Edit tour

Windows Analysis Report
mssecsvc.exe.exe

Overview

General Information

Sample name:mssecsvc.exe.exe
(renamed file extension from malware to exe)
Original sample name:mssecsvc.exe.malware
Analysis ID:1651503
MD5:0c694193ceac8bfb016491ffb534eb7c
SHA1:3afa73283d1e17de1bde6cc14e19417e70fc9554
SHA256:dbf3890b782ac04136c3336814eef97e3c0f4133f9592e882c131c179161b27b
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Tries to download HTTP data from a sinkholed server
Yara detected Wannacry ransomware
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Drops executables to the windows directory (C:\Windows) and starts them
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Connects to several IPs in different countries
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
HTTP GET or POST without a user agent
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w7x64
  • mssecsvc.exe.exe (PID: 3504 cmdline: "C:\Users\user\Desktop\mssecsvc.exe.exe" MD5: 0C694193CEAC8BFB016491FFB534EB7C)
    • tasksche.exe (PID: 3792 cmdline: C:\WINDOWS\tasksche.exe /i MD5: 7F7CCAA16FB15EB1C7399D422F8363E8)
  • mssecsvc.exe.exe (PID: 3676 cmdline: C:\Users\user\Desktop\mssecsvc.exe.exe -m security MD5: 0C694193CEAC8BFB016491FFB534EB7C)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
WannaCryptor, WannaCry, WannaCryptWannaCry is ransomware that contains a worm component enabled by the EternalBlue exploit. It attempts to use vulnerabilities in the Windows SMBv1 server to remotely compromise systems, encrypt files, and spread to other hosts. Systems that have installed the MS17-010 patch are not vulnerable to the exploits used. The spreading was stopped about 8 hours after initial outbreak due to triggering a kill switch domain.
  • Lazarus Group
https://malpedia.caad.fkie.fraunhofer.de/details/win.wannacryptor
No configs have been found
SourceRuleDescriptionAuthorStrings
mssecsvc.exe.exeJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    mssecsvc.exe.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x415a0:$x1: icacls . /grant Everyone:F /T /C /Q
    • 0x3136c:$x3: tasksche.exe
    • 0x4157c:$x3: tasksche.exe
    • 0x41558:$x4: Global\MsWinZonesCacheCounterMutexA
    • 0x415d0:$x5: WNcry@2ol7
    • 0x313d7:$x6: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
    • 0xe048:$x7: mssecsvc.exe
    • 0x17350:$x7: mssecsvc.exe
    • 0x31344:$x8: C:\%s\qeriuwjhrf
    • 0x415a0:$x9: icacls . /grant Everyone:F /T /C /Q
    • 0xe034:$s1: C:\%s\%s
    • 0x17338:$s1: C:\%s\%s
    • 0x31358:$s1: C:\%s\%s
    • 0x414d0:$s3: cmd.exe /c "%s"
    • 0x73a24:$s4: msg/m_portuguese.wnry
    • 0x2e68c:$s5: \\192.168.56.20\IPC$
    • 0x1ba81:$s6: \\172.16.99.5\IPC$
    • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
    • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
    • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
    • 0x34aa6:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
    mssecsvc.exe.exeWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
    • 0x1bacc:$s1: __TREEID__PLACEHOLDER__
    • 0x1bb68:$s1: __TREEID__PLACEHOLDER__
    • 0x1c3d4:$s1: __TREEID__PLACEHOLDER__
    • 0x1d439:$s1: __TREEID__PLACEHOLDER__
    • 0x1e4a0:$s1: __TREEID__PLACEHOLDER__
    • 0x1f508:$s1: __TREEID__PLACEHOLDER__
    • 0x20570:$s1: __TREEID__PLACEHOLDER__
    • 0x215d8:$s1: __TREEID__PLACEHOLDER__
    • 0x22640:$s1: __TREEID__PLACEHOLDER__
    • 0x236a8:$s1: __TREEID__PLACEHOLDER__
    • 0x24710:$s1: __TREEID__PLACEHOLDER__
    • 0x25778:$s1: __TREEID__PLACEHOLDER__
    • 0x267e0:$s1: __TREEID__PLACEHOLDER__
    • 0x27848:$s1: __TREEID__PLACEHOLDER__
    • 0x288b0:$s1: __TREEID__PLACEHOLDER__
    • 0x29918:$s1: __TREEID__PLACEHOLDER__
    • 0x2a980:$s1: __TREEID__PLACEHOLDER__
    • 0x2ab94:$s1: __TREEID__PLACEHOLDER__
    • 0x2abf4:$s1: __TREEID__PLACEHOLDER__
    • 0x2e2c4:$s1: __TREEID__PLACEHOLDER__
    • 0x2e340:$s1: __TREEID__PLACEHOLDER__
    mssecsvc.exe.exewanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
    • 0x4157c:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
    • 0x415a4:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
    mssecsvc.exe.exeWin32_Ransomware_WannaCryunknownReversingLabs
    • 0x340ba:$main_2: 68 08 02 00 00 33 DB 50 53 FF 15 8C 80 40 00 68 AC F8 40 00 E8 F6 F1 FF FF 59 FF 15 6C 81 40 00 83 38 02 75 53 68 38 F5 40 00 FF 15 68 81 40 00 8B 00 FF 70 04 E8 F0 56 00 00 59 85 C0 59 75 38 ...
    • 0x8090:$start_service_3: 83 EC 10 68 04 01 00 00 68 60 F7 70 00 6A 00 FF 15 6C A0 40 00 FF 15 2C A1 40 00 83 38 02 7D 09 E8 6B FE FF FF 83 C4 10 C3 57 68 3F 00 0F 00 6A 00 6A 00 FF 15 10 A0 40 00 8B F8 85 FF 74 32 53 ...
    • 0x9a16:$entrypoint_all: 55 8B EC 6A FF 68 A0 A1 40 00 68 A2 9B 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C0 A0 40 00 59 83 0D 94 F8 70 00 FF 83 0D 98 F8 70 ...
    • 0x3985e:$entrypoint_all: 55 8B EC 6A FF 68 88 D4 40 00 68 F4 76 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C4 81 40 00 59 83 0D 4C F9 40 00 FF 83 0D 50 F9 40 ...
    SourceRuleDescriptionAuthorStrings
    C:\Windows\tasksche.exeJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      C:\Windows\tasksche.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
      • 0xf4fc:$x1: icacls . /grant Everyone:F /T /C /Q
      • 0xf4d8:$x3: tasksche.exe
      • 0xf4b4:$x4: Global\MsWinZonesCacheCounterMutexA
      • 0xf52c:$x5: WNcry@2ol7
      • 0xf4fc:$x9: icacls . /grant Everyone:F /T /C /Q
      • 0xf42c:$s3: cmd.exe /c "%s"
      • 0x41980:$s4: msg/m_portuguese.wnry
      • 0x2a02:$op4: 09 FF 76 30 50 FF 56 2C 59 59 47 3B 7E 0C 7C
      • 0x26dc:$op5: C1 EA 1D C1 EE 1E 83 E2 01 83 E6 01 8D 14 56
      • 0x22c8:$op6: 8D 48 FF F7 D1 8D 44 10 FF 23 F1 23 C1
      C:\Windows\tasksche.exewanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
      • 0xf4d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
      • 0xf500:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
      C:\Windows\tasksche.exeWin32_Ransomware_WannaCryunknownReversingLabs
      • 0x2016:$main_2: 68 08 02 00 00 33 DB 50 53 FF 15 8C 80 40 00 68 AC F8 40 00 E8 F6 F1 FF FF 59 FF 15 6C 81 40 00 83 38 02 75 53 68 38 F5 40 00 FF 15 68 81 40 00 8B 00 FF 70 04 E8 F0 56 00 00 59 85 C0 59 75 38 ...
      • 0x77ba:$entrypoint_all: 55 8B EC 6A FF 68 88 D4 40 00 68 F4 76 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 68 53 56 57 89 65 E8 33 DB 89 5D FC 6A 02 FF 15 C4 81 40 00 59 83 0D 4C F9 40 00 FF 83 0D 50 F9 40 ...
      SourceRuleDescriptionAuthorStrings
      00000004.00000002.493697479.000000000042E000.00000004.00000001.01000000.00000003.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        00000005.00000000.357354210.000000000040E000.00000008.00000001.01000000.00000005.sdmpwanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
        • 0x14d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
        • 0x1500:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
        00000005.00000002.357560055.000000000040E000.00000008.00000001.01000000.00000005.sdmpwanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
        • 0x14d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
        • 0x1500:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
        00000000.00000002.358030594.000000000040F000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          00000000.00000000.350973560.000000000040F000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            Click to see the 15 entries

            System Summary

            barindex
            Source: Registry Key setAuthor: frack113: Data: Details: 46 00 00 00 2A 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 02 16 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\mssecsvc.exe.exe, ProcessId: 3504, TargetObject: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-28T22:13:26.998295+010020315153Misc activity104.16.166.22880192.168.2.2249161TCP
            2025-03-28T22:13:27.867818+010020315153Misc activity104.16.166.22880192.168.2.2249162TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-28T22:13:26.695035+010020242911A Network Trojan was detected192.168.2.22545628.8.8.853UDP
            2025-03-28T22:13:27.565802+010020242911A Network Trojan was detected192.168.2.22529178.8.8.853UDP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-28T22:13:26.998238+010020242981A Network Trojan was detected192.168.2.2249161104.16.166.22880TCP
            2025-03-28T22:13:27.867162+010020242981A Network Trojan was detected192.168.2.2249162104.16.166.22880TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-28T22:13:26.998238+010020242991A Network Trojan was detected192.168.2.2249161104.16.166.22880TCP
            2025-03-28T22:13:27.867162+010020242991A Network Trojan was detected192.168.2.2249162104.16.166.22880TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-28T22:13:26.998238+010020243011A Network Trojan was detected192.168.2.2249161104.16.166.22880TCP
            2025-03-28T22:13:27.867162+010020243011A Network Trojan was detected192.168.2.2249162104.16.166.22880TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-28T22:13:26.998238+010020243021A Network Trojan was detected192.168.2.2249161104.16.166.22880TCP
            2025-03-28T22:13:27.867162+010020243021A Network Trojan was detected192.168.2.2249162104.16.166.22880TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-28T22:13:26.998238+010028033043Unknown Traffic192.168.2.2249161104.16.166.22880TCP
            2025-03-28T22:13:27.867162+010028033043Unknown Traffic192.168.2.2249162104.16.166.22880TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: mssecsvc.exe.exeAvira: detected
            Source: C:\Windows\tasksche.exeAvira: detection malicious, Label: TR/AD.WannaCry.sewvt
            Source: C:\Windows\tasksche.exeReversingLabs: Detection: 100%
            Source: mssecsvc.exe.exeReversingLabs: Detection: 100%
            Source: mssecsvc.exe.exeVirustotal: Detection: 93%Perma Link

