63->64 65 409a99 64->65 66 409a8d __setusermatherr 64->66 75 409b8c _controlfp 65->75 66->65 68 409a9e _initterm __getmainargs _initterm 69 409af2 GetStartupInfoA 68->69 71 409b26 GetModuleHandleA 69->71 76 408140 InternetOpenA InternetOpenUrlA 71->76 75->68 77 4081a7 InternetCloseHandle InternetCloseHandle 76->77 80 408090 GetModuleFileNameA __p___argc 77->80 79 4081b2 exit _XcptFilter 81 4080b0 80->81 82 4080b9 OpenSCManagerA 80->82 91 407f20 81->91 83 408101 StartServiceCtrlDispatcherA 82->83 84 4080cf OpenServiceA 82->84 83->79 86 4080fc CloseServiceHandle 84->86 87 4080ee 84->87 86->83 96 407fa0 ChangeServiceConfig2A 87->96 90 4080f6 CloseServiceHandle 90->86 97 407c40 sprintf OpenSCManagerA 91->97 93 407f25 102 407ce0 GetModuleHandleW 93->102 96->90 98 407c74 CreateServiceA 97->98 99 407cca 97->99 100 407cbb CloseServiceHandle 98->100 101 407cad StartServiceA CloseServiceHandle 98->101 99->93 100->93 101->100 103 407d01 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 102->103 104 407f08 102->104 103->104 105 407d49 103->105 104->79 105->104 106 407d69 FindResourceA 105->106 106->104 107 407d84 LoadResource 106->107 107->104 108 407d94 LockResource 107->108 108->104 109 407da7 SizeofResource 108->109 109->104 110 407db9 sprintf sprintf MoveFileExA CreateFileA 109->110 110->104 111 407e54 WriteFile CloseHandle CreateProcessA 110->111 111->104 112 407ef2 CloseHandle CloseHandle 111->112 112->104

                  Callgraph

                  Control-flow Graph

                  APIs
                  • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F7F0EF0,?,00000000), ref: 00407CEF
                  • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                  • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                  • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                  • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                  • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                  • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                  • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                  • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                  • sprintf.MSVCRT ref: 00407E01
                  • sprintf.MSVCRT ref: 00407E18
                  • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                  • CreateFileA.KERNELBASE(?,40000000,00000000,00000000,00000002,00000004,00000000), ref: 00407E43
                  • WriteFile.KERNELBASE(00000000,?,00000000,?,00000000), ref: 00407E61
                  • CloseHandle.KERNELBASE(00000000), ref: 00407E68
                  • CreateProcessA.KERNELBASE ref: 00407EE8
                  • CloseHandle.KERNEL32(00000000), ref: 00407EF7
                  • CloseHandle.KERNEL32(08000000), ref: 00407F02
                  Strings
                  Memory Dump Source
                  • Source File: 00000006.00000002.2180847605.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000006.00000002.2180808669.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180905286.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181022913.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181118626.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_6_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleProcResource$CloseFile$Createsprintf$FindLoadLockModuleMoveProcessSizeofWrite
                  • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                  • API String ID: 4281112323-1507730452
                  • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                  • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                  Control-flow Graph

                  APIs
                  • sprintf.MSVCRT ref: 00407C56
                  • OpenSCManagerA.SECHOST(00000000,00000000,000F003F), ref: 00407C68
                  • CreateServiceA.ADVAPI32(00000000,mssecsvc2.0,Microsoft Security Center (2.0) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F7F0EF0,00000000), ref: 00407C9B
                  • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                  Strings
                  Memory Dump Source
                  • Source File: 00000006.00000002.2180847605.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000006.00000002.2180808669.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180905286.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181022913.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181118626.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_6_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                  • String ID: %s -m security$Microsoft Security Center (2.0) Service$mssecsvc2.0
                  • API String ID: 3340711343-4063779371
                  • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                  • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                  Control-flow Graph

                  APIs
                  Memory Dump Source
                  • Source File: 00000006.00000002.2180847605.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000006.00000002.2180808669.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180905286.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181022913.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181118626.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_6_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                  • String ID:
                  • API String ID: 801014965-0
                  • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                  • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59

                  Control-flow Graph

                  APIs
                  • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                  • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                  • InternetCloseHandle.WININET(00000000), ref: 004081A7
                  • InternetCloseHandle.WININET(00000000), ref: 004081AB
                  Memory Dump Source
                  • Source File: 00000006.00000002.2180847605.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000006.00000002.2180808669.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180905286.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181022913.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181118626.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_6_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: Internet$CloseHandleOpen
                  • String ID:
                  • API String ID: 435140893-0
                  • Opcode ID: 7bc602e844cdf910e4a24fc0389d75e4e4c0db4e5e0cdfe1b8e612c3f784a296
                  • Instruction ID: 1dd4d323c29996ceece3d10fb5d3e331cb9ed4e1cabd62d72b2cd6c3d10c6962
                  • Opcode Fuzzy Hash: 7bc602e844cdf910e4a24fc0389d75e4e4c0db4e5e0cdfe1b8e612c3f784a296
                  • Instruction Fuzzy Hash: 050162715443106EE320DF648D01B6B7BE9EF85710F01082EF984E7280EAB59804876B