            Exploits

            barindex
            Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.115:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.116:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.119:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.117:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.118:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.115:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.116:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.119:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.117:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.118:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
            Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
            Source: mssecsvc.exe.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2024298 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 1 : 192.168.2.22:49161 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2024299 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 2 : 192.168.2.22:49161 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2024301 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 4 : 192.168.2.22:49161 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2024302 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 5 : 192.168.2.22:49161 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2024298 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 1 : 192.168.2.22:49162 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2024299 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 2 : 192.168.2.22:49162 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2024301 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 4 : 192.168.2.22:49162 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2024302 - Severity 1 - ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 5 : 192.168.2.22:49162 -> 104.16.166.228:80
            Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 28 Mar 2025 21:13:26 GMTContent-Type: text/htmlContent-Length: 607Connection: closeServer: cloudflareCF-RAY: 927a21a75da023ce-EWRData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 2d 75 73 22 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 3c 74 69 74 6c 65 3e 53 69 6e 6b 68 6f 6c 65 64 20 62 79 20 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 3c 2f 74 69 74 6c 65 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 20 53 69 6e 6b 68 6f 6c 65 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 73 74 61 74 69 63 2e 6b 72 79 70 74 6f 73 6c 6f 67 69 63 73 69 6e 6b 68 6f 6c 65 2e 63 6f 6d 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 2f 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 63 6c 61 73 73 3d 22 66 6c 61 74 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 6f 6e 74 65 6e 74 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 6f 6e 74 65 6e 74 2d 62 6f 78 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 62 69 67 2d 63 6f 6e 74 65 6e 74 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 6c 65 61 72 22 3e 3c 2f 64 69 76 3e 3c 2f 64 69 76 3e 3c 68 31 3e 53 69 6e 6b 68 6f 6c 65 64 21 3c 2f 68 31 3e 3c 70 3e 54 68 69 73 20 64 6f 6d 61 69 6e 20 68 61 73 20 62 65 65 6e 20 73 69 6e 6b 68 6f 6c 65 64 20 62 79 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 6b 72 79 70 74 6f 73 6c 6f 67 69 63 2e 63 6f 6d 22 3e 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 3c 2f 61 3e 2e 3c 2f 70 3e 3c 2f 64 69 76 3e 3c 2f 64 69 76 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html><html lang="en-us" class="no-js"><head><meta charset="utf-8"><title>Sinkholed by Kryptos Logic</title><meta name="description" content="Kryptos Logic Sinkhole"><meta name="viewport" content="width=device-width, initial-scale=1.0"><link href="//static.kryptoslogicsinkhole.com/style.css" rel="stylesheet" type="text/css"/></head><body class="flat"><div class="content"><div class="content-box"><div class="big-content"><div class="clear"></div></div><h1>Sinkholed!</h1><p>This domain has been sinkholed by <a href="https://www.kryptoslogic.com">Kryptos Logic</a>.</p></div></div></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 28 Mar 2025 21:13:27 GMTContent-Type: text/htmlContent-Length: 607Connection: closeServer: cloudflareCF-RAY: 927a21accb51f797-EWRData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 2d 75 73 22 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 3c 74 69 74 6c 65 3e 53 69 6e 6b 68 6f 6c 65 64 20 62 79 20 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 3c 2f 74 69 74 6c 65 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 20 53 69 6e 6b 68 6f 6c 65 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 73 74 61 74 69 63 2e 6b 72 79 70 74 6f 73 6c 6f 67 69 63 73 69 6e 6b 68 6f 6c 65 2e 63 6f 6d 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 2f 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 63 6c 61 73 73 3d 22 66 6c 61 74 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 6f 6e 74 65 6e 74 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 6f 6e 74 65 6e 74 2d 62 6f 78 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 62 69 67 2d 63 6f 6e 74 65 6e 74 22 3e 3c 64 69 76 20 63 6c 61 73 73 3d 22 63 6c 65 61 72 22 3e 3c 2f 64 69 76 3e 3c 2f 64 69 76 3e 3c 68 31 3e 53 69 6e 6b 68 6f 6c 65 64 21 3c 2f 68 31 3e 3c 70 3e 54 68 69 73 20 64 6f 6d 61 69 6e 20 68 61 73 20 62 65 65 6e 20 73 69 6e 6b 68 6f 6c 65 64 20 62 79 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 6b 72 79 70 74 6f 73 6c 6f 67 69 63 2e 63 6f 6d 22 3e 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 3c 2f 61 3e 2e 3c 2f 70 3e 3c 2f 64 69 76 3e 3c 2f 64 69 76 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html><html lang="en-us" class="no-js"><head><meta charset="utf-8"><title>Sinkholed by Kryptos Logic</title><meta name="description" content="Kryptos Logic Sinkhole"><meta name="viewport" content="width=device-width, initial-scale=1.0"><link href="//static.kryptoslogicsinkhole.com/style.css" rel="stylesheet" type="text/css"/></head><body class="flat"><div class="content"><div class="content-box"><div class="big-content"><div class="clear"></div></div><h1>Sinkholed!</h1><p>This domain has been sinkholed by <a href="https://www.kryptoslogic.com">Kryptos Logic</a>.</p></div></div></body></html>
            Source: unknownNetwork traffic detected: IP country count 22
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comCache-Control: no-cache
            Source: Network trafficSuricata IDS: 2024291 - Severity 1 - ET MALWARE Possible WannaCry DNS Lookup 1 : 192.168.2.22:54562 -> 8.8.8.8:53
            Source: Network trafficSuricata IDS: 2024291 - Severity 1 - ET MALWARE Possible WannaCry DNS Lookup 1 : 192.168.2.22:52917 -> 8.8.8.8:53
            Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.22:49161 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.22:49162 -> 104.16.166.228:80
            Source: Network trafficSuricata IDS: 2031515 - Severity 3 - ET MALWARE Known Sinkhole Response Kryptos Logic : 104.16.166.228:80 -> 192.168.2.22:49161
            Source: Network trafficSuricata IDS: 2031515 - Severity 3 - ET MALWARE Known Sinkhole Response Kryptos Logic : 104.16.166.228:80 -> 192.168.2.22:49162
            Source: unknownTCP traffic detected without corresponding DNS query: 179.149.119.240
            Source: unknownTCP traffic detected without corresponding DNS query: 5.161.3.226
            Source: unknownTCP traffic detected without corresponding DNS query: 41.249.225.248
            Source: unknownTCP traffic detected without corresponding DNS query: 60.243.179.166
            Source: unknownTCP traffic detected without corresponding DNS query: 46.78.169.146
            Source: unknownTCP traffic detected without corresponding DNS query: 197.18.246.111
            Source: unknownTCP traffic detected without corresponding DNS query: 197.154.3.137
            Source: unknownTCP traffic detected without corresponding DNS query: 184.42.88.36
            Source: unknownTCP traffic detected without corresponding DNS query: 50.103.164.43
            Source: unknownTCP traffic detected without corresponding DNS query: 219.79.251.133
            Source: unknownTCP traffic detected without corresponding DNS query: 11.80.13.222
            Source: unknownTCP traffic detected without corresponding DNS query: 173.48.34.114
            Source: unknownTCP traffic detected without corresponding DNS query: 207.193.131.196
            Source: unknownTCP traffic detected without corresponding DNS query: 76.85.155.151
            Source: unknownTCP traffic detected without corresponding DNS query: 105.153.176.87
            Source: unknownTCP traffic detected without corresponding DNS query: 143.95.188.165
            Source: unknownTCP traffic detected without corresponding DNS query: 201.11.248.31
            Source: unknownTCP traffic detected without corresponding DNS query: 92.139.187.164
            Source: unknownTCP traffic detected without corresponding DNS query: 206.70.205.171
            Source: unknownTCP traffic detected without corresponding DNS query: 177.35.175.109
            Source: unknownTCP traffic detected without corresponding DNS query: 149.136.152.42
            Source: unknownTCP traffic detected without corresponding DNS query: 193.167.47.61
            Source: unknownTCP traffic detected without corresponding DNS query: 31.165.163.7
            Source: unknownTCP traffic detected without corresponding DNS query: 160.195.89.246
            Source: unknownTCP traffic detected without corresponding DNS query: 25.26.63.98
            Source: unknownTCP traffic detected without corresponding DNS query: 15.243.91.206
            Source: unknownTCP traffic detected without corresponding DNS query: 199.114.150.9
            Source: unknownTCP traffic detected without corresponding DNS query: 66.31.1.205
            Source: unknownTCP traffic detected without corresponding DNS query: 156.145.178.95
            Source: unknownTCP traffic detected without corresponding DNS query: 185.27.29.32
            Source: unknownTCP traffic detected without corresponding DNS query: 194.147.16.167
            Source: unknownTCP traffic detected without corresponding DNS query: 6.125.30.242
            Source: unknownTCP traffic detected without corresponding DNS query: 149.180.173.172
            Source: unknownTCP traffic detected without corresponding DNS query: 43.26.27.7
            Source: unknownTCP traffic detected without corresponding DNS query: 188.92.66.47
            Source: unknownTCP traffic detected without corresponding DNS query: 7.74.55.124
            Source: unknownTCP traffic detected without corresponding DNS query: 70.38.197.97
            Source: unknownTCP traffic detected without corresponding DNS query: 119.41.187.169
            Source: unknownTCP traffic detected without corresponding DNS query: 53.33.231.37
            Source: unknownTCP traffic detected without corresponding DNS query: 187.49.66.157
            Source: unknownTCP traffic detected without corresponding DNS query: 24.207.133.106
            Source: unknownTCP traffic detected without corresponding DNS query: 117.62.196.67
            Source: unknownTCP traffic detected without corresponding DNS query: 122.166.104.87
            Source: unknownTCP traffic detected without corresponding DNS query: 75.59.51.134
            Source: unknownTCP traffic detected without corresponding DNS query: 41.123.182.192
            Source: unknownTCP traffic detected without corresponding DNS query: 113.90.248.144
            Source: unknownTCP traffic detected without corresponding DNS query: 148.134.135.3
            Source: unknownTCP traffic detected without corresponding DNS query: 1.165.181.98
            Source: unknownTCP traffic detected without corresponding DNS query: 168.55.217.78
            Source: unknownTCP traffic detected without corresponding DNS query: 1.165.100.74
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile created: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.datJump to behavior
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comCache-Control: no-cache
            Source: global trafficDNS traffic detected: DNS query: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
            Source: mssecsvc.exe.exeString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
            Source: mssecsvc.exe.exe, 00000000.00000002.358148762.0000000000BF4000.00000004.00000020.00020000.00000000.sdmp, mssecsvc.exe.exe, 00000004.00000002.493648746.00000000002D4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com/
            Source: mssecsvc.exe.exe, 00000004.00000002.493631174.000000000018C000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comJ
            Source: mssecsvc.exe.exe, 00000004.00000002.493648746.00000000002F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.kryptoslogic.com

            Spam, unwanted Advertisements and Ransom Demands

            barindex
            Source: Yara matchFile source: mssecsvc.exe.exe, type: SAMPLE
            Source: Yara matchFile source: 00000004.00000002.493697479.000000000042E000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.358030594.000000000040F000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000000.350973560.000000000040F000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000004.00000000.355043612.000000000040F000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000004.00000000.355162582.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000004.00000002.493989278.000000000289B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000004.00000002.493722594.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000000.350995207.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.358062507.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000004.00000002.493920709.0000000002383000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: mssecsvc.exe.exe PID: 3504, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: mssecsvc.exe.exe PID: 3676, type: MEMORYSTR
            Source: Yara matchFile source: C:\Windows\tasksche.exe, type: DROPPED

            System Summary

            barindex
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
            Source: 00000005.00000000.357354210.000000000040E000.00000008.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: 00000005.00000002.357560055.000000000040E000.00000008.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: 00000004.00000000.355162582.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: 00000004.00000002.493989278.000000000289B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: 00000004.00000002.493722594.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: 00000000.00000000.350995207.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: 00000000.00000002.358062507.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: 00000004.00000002.493920709.0000000002383000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
            Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
            Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry Author: ReversingLabs
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeMemory allocated: 770B0000 page execute and read and writeJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeMemory allocated: 770B0000 page execute and read and writeJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile created: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.datJump to behavior
            Source: Joe Sandbox ViewDropped File: C:\Windows\tasksche.exe 2584E1521065E45EC3C17767C065429038FC6291C091097EA8B22C8A502C41DD
            Source: mssecsvc.exe.exeStatic PE information: Resource name: R type: PE32 executable (GUI) Intel 80386, for MS Windows
            Source: tasksche.exe.0.drStatic PE information: Resource name: XIA type: Zip archive data, at least v2.0 to extract, compression method=deflate
            Source: mssecsvc.exe.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: mssecsvc.exe.exe, type: SAMPLEMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
            Source: 00000005.00000000.357354210.000000000040E000.00000008.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: 00000005.00000002.357560055.000000000040E000.00000008.00000001.01000000.00000005.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: 00000004.00000000.355162582.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: 00000004.00000002.493989278.000000000289B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: 00000004.00000002.493722594.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: 00000000.00000000.350995207.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: 00000000.00000002.358062507.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: 00000004.00000002.493920709.0000000002383000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
            Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
            Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware
            Source: tasksche.exe, 00000005.00000002.357560055.000000000040E000.00000008.00000001.01000000.00000005.sdmp, mssecsvc.exe.exe, tasksche.exe.0.drBinary or memory string: @.der.pfx.key.crt.csr.p12.pem.odt.ott.sxw.stw.uot.3ds.max.3dm.ods.ots.sxc.stc.dif.slk.wb2.odp.otp.sxd.std.uop.odg.otg.sxm.mml.lay.lay6.asc.sqlite3.sqlitedb.sql.accdb.mdb.db.dbf.odb.frm.myd.myi.ibd.mdf.ldf.sln.suo.cs.c.cpp.pas.h.asm.js.cmd.bat.ps1.vbs.vb.pl.dip.dch.sch.brd.jsp.php.asp.rb.java.jar.class.sh.mp3.wav.swf.fla.wmv.mpg.vob.mpeg.asf.avi.mov.mp4.3gp.mkv.3g2.flv.wma.mid.m3u.m4u.djvu.svg.ai.psd.nef.tiff.tif.cgm.raw.gif.png.bmp.jpg.jpeg.vcd.iso.backup.zip.rar.7z.gz.tgz.tar.bak.tbk.bz2.PAQ.ARC.aes.gpg.vmx.vmdk.vdi.sldm.sldx.sti.sxi.602.hwp.snt.onetoc2.dwg.pdf.wk1.wks.123.rtf.csv.txt.vsdx.vsd.edb.eml.msg.ost.pst.potm.potx.ppam.ppsx.ppsm.pps.pot.pptm.pptx.ppt.xltm.xltx.xlc.xlm.xlt.xlw.xlsb.xlsm.xlsx.xls.dotx.dotm.dot.docm.docb.docx.docWANACRY!%s\%sCloseHandleDeleteFileWMoveFileExWMoveFileWReadFileWriteFileCreateFileWkernel32.dll
            Source: classification engineClassification label: mal100.rans.expl.evad.winEXE@4/1@2/100
            Source: mssecsvc.exe.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: mssecsvc.exe.exeReversingLabs: Detection: 100%
            Source: mssecsvc.exe.exeVirustotal: Detection: 93%
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile read: C:\Users\user\Desktop\mssecsvc.exe.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\mssecsvc.exe.exe "C:\Users\user\Desktop\mssecsvc.exe.exe"
            Source: unknownProcess created: C:\Users\user\Desktop\mssecsvc.exe.exe C:\Users\user\Desktop\mssecsvc.exe.exe -m security
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeProcess created: C:\Windows\tasksche.exe C:\WINDOWS\tasksche.exe /i
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeProcess created: C:\Windows\tasksche.exe C:\WINDOWS\tasksche.exe /iJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: wow64win.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: wow64cpu.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: msvcp60.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: webio.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: nlaapi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: rpcrtremote.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: wow64win.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: wow64cpu.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: msvcp60.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: webio.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: nlaapi.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeSection loaded: rpcrtremote.dllJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcServer32Jump to behavior
            Source: mssecsvc.exe.exeStatic file information: File size 3723264 > 1048576
            Source: mssecsvc.exe.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x35b000

            Persistence and Installation Behavior

            barindex
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeExecutable created and started: C:\WINDOWS\tasksche.exeJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile created: C:\Windows\tasksche.exeJump to dropped file
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeFile created: C:\Windows\tasksche.exeJump to dropped file
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeThread delayed: delay time: 86400000Jump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exe TID: 3544Thread sleep time: -120000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exe TID: 3736Thread sleep time: -60000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exe TID: 3748Thread sleep count: 50 > 30Jump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exe TID: 3748Thread sleep time: -100000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exe TID: 3752Thread sleep count: 43 > 30Jump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exe TID: 3756Thread sleep count: 163 > 30Jump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exe TID: 3748Thread sleep time: -86400000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeThread delayed: delay time: 86400000Jump to behavior
            Source: C:\Users\user\Desktop\mssecsvc.exe.exeProcess created: C:\Windows\tasksche.exe C:\WINDOWS\tasksche.exe /iJump to behavior
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
            DLL Side-Loading
            11
            Process Injection
            12
            Masquerading
            OS Credential Dumping1
            Network Share Discovery
            Remote ServicesData from Local System2
            Non-Application Layer Protocol
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            21
            Virtualization/Sandbox Evasion
            LSASS Memory1
            Security Software Discovery
            Remote Desktop ProtocolData from Removable Media2
            Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
            Process Injection
            Security Account Manager21
            Virtualization/Sandbox Evasion
            SMB/Windows Admin SharesData from Network Shared Drive12
            Ingress Tool Transfer
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            DLL Side-Loading
            NTDS1
            System Information Discovery
            Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
            Remote System Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet
            behaviorgraph top1 signatures2 2 Behavior Graph ID: 1651503 Sample: mssecsvc.exe.malware Startdate: 28/03/2025 Architecture: WINDOWS Score: 100 26 Tries to download HTTP data from a sinkholed server 2->26 28 Suricata IDS alerts for network traffic 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 3 other signatures 2->32 6 mssecsvc.exe.exe 10 2->6         started        11 mssecsvc.exe.exe 2 10 2->11         started        process3 dnsIp4 18 www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com 6->18 16 C:\Windows\tasksche.exe, PE32 6->16 dropped 34 Drops executables to the windows directory (C:\Windows) and starts them 6->34 13 tasksche.exe 6->13         started        20 192.168.2.96 unknown unknown 11->20 22 192.168.2.97 unknown unknown 11->22 24 99 other IPs or domains 11->24 36 Connects to many different private IPs via SMB (likely to spread or exploit) 11->36 38 Connects to many different private IPs (likely to spread or exploit) 11->38 file5 signatures6 process7 signatures8 40 Antivirus detection for dropped file 13->40 42 Multi AV Scanner detection for dropped file 13->42

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            mssecsvc.exe.exe100%ReversingLabsWin32.Ransomware.WannaCry
            mssecsvc.exe.exe93%VirustotalBrowse
            mssecsvc.exe.exe100%AviraTR/AD.WannaCry.bqdjz
            SourceDetectionScannerLabelLink
            C:\Windows\tasksche.exe100%AviraTR/AD.WannaCry.sewvt
            C:\Windows\tasksche.exe100%ReversingLabsWin32.Ransomware.WannaCry
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            https://www.kryptoslogic.com0%Avira URL Cloudsafe