                  Control-flow Graph

                  APIs
                  • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                  • __p___argc.MSVCRT ref: 004080A5
                  • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                  • OpenServiceA.ADVAPI32(00000000,mssecsvc2.0,000F01FF,6F7F0EF0,00000000,?,004081B2), ref: 004080DC
                  • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                  • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                  • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                  Strings
                  Memory Dump Source
                  • Source File: 00000006.00000002.2180847605.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000006.00000002.2180808669.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180905286.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2180950721.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181022913.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000006.00000002.2181118626.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_6_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                  • String ID: mssecsvc2.0
                  • API String ID: 4274534310-3729025388
                  • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                  • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                  Execution Graph

                  Execution Coverage:34.8%
                  Dynamic/Decrypted Code Coverage:0%
                  Signature Coverage:0%
                  Total number of Nodes:36
                  Total number of Limit Nodes:2

                  Callgraph

                  Control-flow Graph

                  APIs
                  • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                  • __p___argc.MSVCRT ref: 004080A5
                  • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                  • OpenServiceA.ADVAPI32(00000000,mssecsvc2.0,000F01FF,6F7F0EF0,00000000,?,004081B2), ref: 004080DC
                  • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                  • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                  • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                  Strings
                  Memory Dump Source
                  • Source File: 00000008.00000002.2810185930.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000008.00000002.2810173517.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810198451.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810249542.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810260810.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810332452.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_8_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                  • String ID: mssecsvc2.0
                  • API String ID: 4274534310-3729025388
                  • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                  • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                  Control-flow Graph

                  APIs
                  • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                  • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                  • InternetCloseHandle.WININET(00000000), ref: 004081A7
                  • InternetCloseHandle.WININET(00000000), ref: 004081AB
                  Memory Dump Source
                  • Source File: 00000008.00000002.2810185930.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000008.00000002.2810173517.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810198451.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810249542.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810260810.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810332452.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_8_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: Internet$CloseHandleOpen
                  • String ID:
                  • API String ID: 435140893-0
                  • Opcode ID: 7bc602e844cdf910e4a24fc0389d75e4e4c0db4e5e0cdfe1b8e612c3f784a296
                  • Instruction ID: 1dd4d323c29996ceece3d10fb5d3e331cb9ed4e1cabd62d72b2cd6c3d10c6962
                  • Opcode Fuzzy Hash: 7bc602e844cdf910e4a24fc0389d75e4e4c0db4e5e0cdfe1b8e612c3f784a296
                  • Instruction Fuzzy Hash: 050162715443106EE320DF648D01B6B7BE9EF85710F01082EF984E7280EAB59804876B

                  Control-flow Graph

                  APIs
                  • sprintf.MSVCRT ref: 00407C56
                  • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                  • CreateServiceA.ADVAPI32(00000000,mssecsvc2.0,Microsoft Security Center (2.0) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F7F0EF0,00000000), ref: 00407C9B
                  • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                  Strings
                  Memory Dump Source
                  • Source File: 00000008.00000002.2810185930.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000008.00000002.2810173517.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810198451.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810249542.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810260810.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810332452.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_8_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                  • String ID: %s -m security$Microsoft Security Center (2.0) Service$mssecsvc2.0
                  • API String ID: 3340711343-4063779371
                  • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                  • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 15 407ce0-407cfb GetModuleHandleW 16 407d01-407d43 GetProcAddress * 4 15->16 17 407f08-407f14 15->17 16->17 18 407d49-407d4f 16->18 18->17 19 407d55-407d5b 18->19 19->17 20 407d61-407d63 19->20 20->17 21 407d69-407d7e FindResourceA 20->21 21->17 22 407d84-407d8e LoadResource 21->22 22->17 23 407d94-407da1 LockResource 22->23 23->17 24 407da7-407db3 SizeofResource 23->24 24->17 25 407db9-407e4e sprintf * 2 MoveFileExA 24->25 25->17 27 407e54-407ef0 25->27 27->17 31 407ef2-407f01 27->31 31->17
                  APIs
                  • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F7F0EF0,?,00000000), ref: 00407CEF
                  • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                  • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                  • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                  • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                  • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                  • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                  • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                  • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                  • sprintf.MSVCRT ref: 00407E01
                  • sprintf.MSVCRT ref: 00407E18
                  • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                  Strings
                  Memory Dump Source
                  • Source File: 00000008.00000002.2810185930.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000008.00000002.2810173517.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810198451.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810249542.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810260810.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810332452.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_8_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressProcResource$sprintf$FileFindHandleLoadLockModuleMoveSizeof
                  • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                  • API String ID: 4072214828-1507730452
                  • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                  • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                  Control-flow Graph

                  APIs
                  Memory Dump Source
                  • Source File: 00000008.00000002.2810185930.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000008.00000002.2810173517.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810198451.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810209470.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810238501.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810249542.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810260810.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                  • Associated: 00000008.00000002.2810332452.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_8_2_400000_mssecsvc.jbxd
                  Yara matches
                  Similarity
                  • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                  • String ID:
                  • API String ID: 801014965-0
                  • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                  • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59