            Download Network PCAP: filteredfull

            NameIPActiveMaliciousAntivirus DetectionReputation
            www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
            104.16.166.228
            truefalse
              high
              NameMaliciousAntivirus DetectionReputation
              http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com/false
                high
                NameSourceMaliciousAntivirus DetectionReputation
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.commssecsvc.exe.exefalse
                  high
                  https://www.kryptoslogic.commssecsvc.exe.exe, 00000004.00000002.493648746.00000000002F3000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: safe
                  unknown
                  http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comJmssecsvc.exe.exe, 00000004.00000002.493631174.000000000018C000.00000004.00000010.00020000.00000000.sdmpfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    48.187.158.110
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    54.116.157.253
                    unknownUnited States
                    16509AMAZON-02USfalse
                    99.8.119.98
                    unknownUnited States
                    7018ATT-INTERNET4USfalse
                    94.171.178.161
                    unknownNetherlands
                    6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
                    5.19.71.212
                    unknownRussian Federation
                    41733ZTELECOM-ASRUfalse
                    208.211.201.31
                    unknownUnited States
                    701UUNETUSfalse
                    101.224.25.68
                    unknownChina
                    4812CHINANET-SH-APChinaTelecomGroupCNfalse
                    140.117.16.146
                    unknownTaiwan; Republic of China (ROC)
                    17716NTU-TWNationalTaiwanUniversityTWfalse
                    89.1.134.73
                    unknownGermany
                    8422NETCOLOGNEDEfalse
                    146.205.176.228
                    unknownUnited States
                    6871PLUSNETUKInternetServiceProviderGBfalse
                    172.174.65.158
                    unknownUnited States
                    7018ATT-INTERNET4USfalse
                    108.107.122.201
                    unknownUnited States
                    10507SPCSUSfalse
                    47.207.218.58
                    unknownUnited States
                    5650FRONTIER-FRTRUSfalse
                    163.158.157.127
                    unknownNetherlands
                    15435KABELFOONDELTAFiberNederlandNLfalse
                    119.227.153.127
                    unknownIndia
                    9583SIFY-AS-INSifyLimitedINfalse
                    190.219.15.10
                    unknownPanama
                    18809CableOndaPAfalse
                    56.184.149.100
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    91.54.57.35
                    unknownGermany
                    3320DTAGInternetserviceprovideroperationsDEfalse
                    33.171.101.209
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    88.88.35.227
                    unknownNorway
                    2119TELENOR-NEXTELTelenorNorgeASNOfalse
                    197.203.173.195
                    unknownAlgeria
                    36947ALGTEL-ASDZfalse
                    207.153.60.229
                    unknownUnited States
                    10242USINTERNETUSfalse
                    184.42.88.36
                    unknownUnited States
                    5778CENTURYLINK-LEGACY-EMBARQ-RCMTUSfalse
                    47.217.200.31
                    unknownUnited States
                    19108SUDDENLINK-COMMUNICATIONSUSfalse
                    61.0.40.163
                    unknownIndia
                    9829BSNL-NIBNationalInternetBackboneINfalse
                    169.241.72.57
                    unknownUnited States
                    22164CCSDUSfalse
                    86.11.57.185
                    unknownUnited Kingdom
                    5089NTLGBfalse
                    120.220.204.128
                    unknownChina
                    24444CMNET-V4SHANDONG-AS-APShandongMobileCommunicationCompanyfalse
                    73.62.122.29
                    unknownUnited States
                    7922COMCAST-7922USfalse
                    73.147.49.137
                    unknownUnited States
                    7922COMCAST-7922USfalse
                    108.235.14.36
                    unknownUnited States
                    7018ATT-INTERNET4USfalse
                    17.11.229.29
                    unknownUnited States
                    714APPLE-ENGINEERINGUSfalse
                    139.16.199.207
                    unknownGermany
                    9905LINKNET-ID-APLinknetASNIDfalse
                    50.76.102.155
                    unknownUnited States
                    7922COMCAST-7922USfalse
                    27.253.113.223
                    unknownAustralia
                    4804MPX-ASMicroplexPTYLTDAUfalse
                    128.24.67.56
                    unknownUnited States
                    786JANETJiscServicesLimitedGBfalse
                    31.165.163.7
                    unknownSwitzerland
                    6730SUNRISECHfalse
                    115.53.69.235
                    unknownChina
                    4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                    23.21.155.227
                    unknownUnited States
                    14618AMAZON-AESUSfalse
                    171.176.151.176
                    unknownUnited States
                    9874STARHUB-MOBILEStarHubLtdSGfalse
                    37.174.65.106
                    unknownFrance
                    51207FREEMFRfalse
                    114.86.40.249
                    unknownChina
                    4812CHINANET-SH-APChinaTelecomGroupCNfalse
                    169.215.77.25
                    unknownKorea Republic of
                    37611AfrihostZAfalse
                    185.22.86.4
                    unknownItaly
                    12874FASTWEBITfalse
                    61.166.54.193
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    36.252.138.242
                    unknownNepal
                    38565NCELL-AS-NPNcellPvtLtdNPfalse
                    130.82.143.12
                    unknownSwitzerland
                    559SWITCHPeeringrequestspeeringswitchchEUfalse
                    68.149.251.220
                    unknownCanada
                    6327SHAWCAfalse
                    119.41.187.169
                    unknownChina
                    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                    32.158.251.29
                    unknownUnited States
                    2686ATGS-MMD-ASUSfalse
                    203.97.45.90
                    unknownNew Zealand
                    4768VFNZ-INET-ASVodafoneNZLtdNZfalse
                    27.5.84.185
                    unknownIndia
                    17488HATHWAY-NET-APHathwayIPOverCableInternetINfalse
                    112.79.67.193
                    unknownIndia
                    38266VODAFONE-INVodafoneIndiaLtdINfalse
                    78.85.4.49
                    unknownRussian Federation
                    12389ROSTELECOM-ASRUfalse
                    207.106.28.14
                    unknownUnited States
                    7029WINDSTREAMUSfalse
                    75.137.181.145
                    unknownUnited States
                    20115CHARTER-20115USfalse
                    84.172.176.246
                    unknownGermany
                    3320DTAGInternetserviceprovideroperationsDEfalse
                    98.232.68.241
                    unknownUnited States
                    7922COMCAST-7922USfalse
                    74.205.177.150
                    unknownCanada
                    53618ADITY-OSH-ASCAfalse
                    2.142.134.135
                    unknownSpain
                    3352TELEFONICA_DE_ESPANAESfalse
                    187.239.131.71
                    unknownMexico
                    8151UninetSAdeCVMXfalse
                    84.213.184.157
                    unknownNorway
                    41164GET-NOGETNorwayNOfalse
                    IP
                    192.168.2.148
                    192.168.2.149
                    192.168.2.146
                    192.168.2.147
                    192.168.2.140
                    192.168.2.141
                    192.168.2.144
                    192.168.2.145
                    192.168.2.142
                    192.168.2.143
                    192.168.2.159
                    192.168.2.157
                    192.168.2.158
                    192.168.2.151
                    192.168.2.152
                    192.168.2.150
                    192.168.2.155
                    192.168.2.156
                    192.168.2.153
                    192.168.2.154
                    192.168.2.126
                    192.168.2.127
                    192.168.2.124
                    192.168.2.125
                    192.168.2.128
                    192.168.2.129
                    192.168.2.122
                    192.168.2.123
                    192.168.2.120
                    192.168.2.121
                    192.168.2.97
                    192.168.2.137
                    192.168.2.96
                    192.168.2.138
                    192.168.2.99
                    192.168.2.135
                    192.168.2.98
                    192.168.2.136
                    Joe Sandbox version:42.0.0 Malachite
                    Analysis ID:1651503
                    Start date and time:2025-03-28 22:12:33 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 4m 16s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:default.jbs
                    Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
                    Number of analysed new started processes analysed:7
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Sample name:mssecsvc.exe.exe
                    (renamed file extension from malware to exe)
                    Original Sample Name:mssecsvc.exe.malware
                    Detection:MAL
                    Classification:mal100.rans.expl.evad.winEXE@4/1@2/100
                    • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe
                    • Report size exceeded maximum capacity and may have missing behavior information.
                    • Report size getting too big, too many NtDeviceIoControlFile calls found.
                    • Report size getting too big, too many NtOpenKeyEx calls found.
                    • Report size getting too big, too many NtQueryValueKey calls found.
                    TimeTypeDescription
                    17:13:24API Interceptor3483x Sleep call for process: mssecsvc.exe.exe modified
                    No context
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com5V38PCLhiz.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    ImPgtzz6o4.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    ET6LdJaK54.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    GeW4GzT8G8.dllGet hashmaliciousVirut, WannacryBrowse
                    • 104.16.166.228
                    JRTn7b1kHg.dllGet hashmaliciousWannacryBrowse
                    • 104.16.166.228
                    alN48K3xcD.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    NZZ71x6Cyz.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    bC61G18iPf.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    XB6SkLK7Al.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    ue5QSYCBPt.dllGet hashmaliciousWannacryBrowse
                    • 104.16.167.228
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    AMAZON-02USjade420.x86.elfGet hashmaliciousMiraiBrowse
                    • 34.249.145.219
                    http://188.114.96.3Get hashmaliciousUnknownBrowse
                    • 13.216.34.24
                    SPChaotic.exeGet hashmaliciousXWormBrowse
                    • 3.126.224.214
                    SysRuntime.exeGet hashmaliciousXWormBrowse
                    • 3.126.224.214
                    https://clicktime.cloud.postoffice.net/clicktime.php?U=https://jpmchase.secure.virtru.com/start/%3Fc%3Dexperiment%26t%3Demailtemplate2019-09%26s%3Dddc.sr%2540chase.com%26p%3D7db6612f-a3dd-473a-95ad-f5289da77171%23v%3D3.0.0%26d%3Dhttps%253A%252F%252Fapi.virtru.com%252Fstorage%252Fapi%252Fpolicies%252F7db6612f-a3dd-473a-95ad-f5289da77171%252Fdata%252Fmetadata%26dk%3DoebNRZyiVlMa6AoTyAKeCwLGpwgdjLHhM1YiU6zqddU%253D&E=jwyland%40woodlandsbank.com&X=XID390dcbRyp9059Xd1&T=WDLP&HV=U,E,X,T&H=ec39b06efb6207f560ffe0a7da20e1335f9cfff7Get hashmaliciousUnknownBrowse
                    • 44.225.54.253
                    SystemRuntime.exeGet hashmaliciousXWormBrowse
                    • 3.126.224.214
                    clientiac.exeGet hashmaliciousXWormBrowse
                    • 3.126.224.214
                    Clientiawh.exeGet hashmaliciousXWormBrowse
                    • 3.126.224.214
                    https://6uq8xyud.bucpdccx.ru/YSEJz/Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                    • 3.168.73.27
                    https://L1h.toliviraxen.ru/MzobBPAf/Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                    • 13.224.214.119
                    LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingbimbo-mpsl.elfGet hashmaliciousUnknownBrowse
                    • 89.75.162.14
                    bimbo-x86.elfGet hashmaliciousUnknownBrowse
                    • 80.218.194.247
                    k03ldc.arm.elfGet hashmaliciousUnknownBrowse
                    • 109.90.234.37
                    k03ldc.mpsl.elfGet hashmaliciousUnknownBrowse
                    • 86.49.76.47
                    m68k.elfGet hashmaliciousUnknownBrowse
                    • 94.171.245.99
                    vjwe68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                    • 88.146.165.82
                    bejv86.elfGet hashmaliciousMiraiBrowse
                    • 88.153.178.20
                    efjepc.elfGet hashmaliciousGafgyt, MiraiBrowse
                    • 80.110.209.41
                    eehah4.elfGet hashmaliciousGafgyt, MiraiBrowse
                    • 80.218.194.240
                    resgod.sh4.elfGet hashmaliciousMiraiBrowse
                    • 85.124.31.24
                    ATGS-MMD-ASUShttp://188.114.96.3Get hashmaliciousUnknownBrowse
                    • 34.49.212.111
                    https://clicktime.cloud.postoffice.net/clicktime.php?U=https://jpmchase.secure.virtru.com/start/%3Fc%3Dexperiment%26t%3Demailtemplate2019-09%26s%3Dddc.sr%2540chase.com%26p%3D7db6612f-a3dd-473a-95ad-f5289da77171%23v%3D3.0.0%26d%3Dhttps%253A%252F%252Fapi.virtru.com%252Fstorage%252Fapi%252Fpolicies%252F7db6612f-a3dd-473a-95ad-f5289da77171%252Fdata%252Fmetadata%26dk%3DoebNRZyiVlMa6AoTyAKeCwLGpwgdjLHhM1YiU6zqddU%253D&E=jwyland%40woodlandsbank.com&X=XID390dcbRyp9059Xd1&T=WDLP&HV=U,E,X,T&H=ec39b06efb6207f560ffe0a7da20e1335f9cfff7Get hashmaliciousUnknownBrowse
                    • 34.160.98.162
                    https://issuu.com/tylockgeorge/docs/gf-007733281?fr=sYmZjNDgzOTA5MjYGet hashmaliciousInvisible JS, Tycoon2FABrowse
                    • 57.144.180.1
                    https://url.us.m.mimecastprotect.com/s/RCIkCyPJBYF0OAoruZfnUxNKPR?domain=issuu.comGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                    • 57.144.180.1
                    https://briggsandstratton.login-usb.mimecast.com/u/login/?gta=secure&tkn=3.AP6_gtafyD5PTk8Aevs7qWMs7rB-RgGOOAKjDD6Jp5jm6n3ECvVIZPaSlRslpe0yv7DdQAhFJCSa--KRirpg9vlymGkSVGUQ63wUGFYsG3Fzz2ibtSIyhA08Z5SvCFfw.5XaglCTBXgq_lRG5w_yCsQGet hashmaliciousUnknownBrowse
                    • 34.36.213.229
                    https://openrefine.org/downloadGet hashmaliciousUnknownBrowse
                    • 34.54.88.138
                    ATT02683-1.pdfGet hashmaliciousUnknownBrowse
                    • 34.149.73.226
                    https://app.eraser.io/workspace/ISn1eLCg7dzDBCScfS1e?origin=shareGet hashmaliciousUnknownBrowse
                    • 34.8.177.196
                    http://ergonperizie.notion.site/1c3e29532f0a808e8960ccaa2fe479e5Get hashmaliciousHTMLPhisherBrowse
                    • 57.144.180.128
                    https://innovation-platform-6635.my.salesforce-sites.com/secGet hashmaliciousHTMLPhisherBrowse
                    • 34.49.212.111
                    ATT-INTERNET4USA_W-NP_packetstream.exeGet hashmaliciousUnknownBrowse
                    • 209.38.174.165
                    A_W-NP_packetstream.exeGet hashmaliciousUnknownBrowse
                    • 209.38.174.165
                    bimbo-m68k.elfGet hashmaliciousUnknownBrowse
                    • 63.192.66.211
                    bimbo-mpsl.elfGet hashmaliciousUnknownBrowse
                    • 12.38.242.165
                    bimbo-arm.elfGet hashmaliciousUnknownBrowse
                    • 75.3.79.141
                    bimbo-ppc.elfGet hashmaliciousUnknownBrowse
                    • 12.198.36.114
                    bimbo-spc.elfGet hashmaliciousUnknownBrowse
                    • 74.185.28.70
                    bimbo-x86.elfGet hashmaliciousUnknownBrowse
                    • 172.182.199.18
                    bimbo-mips.elfGet hashmaliciousUnknownBrowse
                    • 68.252.41.131
                    k03ldc.arm.elfGet hashmaliciousUnknownBrowse
                    • 65.64.249.114
                    No context
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    C:\Windows\tasksche.exeGeW4GzT8G8.dllGet hashmaliciousVirut, WannacryBrowse
                      JRTn7b1kHg.dllGet hashmaliciousWannacryBrowse
                        S8LDvVdtOk.dllGet hashmaliciousWannacryBrowse
                          9nNO3SHiV1.dllGet hashmaliciousWannacryBrowse
                            zbRmQrzaHY.dllGet hashmaliciousWannacryBrowse
                              zyeX8bTkky.dllGet hashmaliciousWannacryBrowse
                                qt680eucI4.dllGet hashmaliciousWannacryBrowse
                                  1w3BDu68Sg.dllGet hashmaliciousWannacryBrowse
                                    qCc1a4w5YZ.exeGet hashmaliciousWannacryBrowse
                                      stN592INV6.exeGet hashmaliciousWannacryBrowse
                                        Process:C:\Users\user\Desktop\mssecsvc.exe.exe
                                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):3514368
                                        Entropy (8bit):7.996072890929898
                                        Encrypted:true
                                        SSDEEP:98304:QqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2Hj:QqPe1Cxcxk3ZAEUadzR8yc4Hj
                                        MD5:7F7CCAA16FB15EB1C7399D422F8363E8
                                        SHA1:BD44D0AB543BF814D93B719C24E90D8DD7111234
                                        SHA-256:2584E1521065E45EC3C17767C065429038FC6291C091097EA8B22C8A502C41DD
                                        SHA-512:83E334B80DE08903CFA9891A3FA349C1ECE7E19F8E62B74A017512FA9A7989A0FD31929BF1FC13847BEE04F2DA3DACF6BC3F5EE58F0E4B9D495F4B9AF12ED2B7
                                        Malicious:true
                                        Yara Hits:
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Windows\tasksche.exe, Author: Joe Security
                                        • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\tasksche.exe, Author: Florian Roth (with the help of binar.ly)
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: C:\Windows\tasksche.exe, Author: us-cert code analysis team
                                        • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Windows\tasksche.exe, Author: ReversingLabs
                                        Antivirus:
                                        • Antivirus: Avira, Detection: 100%
                                        • Antivirus: ReversingLabs, Detection: 100%
                                        Joe Sandbox View:
                                        • Filename: GeW4GzT8G8.dll, Detection: malicious, Browse
                                        • Filename: JRTn7b1kHg.dll, Detection: malicious, Browse
                                        • Filename: S8LDvVdtOk.dll, Detection: malicious, Browse
                                        • Filename: 9nNO3SHiV1.dll, Detection: malicious, Browse
                                        • Filename: zbRmQrzaHY.dll, Detection: malicious, Browse
                                        • Filename: zyeX8bTkky.dll, Detection: malicious, Browse
                                        • Filename: qt680eucI4.dll, Detection: malicious, Browse
                                        • Filename: 1w3BDu68Sg.dll, Detection: malicious, Browse
                                        • Filename: qCc1a4w5YZ.exe, Detection: malicious, Browse
                                        • Filename: stN592INV6.exe, Detection: malicious, Browse
                                        Reputation:moderate, very likely benign file
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........:..T...T...T..X...T.._...T.'.Z...T..^...T..P...T.g.....T...U...T..._...T.c.R...T.Rich..T.........................PE..L...A..L.................p... 5......w............@...........................5.................................................d.........4..........................................................................................................text....i.......p.................. ..`.rdata..p_.......`..................@..@.data...X........ ..................@....rsrc.....4.......4.................@..@........................................................................................................................................................................................................................................................................................................................................................
                                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Entropy (8bit):7.965905243891064
                                        TrID:
                                        • Win32 Executable (generic) a (10002005/4) 99.96%
                                        • Generic Win/DOS Executable (2004/3) 0.02%
                                        • DOS Executable Generic (2002/1) 0.02%
                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                        File name:mssecsvc.exe.exe
                                        File size:3'723'264 bytes
                                        MD5:0c694193ceac8bfb016491ffb534eb7c
                                        SHA1:3afa73283d1e17de1bde6cc14e19417e70fc9554
                                        SHA256:dbf3890b782ac04136c3336814eef97e3c0f4133f9592e882c131c179161b27b
                                        SHA512:bfa729e9449c0a438cfb51fc9f4314022b2f18092938fd42702a06246edc865db77327399a8d21cc1fa208a99e3436e4a460cb010e428caddc638c3fa6547afb
                                        SSDEEP:98304:yDqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2HI:yDqPe1Cxcxk3ZAEUadzR8yc4HI
                                        TLSH:19063394612CB2FCF0440EB44473896AB7B33C69A7BA5E1F9BC086670D53B5BAFD0641
                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......U<S..]=..]=..]=.jA1..]=..A3..]=.~B7..]=.~B6..]=.~B9..]=..R`..]=..]<.J]=.'{6..]=..[;..]=.Rich.]=.........................PE..L..
                                        Icon Hash:aaf3e3e3918382a0
                                        Entrypoint:0x409a16
                                        Entrypoint Section:.text
                                        Digitally signed:false
                                        Imagebase:0x400000
                                        Subsystem:windows gui
                                        Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                        DLL Characteristics:
                                        Time Stamp:0x4CE78ECC [Sat Nov 20 09:03:08 2010 UTC]
                                        TLS Callbacks:
                                        CLR (.Net) Version:
                                        OS Version Major:4
                                        OS Version Minor:0
                                        File Version Major:4
                                        File Version Minor:0
                                        Subsystem Version Major:4
                                        Subsystem Version Minor:0
                                        Import Hash:9ecee117164e0b870a53dd187cdd7174
                                        Instruction
                                        push ebp
                                        mov ebp, esp
                                        push FFFFFFFFh
                                        push 0040A1A0h
                                        push 00409BA2h
                                        mov eax, dword ptr fs:[00000000h]
                                        push eax
                                        mov dword ptr fs:[00000000h], esp
                                        sub esp, 68h
                                        push ebx
                                        push esi
                                        push edi
                                        mov dword ptr [ebp-18h], esp
                                        xor ebx, ebx
                                        mov dword ptr [ebp-04h], ebx
                                        push 00000002h
                                        call dword ptr [0040A0C0h]
                                        pop ecx
                                        or dword ptr [0070F894h], FFFFFFFFh
                                        or dword ptr [0070F898h], FFFFFFFFh
                                        call dword ptr [0040A0C8h]
                                        mov ecx, dword ptr [0070F88Ch]
                                        mov dword ptr [eax], ecx
                                        call dword ptr [0040A0CCh]
                                        mov ecx, dword ptr [0070F888h]
                                        mov dword ptr [eax], ecx
                                        mov eax, dword ptr [0040A0E4h]
                                        mov eax, dword ptr [eax]
                                        mov dword ptr [0070F890h], eax
                                        call 00007F2EB07F5D31h
                                        cmp dword ptr [00431410h], ebx
                                        jne 00007F2EB07F5C1Eh
                                        push 00409B9Eh
                                        call dword ptr [0040A0D4h]
                                        pop ecx
                                        call 00007F2EB07F5D03h
                                        push 0040B010h
                                        push 0040B00Ch
                                        call 00007F2EB07F5CEEh
                                        mov eax, dword ptr [0070F884h]
                                        mov dword ptr [ebp-6Ch], eax
                                        lea eax, dword ptr [ebp-6Ch]
                                        push eax
                                        push dword ptr [0070F880h]
                                        lea eax, dword ptr [ebp-64h]
                                        push eax
                                        lea eax, dword ptr [ebp-70h]
                                        push eax
                                        lea eax, dword ptr [ebp-60h]
                                        push eax
                                        call dword ptr [0040A0DCh]
                                        push 0040B008h
                                        push 0040B000h
                                        call 00007F2EB07F5CBBh
                                        Programming Language:
                                        • [C++] VS98 (6.0) SP6 build 8804
                                        • [EXP] VC++ 6.0 SP5 build 8804
                                        NameVirtual AddressVirtual Size Is in Section
                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_IMPORT0xa1e00xa0.rdata
                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x3100000x35a454.rsrc
                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_IAT0xa0000x188.rdata
                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                        .text0x10000x8bca0x9000799fa6f54ef4176da2990896faea65d8False0.534423828125data6.1345234015658825IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                        .rdata0xa0000x9980x1000d8037d744b539326c06e897625751cc9False0.29345703125data3.503615586181224IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        .data0xb0000x30489c0x2700022a8598dc29cad7078c291e94612ce26unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                        .rsrc0x3100000x35a4540x35b000a19437cf29a158eae9109b8ecb75975dunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        NameRVASizeTypeLanguageCountryZLIB Complexity
                                        R0x3100a40x35a000PE32 executable (GUI) Intel 80386, for MS WindowsEnglishUnited States0.9710664749145508
                                        RT_VERSION0x66a0a40x3b0dataEnglishUnited States1.0116525423728813
                                        DLLImport
                                        KERNEL32.dllWaitForSingleObject, InterlockedIncrement, GetCurrentThreadId, GetCurrentThread, ReadFile, GetFileSize, CreateFileA, MoveFileExA, SizeofResource, TerminateThread, LoadResource, FindResourceA, GetProcAddress, GetModuleHandleW, ExitProcess, GetModuleFileNameA, LocalFree, LocalAlloc, CloseHandle, InterlockedDecrement, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, GlobalAlloc, GlobalFree, QueryPerformanceFrequency, QueryPerformanceCounter, GetTickCount, LockResource, Sleep, GetStartupInfoA, GetModuleHandleA
                                        ADVAPI32.dllStartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, ChangeServiceConfig2A, SetServiceStatus, OpenSCManagerA, CreateServiceA, CloseServiceHandle, StartServiceA, CryptGenRandom, CryptAcquireContextA, OpenServiceA
                                        WS2_32.dllclosesocket, recv, send, htonl, ntohl, WSAStartup, inet_ntoa, ioctlsocket, select, htons, socket, connect, inet_addr
                                        MSVCP60.dll??1_Lockit@std@@QAE@XZ, ??0_Lockit@std@@QAE@XZ
                                        iphlpapi.dllGetAdaptersInfo, GetPerAdapterInfo
                                        WININET.dllInternetOpenA, InternetOpenUrlA, InternetCloseHandle
                                        MSVCRT.dll__set_app_type, _stricmp, __p__fmode, __p__commode, _except_handler3, __setusermatherr, _initterm, __getmainargs, _acmdln, _adjust_fdiv, _controlfp, exit, _XcptFilter, _exit, _onexit, __dllonexit, free, ??2@YAPAXI@Z, _ftol, sprintf, _endthreadex, strncpy, rand, _beginthreadex, __CxxFrameHandler, srand, time, __p___argc
                                        Language of compilation systemCountry where language is spokenMap
                                        EnglishUnited States

                                        Download Network PCAP: filteredfull

                                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                        2025-03-28T22:13:26.695035+01002024291ET MALWARE Possible WannaCry DNS Lookup 11192.168.2.22545628.8.8.853UDP
                                        2025-03-28T22:13:26.998238+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.2249161104.16.166.22880TCP
                                        2025-03-28T22:13:26.998238+01002024298ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 11192.168.2.2249161104.16.166.22880TCP
                                        2025-03-28T22:13:26.998238+01002024299ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 21192.168.2.2249161104.16.166.22880TCP
                                        2025-03-28T22:13:26.998238+01002024301ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 41192.168.2.2249161104.16.166.22880TCP
                                        2025-03-28T22:13:26.998238+01002024302ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 51192.168.2.2249161104.16.166.22880TCP
                                        2025-03-28T22:13:26.998295+01002031515ET MALWARE Known Sinkhole Response Kryptos Logic3104.16.166.22880192.168.2.2249161TCP
                                        2025-03-28T22:13:27.565802+01002024291ET MALWARE Possible WannaCry DNS Lookup 11192.168.2.22529178.8.8.853UDP
                                        2025-03-28T22:13:27.867162+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.2249162104.16.166.22880TCP
                                        2025-03-28T22:13:27.867162+01002024298ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 11192.168.2.2249162104.16.166.22880TCP
                                        2025-03-28T22:13:27.867162+01002024299ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 21192.168.2.2249162104.16.166.22880TCP
                                        2025-03-28T22:13:27.867162+01002024301ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 41192.168.2.2249162104.16.166.22880TCP
                                        2025-03-28T22:13:27.867162+01002024302ET MALWARE W32/WannaCry.Ransomware Killswitch Domain HTTP Request 51192.168.2.2249162104.16.166.22880TCP
                                        2025-03-28T22:13:27.867818+01002031515ET MALWARE Known Sinkhole Response Kryptos Logic3104.16.166.22880192.168.2.2249162TCP
                                        • Total Packets: 999
                                        • 445 (Microsoft-DS)
                                        • 80 (HTTP)
                                        • 53 (DNS)
                                        TimestampSource PortDest PortSource IPDest IP
                                        Mar 28, 2025 22:13:26.812019110 CET4916180192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:26.896403074 CET8049161104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:26.896492004 CET4916180192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:26.896770954 CET4916180192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:26.981064081 CET8049161104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:26.998145103 CET8049161104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:26.998238087 CET4916180192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:26.998295069 CET8049161104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:26.998341084 CET4916180192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.015580893 CET4916180192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.099975109 CET8049161104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:27.656785011 CET4916280192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.740268946 CET8049162104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:27.740335941 CET4916280192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.765008926 CET4916280192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.850300074 CET8049162104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:27.867098093 CET8049162104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:27.867161989 CET4916280192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.867818117 CET8049162104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:27.867875099 CET4916280192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.874833107 CET4916280192.168.2.22104.16.166.228
                                        Mar 28, 2025 22:13:27.897934914 CET49163445192.168.2.22179.149.119.240
                                        Mar 28, 2025 22:13:27.958687067 CET8049162104.16.166.228192.168.2.22
                                        Mar 28, 2025 22:13:29.007746935 CET49176445192.168.2.225.161.3.226
                                        Mar 28, 2025 22:13:29.898066044 CET49187445192.168.2.2241.249.225.248
                                        Mar 28, 2025 22:13:30.132015944 CET49188445192.168.2.2260.243.179.166
                                        Mar 28, 2025 22:13:31.051357031 CET49200445192.168.2.2274.10.148.155
                                        Mar 28, 2025 22:13:31.254194975 CET49203445192.168.2.2246.78.169.146
                                        Mar 28, 2025 22:13:31.917346954 CET49211445192.168.2.22197.18.246.111
                                        Mar 28, 2025 22:13:32.174642086 CET49214445192.168.2.22197.154.3.137
                                        Mar 28, 2025 22:13:32.377566099 CET49216445192.168.2.22184.42.88.36
                                        Mar 28, 2025 22:13:33.032850981 CET49224445192.168.2.2250.103.164.43
                                        Mar 28, 2025 22:13:33.298491001 CET49229445192.168.2.22219.79.251.133
                                        Mar 28, 2025 22:13:33.500845909 CET49231445192.168.2.22110.137.80.58
                                        Mar 28, 2025 22:13:33.923280001 CET49239445192.168.2.2211.80.13.222
                                        Mar 28, 2025 22:13:34.155889034 CET49242445192.168.2.22173.48.34.114
                                        Mar 28, 2025 22:13:34.421067953 CET49244445192.168.2.22207.193.131.196
                                        Mar 28, 2025 22:13:34.623821974 CET49247445192.168.2.2276.85.155.151
                                        Mar 28, 2025 22:13:35.045094967 CET49254445192.168.2.22105.153.176.87
                                        Mar 28, 2025 22:13:35.279028893 CET49257445192.168.2.22143.95.188.165
                                        Mar 28, 2025 22:13:35.544378996 CET49259445192.168.2.22201.11.248.31
                                        Mar 28, 2025 22:13:35.747322083 CET49262445192.168.2.2292.139.187.164
                                        Mar 28, 2025 22:13:35.935193062 CET49265445192.168.2.22206.70.205.171
                                        Mar 28, 2025 22:13:36.168174982 CET49270445192.168.2.22177.35.175.109
                                        Mar 28, 2025 22:13:36.402201891 CET49273445192.168.2.22149.136.152.42
                                        Mar 28, 2025 22:13:36.667462111 CET49275445192.168.2.22193.167.47.61
                                        Mar 28, 2025 22:13:36.870326996 CET49278445192.168.2.2231.165.163.7
                                        Mar 28, 2025 22:13:37.057884932 CET49281445192.168.2.22160.195.89.246
                                        Mar 28, 2025 22:13:37.291415930 CET49286445192.168.2.2225.26.63.98
                                        Mar 28, 2025 22:13:37.525475979 CET49289445192.168.2.2215.243.91.206
                                        Mar 28, 2025 22:13:37.790760994 CET49291445192.168.2.22199.114.150.9
                                        Mar 28, 2025 22:13:37.947860003 CET49294445192.168.2.2266.31.1.205
                                        Mar 28, 2025 22:13:37.993495941 CET49296445192.168.2.22156.145.178.95
                                        Mar 28, 2025 22:13:38.180711031 CET49300445192.168.2.22185.27.29.32
                                        Mar 28, 2025 22:13:38.414688110 CET49303445192.168.2.22194.147.16.167
                                        Mar 28, 2025 22:13:38.648663998 CET49307445192.168.2.226.125.30.242
                                        Mar 28, 2025 22:13:38.913952112 CET49308445192.168.2.22149.180.173.172
                                        Mar 28, 2025 22:13:39.069796085 CET49311445192.168.2.2243.26.27.7
                                        Mar 28, 2025 22:13:39.116724968 CET49313445192.168.2.22188.92.66.47
                                        Mar 28, 2025 22:13:39.303988934 CET49317445192.168.2.227.74.55.124
                                        Mar 28, 2025 22:13:39.537976980 CET49320445192.168.2.2270.38.197.97
                                        Mar 28, 2025 22:13:39.771815062 CET49324445192.168.2.22119.41.187.169
                                        Mar 28, 2025 22:13:39.960212946 CET49325445192.168.2.2253.33.231.37
                                        Mar 28, 2025 22:13:40.037031889 CET49327445192.168.2.22187.49.66.157
                                        Mar 28, 2025 22:13:40.193061113 CET49329445192.168.2.2224.207.133.106
                                        Mar 28, 2025 22:13:40.240475893 CET49331445192.168.2.22117.62.196.67
                                        Mar 28, 2025 22:13:40.427160025 CET49335445192.168.2.22122.166.104.87
                                        Mar 28, 2025 22:13:40.661109924 CET49339445192.168.2.2275.59.51.134
                                        Mar 28, 2025 22:13:40.895139933 CET49342445192.168.2.2241.123.182.192
                                        Mar 28, 2025 22:13:41.082201958 CET49344445192.168.2.22113.90.248.144
                                        Mar 28, 2025 22:13:41.160212994 CET49345445192.168.2.22148.134.135.3
                                        Mar 28, 2025 22:13:41.316350937 CET49348445192.168.2.221.165.181.98
                                        Mar 28, 2025 22:13:41.363159895 CET49350445192.168.2.22168.55.217.78
                                        Mar 28, 2025 22:13:41.550343990 CET49354445192.168.2.221.165.100.74
                                        Mar 28, 2025 22:13:41.784269094 CET49357445192.168.2.22174.55.128.32
                                        Mar 28, 2025 22:13:41.971725941 CET49360445192.168.2.22220.29.156.26
                                        Mar 28, 2025 22:13:42.018215895 CET49361445192.168.2.22130.244.121.188
                                        Mar 28, 2025 22:13:42.205485106 CET49363445192.168.2.22120.13.28.253
                                        Mar 28, 2025 22:13:42.283406019 CET49364445192.168.2.22174.78.90.36
                                        Mar 28, 2025 22:13:42.439479113 CET49367445192.168.2.22199.225.245.161
                                        Mar 28, 2025 22:13:42.486160040 CET49369445192.168.2.22169.225.211.231
                                        Mar 28, 2025 22:13:42.673567057 CET49373445192.168.2.2279.120.121.88
                                        Mar 28, 2025 22:13:42.907396078 CET49376445192.168.2.227.183.154.32
                                        Mar 28, 2025 22:13:43.094516039 CET49379445192.168.2.22202.138.100.114
                                        Mar 28, 2025 22:13:43.141357899 CET49380445192.168.2.2216.13.30.135
                                        Mar 28, 2025 22:13:43.328836918 CET49382445192.168.2.22124.148.8.236
                                        Mar 28, 2025 22:13:43.406661034 CET49384445192.168.2.22105.228.76.67
                                        Mar 28, 2025 22:13:43.585227966 CET49387445192.168.2.22152.163.32.169
                                        Mar 28, 2025 22:13:43.609450102 CET49388445192.168.2.2215.201.178.168
                                        Mar 28, 2025 22:13:43.796762943 CET49392445192.168.2.2220.30.150.187
                                        Mar 28, 2025 22:13:43.984184980 CET49394445192.168.2.22197.203.173.195
                                        Mar 28, 2025 22:13:44.030601978 CET49396445192.168.2.2296.81.82.135
                                        Mar 28, 2025 22:13:44.217835903 CET49399445192.168.2.2234.238.48.77
                                        Mar 28, 2025 22:13:44.324876070 CET49400445192.168.2.22151.14.212.165
                                        Mar 28, 2025 22:13:44.454633951 CET49402445192.168.2.22148.229.217.69
                                        Mar 28, 2025 22:13:44.530853987 CET49404445192.168.2.22195.147.120.80
                                        Mar 28, 2025 22:13:44.701452017 CET49408445192.168.2.22119.91.210.129
                                        Mar 28, 2025 22:13:44.732626915 CET49410445192.168.2.22207.106.28.14
                                        Mar 28, 2025 22:13:44.919825077 CET49413445192.168.2.2255.245.252.132
                                        Mar 28, 2025 22:13:45.106952906 CET49416445192.168.2.22189.209.116.60
                                        Mar 28, 2025 22:13:45.153925896 CET49418445192.168.2.2241.238.172.233
                                        Mar 28, 2025 22:13:45.341070890 CET49419445192.168.2.224.84.0.61
                                        Mar 28, 2025 22:13:45.450221062 CET49421445192.168.2.22214.24.149.164
                                        Mar 28, 2025 22:13:45.575120926 CET49422445192.168.2.22123.18.170.237
                                        Mar 28, 2025 22:13:45.653009892 CET49424445192.168.2.2298.151.217.175
                                        Mar 28, 2025 22:13:45.824590921 CET49428445192.168.2.22105.178.220.183
                                        Mar 28, 2025 22:13:45.855813980 CET49429445192.168.2.22148.39.0.26
                                        Mar 28, 2025 22:13:45.996299982 CET49433445192.168.2.2260.194.22.156
                                        Mar 28, 2025 22:13:46.043176889 CET49434445192.168.2.22159.234.222.237
                                        Mar 28, 2025 22:13:46.230178118 CET49438445192.168.2.2273.147.49.137
                                        Mar 28, 2025 22:13:46.277045965 CET49439445192.168.2.22123.131.59.57
                                        Mar 28, 2025 22:13:46.464360952 CET49441445192.168.2.22184.88.152.97
                                        Mar 28, 2025 22:13:46.573539019 CET49442445192.168.2.2220.28.170.20
                                        Mar 28, 2025 22:13:46.698235989 CET49443445192.168.2.2288.53.76.71
                                        Mar 28, 2025 22:13:46.776209116 CET49445445192.168.2.22193.62.156.36
                                        Mar 28, 2025 22:13:46.948220015 CET49449445192.168.2.2279.171.69.105
                                        Mar 28, 2025 22:13:46.979208946 CET49450445192.168.2.221.239.5.200
                                        Mar 28, 2025 22:13:47.120795965 CET49453445192.168.2.2231.117.66.175
                                        Mar 28, 2025 22:13:47.168914080 CET49455445192.168.2.22171.73.152.92
                                        Mar 28, 2025 22:13:47.355230093 CET49459445192.168.2.22181.94.75.76
                                        Mar 28, 2025 22:13:47.406860113 CET49460445192.168.2.2227.120.100.183
                                        Mar 28, 2025 22:13:47.590503931 CET49462445192.168.2.22122.58.126.15
                                        Mar 28, 2025 22:13:47.699323893 CET49463445192.168.2.22218.146.212.110
                                        Mar 28, 2025 22:13:47.821695089 CET49465445192.168.2.22110.172.80.85
                                        Mar 28, 2025 22:13:47.899441004 CET49466445192.168.2.2262.185.251.241
                                        Mar 28, 2025 22:13:48.008706093 CET49469445192.168.2.2247.217.200.31
                                        Mar 28, 2025 22:13:48.071049929 CET49471445192.168.2.22218.138.187.213
                                        Mar 28, 2025 22:13:48.102551937 CET49472445192.168.2.22142.239.251.76
                                        Mar 28, 2025 22:13:48.242666960 CET49476445192.168.2.22204.32.121.17
                                        Mar 28, 2025 22:13:48.289539099 CET49477445192.168.2.22141.175.149.49
                                        Mar 28, 2025 22:13:48.476635933 CET49481445192.168.2.2221.63.180.101
                                        Mar 28, 2025 22:13:48.523544073 CET49482445192.168.2.22120.107.118.33
                                        Mar 28, 2025 22:13:48.710716963 CET49484445192.168.2.2275.137.181.145
                                        Mar 28, 2025 22:13:48.819924116 CET49485445192.168.2.22118.108.63.98
                                        Mar 28, 2025 22:13:48.944761038 CET49487445192.168.2.22216.159.85.220
                                        Mar 28, 2025 22:13:49.022763968 CET49488445192.168.2.22195.188.243.7
                                        Mar 28, 2025 22:13:49.131767035 CET49491445192.168.2.2288.174.211.137
                                        Mar 28, 2025 22:13:49.194215059 CET49493445192.168.2.2271.83.121.60
                                        Mar 28, 2025 22:13:49.225405931 CET49494445192.168.2.2251.18.108.58
                                        Mar 28, 2025 22:13:49.365928888 CET49498445192.168.2.2251.90.227.172
                                        Mar 28, 2025 22:13:49.413614035 CET49499445192.168.2.22101.110.219.96
                                        Mar 28, 2025 22:13:49.599847078 CET49503445192.168.2.2263.94.226.140
                                        Mar 28, 2025 22:13:49.646697044 CET49504445192.168.2.228.71.91.91
                                        Mar 28, 2025 22:13:49.833899975 CET49506445192.168.2.22167.189.200.101
                                        Mar 28, 2025 22:13:49.960014105 CET49507445192.168.2.22212.44.72.209
                                        Mar 28, 2025 22:13:50.028090954 CET49509445192.168.2.22183.149.227.148
                                        Mar 28, 2025 22:13:50.068206072 CET49510445192.168.2.22193.140.205.131
                                        Mar 28, 2025 22:13:50.148314953 CET49511445192.168.2.22193.57.176.125
                                        Mar 28, 2025 22:13:50.257467985 CET49514445192.168.2.2268.154.153.234
                                        Mar 28, 2025 22:13:50.317810059 CET49516445192.168.2.2216.251.104.223
                                        Mar 28, 2025 22:13:50.352611065 CET49517445192.168.2.22116.151.102.168
                                        Mar 28, 2025 22:13:50.489144087 CET49521445192.168.2.222.186.65.81
                                        Mar 28, 2025 22:13:50.536037922 CET49522445192.168.2.2236.74.206.57
                                        Mar 28, 2025 22:13:50.723254919 CET49526445192.168.2.22164.61.205.169
                                        Mar 28, 2025 22:13:50.769944906 CET49527445192.168.2.22198.172.240.205
                                        Mar 28, 2025 22:13:50.957025051 CET49529445192.168.2.2293.12.253.31
                                        Mar 28, 2025 22:13:51.081834078 CET49531445192.168.2.2219.29.137.244
                                        Mar 28, 2025 22:13:51.144167900 CET49532445192.168.2.22139.189.11.160
                                        Mar 28, 2025 22:13:51.191212893 CET49533445192.168.2.2282.93.181.178
                                        Mar 28, 2025 22:13:51.269089937 CET49534445192.168.2.2213.238.197.114
                                        Mar 28, 2025 22:13:51.378145933 CET49537445192.168.2.2284.172.176.246
                                        Mar 28, 2025 22:13:51.440654039 CET49539445192.168.2.22179.179.108.29
                                        Mar 28, 2025 22:13:51.471824884 CET49540445192.168.2.22182.213.185.55
                                        Mar 28, 2025 22:13:51.612433910 CET49544445192.168.2.2282.141.231.90
                                        Mar 28, 2025 22:13:51.659259081 CET49545445192.168.2.2241.94.210.46
                                        Mar 28, 2025 22:13:51.846312046 CET49549445192.168.2.2299.174.244.233
                                        Mar 28, 2025 22:13:52.033839941 CET49552445192.168.2.22186.180.179.65
                                        Mar 28, 2025 22:13:52.080276012 CET49554445192.168.2.2254.31.142.49
                                        Mar 28, 2025 22:13:52.205276966 CET49555445192.168.2.2258.102.174.6
                                        Mar 28, 2025 22:13:52.267576933 CET49556445192.168.2.22124.139.246.184
                                        Mar 28, 2025 22:13:52.314368010 CET49557445192.168.2.22218.64.104.126
                                        Mar 28, 2025 22:13:52.392319918 CET49559445192.168.2.22134.160.150.158
                                        Mar 28, 2025 22:13:52.501679897 CET49562445192.168.2.22132.221.185.37
                                        Mar 28, 2025 22:13:52.566391945 CET49564445192.168.2.22186.221.76.216
                                        Mar 28, 2025 22:13:52.595077038 CET49566445192.168.2.2288.143.91.35
                                        Mar 28, 2025 22:13:52.735485077 CET49568445192.168.2.2216.116.78.208
                                        Mar 28, 2025 22:13:52.788114071 CET49569445192.168.2.22162.251.130.244
                                        Mar 28, 2025 22:13:52.971431971 CET49573445192.168.2.227.6.97.154
                                        Mar 28, 2025 22:13:53.016390085 CET49574445192.168.2.2298.233.164.168
                                        Mar 28, 2025 22:13:53.162344933 CET49577445192.168.2.2278.11.62.65
                                        Mar 28, 2025 22:13:53.203995943 CET49578445192.168.2.2211.164.73.11
                                        Mar 28, 2025 22:13:53.369350910 CET49579445192.168.2.2232.158.251.29
                                        Mar 28, 2025 22:13:53.390619040 CET49581445192.168.2.22185.168.65.222
                                        Mar 28, 2025 22:13:53.437482119 CET49583445192.168.2.2283.218.187.193
                                        Mar 28, 2025 22:13:53.515522957 CET49584445192.168.2.22211.65.232.156
                                        Mar 28, 2025 22:13:53.624593973 CET49585445192.168.2.22136.123.114.166
                                        Mar 28, 2025 22:13:53.687119961 CET49586445192.168.2.22204.133.149.2
                                        Mar 28, 2025 22:13:53.718234062 CET49587445192.168.2.22174.29.217.201
                                        Mar 28, 2025 22:13:53.858628035 CET49588445192.168.2.2267.131.5.11
                                        Mar 28, 2025 22:13:53.905594110 CET49589445192.168.2.2242.77.207.228
                                        Mar 28, 2025 22:13:54.046173096 CET49590445192.168.2.22100.102.173.178
                                        Mar 28, 2025 22:13:54.092794895 CET49591445192.168.2.22214.58.9.29
                                        Mar 28, 2025 22:13:54.139468908 CET49592445192.168.2.22181.162.25.84
                                        Mar 28, 2025 22:13:54.279815912 CET49593445192.168.2.22141.136.94.45
                                        Mar 28, 2025 22:13:54.326674938 CET49594445192.168.2.22121.63.211.142
                                        Mar 28, 2025 22:13:54.483028889 CET49595445192.168.2.22130.73.209.40
                                        Mar 28, 2025 22:13:54.522900105 CET49596445192.168.2.228.201.179.173
                                        Mar 28, 2025 22:13:54.565586090 CET49597445192.168.2.22180.62.33.214
                                        Mar 28, 2025 22:13:54.638614893 CET49598445192.168.2.2240.250.238.166
                                        Mar 28, 2025 22:13:54.748037100 CET49599445192.168.2.2216.137.24.138
                                        Mar 28, 2025 22:13:54.810631990 CET49600445192.168.2.2213.130.184.21
                                        Mar 28, 2025 22:13:54.841661930 CET49601445192.168.2.2241.195.14.54
                                        Mar 28, 2025 22:13:54.984015942 CET49602445192.168.2.2218.106.91.72
                                        Mar 28, 2025 22:13:55.028920889 CET49603445192.168.2.2250.4.175.155
                                        Mar 28, 2025 22:13:55.169018984 CET49604445192.168.2.22191.190.41.37
                                        Mar 28, 2025 22:13:55.215787888 CET49605445192.168.2.22102.113.230.17
                                        Mar 28, 2025 22:13:55.262608051 CET49606445192.168.2.22221.153.135.51
                                        Mar 28, 2025 22:13:55.403026104 CET49607445192.168.2.226.23.58.202
                                        Mar 28, 2025 22:13:55.449784040 CET49608445192.168.2.2261.0.40.163
                                        Mar 28, 2025 22:13:55.605910063 CET49609445192.168.2.2258.254.36.48
                                        Mar 28, 2025 22:13:55.636991024 CET49610445192.168.2.22219.253.192.186
                                        Mar 28, 2025 22:13:55.683871984 CET49611445192.168.2.22138.237.254.188
                                        Mar 28, 2025 22:13:55.762020111 CET49612445192.168.2.2290.235.143.136
                                        Mar 28, 2025 22:13:55.871249914 CET49613445192.168.2.22110.151.72.78
                                        Mar 28, 2025 22:13:55.933875084 CET49614445192.168.2.22122.155.112.79
                                        Mar 28, 2025 22:13:55.964827061 CET49615445192.168.2.2219.208.149.37
                                        Mar 28, 2025 22:13:56.058657885 CET49616445192.168.2.22147.23.59.218
                                        Mar 28, 2025 22:13:56.104964018 CET49617445192.168.2.22214.41.214.9
                                        Mar 28, 2025 22:13:56.151983976 CET49618445192.168.2.2246.233.70.54
                                        Mar 28, 2025 22:13:56.292268991 CET49619445192.168.2.22192.102.190.157
                                        Mar 28, 2025 22:13:56.339226961 CET49620445192.168.2.22104.162.131.240
                                        Mar 28, 2025 22:13:56.386023045 CET49621445192.168.2.2243.40.212.164
                                        Mar 28, 2025 22:13:56.526415110 CET49622445192.168.2.2299.184.92.83
                                        Mar 28, 2025 22:13:56.573026896 CET49623445192.168.2.22191.38.220.79
                                        Mar 28, 2025 22:13:56.729121923 CET49624445192.168.2.22139.16.199.207
                                        Mar 28, 2025 22:13:56.760201931 CET49625445192.168.2.22107.20.195.27
                                        Mar 28, 2025 22:13:56.807054043 CET49626445192.168.2.2289.193.167.201
                                        Mar 28, 2025 22:13:56.885080099 CET49627445192.168.2.2255.155.99.34
                                        Mar 28, 2025 22:13:56.994226933 CET49628445192.168.2.22217.149.225.63
                                        Mar 28, 2025 22:13:57.056763887 CET49629445192.168.2.22110.56.93.122
                                        Mar 28, 2025 22:13:57.088026047 CET49630445192.168.2.2291.42.124.173
                                        Mar 28, 2025 22:13:57.181493998 CET49631445192.168.2.22142.149.151.128
                                        Mar 28, 2025 22:13:57.228369951 CET49632445192.168.2.2215.81.151.12
                                        Mar 28, 2025 22:13:57.415407896 CET49634445192.168.2.22172.248.128.9
                                        Mar 28, 2025 22:13:57.462840080 CET49635445192.168.2.2256.37.34.1
                                        Mar 28, 2025 22:13:57.509145975 CET49636445192.168.2.22148.80.94.23
                                        Mar 28, 2025 22:13:57.649411917 CET49637445192.168.2.2264.184.145.108
                                        Mar 28, 2025 22:13:57.696476936 CET49638445192.168.2.22103.9.198.209
                                        Mar 28, 2025 22:13:57.874407053 CET49639445192.168.2.2252.146.43.194
                                        Mar 28, 2025 22:13:57.883416891 CET49640445192.168.2.22101.131.133.124
                                        Mar 28, 2025 22:13:57.932275057 CET49641445192.168.2.227.201.98.157
                                        Mar 28, 2025 22:13:58.009708881 CET49642445192.168.2.22137.178.21.76
                                        Mar 28, 2025 22:13:58.071898937 CET49643445192.168.2.22123.24.167.14
                                        Mar 28, 2025 22:13:58.117700100 CET49644445192.168.2.2251.160.249.190
                                        Mar 28, 2025 22:13:58.179950953 CET49645445192.168.2.2259.52.193.102
                                        Mar 28, 2025 22:13:58.213284016 CET49646445192.168.2.22172.31.215.203
                                        Mar 28, 2025 22:13:58.307979107 CET49647445192.168.2.22175.210.209.52
                                        Mar 28, 2025 22:13:58.353734970 CET49648445192.168.2.2244.57.91.176
                                        Mar 28, 2025 22:13:58.399719000 CET49649445192.168.2.22170.91.159.85
                                        Mar 28, 2025 22:13:58.554502964 CET49650445192.168.2.2265.243.62.49
                                        Mar 28, 2025 22:13:58.585500956 CET49651445192.168.2.22136.72.77.194
                                        Mar 28, 2025 22:13:58.632281065 CET49652445192.168.2.2251.15.138.20
                                        Mar 28, 2025 22:13:58.772965908 CET49653445192.168.2.22132.52.241.92
                                        Mar 28, 2025 22:13:58.819442034 CET49654445192.168.2.22184.252.102.107
                                        Mar 28, 2025 22:13:58.991123915 CET49655445192.168.2.22188.223.105.34
                                        Mar 28, 2025 22:13:59.006740093 CET49656445192.168.2.22135.119.166.112
                                        Mar 28, 2025 22:13:59.053524017 CET49657445192.168.2.22204.101.164.38
                                        Mar 28, 2025 22:13:59.131546021 CET49658445192.168.2.22215.223.189.242
                                        Mar 28, 2025 22:13:59.193906069 CET49659445192.168.2.22200.221.215.52
                                        Mar 28, 2025 22:13:59.240639925 CET49660445192.168.2.22101.231.136.50
                                        Mar 28, 2025 22:13:59.303147078 CET49661445192.168.2.2269.15.235.157
                                        Mar 28, 2025 22:13:59.334353924 CET49662445192.168.2.22206.199.118.37
                                        Mar 28, 2025 22:13:59.427892923 CET49663445192.168.2.22134.165.62.75
                                        Mar 28, 2025 22:13:59.474589109 CET49664445192.168.2.2267.90.159.8
                                        Mar 28, 2025 22:13:59.521841049 CET49665445192.168.2.22138.167.78.159
                                        Mar 28, 2025 22:13:59.677762985 CET49666445192.168.2.22113.68.63.111
                                        Mar 28, 2025 22:13:59.708920956 CET49667445192.168.2.2239.218.87.14
                                        Mar 28, 2025 22:13:59.755542994 CET49668445192.168.2.22128.122.125.160
                                        Mar 28, 2025 22:13:59.895787954 CET49669445192.168.2.22157.80.175.69
                                        Mar 28, 2025 22:13:59.942694902 CET49670445192.168.2.22168.116.240.71
                                        Mar 28, 2025 22:14:00.083394051 CET49671445192.168.2.22105.155.64.121
                                        Mar 28, 2025 22:14:00.130033016 CET49672445192.168.2.2270.126.197.199
                                        Mar 28, 2025 22:14:00.142781973 CET49673445192.168.2.22207.142.99.93
                                        Mar 28, 2025 22:14:00.176738977 CET49674445192.168.2.22203.251.211.135
                                        Mar 28, 2025 22:14:00.270360947 CET49675445192.168.2.2253.86.52.241
                                        Mar 28, 2025 22:14:00.317291975 CET49676445192.168.2.2239.143.132.2
                                        Mar 28, 2025 22:14:00.364094019 CET49677445192.168.2.22102.10.60.172
                                        Mar 28, 2025 22:14:00.426414013 CET49678445192.168.2.2214.65.166.75
                                        Mar 28, 2025 22:14:00.457520008 CET49679445192.168.2.22186.199.106.217
                                        Mar 28, 2025 22:14:00.551045895 CET49680445192.168.2.22134.104.202.207
                                        Mar 28, 2025 22:14:00.598093033 CET49681445192.168.2.2228.189.233.238
                                        Mar 28, 2025 22:14:00.645018101 CET49682445192.168.2.22111.172.226.171
                                        Mar 28, 2025 22:14:00.800992966 CET49683445192.168.2.2283.222.160.55
                                        Mar 28, 2025 22:14:00.839031935 CET49684445192.168.2.22118.227.38.237
                                        Mar 28, 2025 22:14:00.879075050 CET49685445192.168.2.2280.2.190.238
                                        Mar 28, 2025 22:14:01.019063950 CET49686445192.168.2.22142.127.200.55
                                        Mar 28, 2025 22:14:01.065855980 CET49687445192.168.2.22119.166.214.194
                                        Mar 28, 2025 22:14:01.206253052 CET49688445192.168.2.2267.27.114.56
                                        Mar 28, 2025 22:14:01.253233910 CET49690445192.168.2.2229.241.159.3
                                        Mar 28, 2025 22:14:01.253257990 CET49689445192.168.2.22144.153.72.99
                                        Mar 28, 2025 22:14:01.300101995 CET49691445192.168.2.22119.188.114.169
                                        Mar 28, 2025 22:14:01.393846989 CET49692445192.168.2.22111.23.77.181
                                        Mar 28, 2025 22:14:01.440413952 CET49693445192.168.2.2284.213.184.157
                                        Mar 28, 2025 22:14:01.487163067 CET49694445192.168.2.2226.128.52.149
                                        Mar 28, 2025 22:14:01.550029993 CET49695445192.168.2.2247.101.231.189
                                        Mar 28, 2025 22:14:01.580656052 CET49696445192.168.2.222.186.251.13
                                        Mar 28, 2025 22:14:01.674597025 CET49697445192.168.2.22170.238.136.160
                                        Mar 28, 2025 22:14:01.721375942 CET49698445192.168.2.22219.252.100.94
                                        Mar 28, 2025 22:14:01.768142939 CET49699445192.168.2.22107.184.141.204
                                        Mar 28, 2025 22:14:01.924108028 CET49700445192.168.2.2251.132.213.203
                                        Mar 28, 2025 22:14:01.955028057 CET49701445192.168.2.22183.184.185.12
                                        Mar 28, 2025 22:14:02.002082109 CET49702445192.168.2.22143.63.72.228
                                        Mar 28, 2025 22:14:02.096129894 CET49703445192.168.2.22157.190.27.125
                                        Mar 28, 2025 22:14:02.142443895 CET49704445192.168.2.2291.54.57.35
                                        Mar 28, 2025 22:14:02.189491034 CET49705445192.168.2.22179.1.182.81
                                        Mar 28, 2025 22:14:02.329437017 CET49706445192.168.2.22118.112.108.157
                                        Mar 28, 2025 22:14:02.376250029 CET49707445192.168.2.227.100.71.236
                                        Mar 28, 2025 22:14:02.376549006 CET49708445192.168.2.22193.212.69.125
                                        Mar 28, 2025 22:14:02.423078060 CET49709445192.168.2.22139.224.234.12
                                        Mar 28, 2025 22:14:02.518691063 CET49710445192.168.2.22111.163.210.91
                                        Mar 28, 2025 22:14:02.564425945 CET49711445192.168.2.22165.14.229.233
                                        Mar 28, 2025 22:14:02.610213041 CET49712445192.168.2.22190.55.60.36
                                        Mar 28, 2025 22:14:02.672632933 CET49713445192.168.2.2263.22.12.114
                                        Mar 28, 2025 22:14:02.703826904 CET49714445192.168.2.22120.220.204.128
                                        Mar 28, 2025 22:14:02.844460011 CET49715445192.168.2.22163.21.38.223
                                        Mar 28, 2025 22:14:02.844542027 CET49716445192.168.2.2263.66.14.81
                                        Mar 28, 2025 22:14:02.891247034 CET49717445192.168.2.22185.121.158.241
                                        Mar 28, 2025 22:14:03.047060966 CET49718445192.168.2.22121.227.60.152
                                        Mar 28, 2025 22:14:03.078248978 CET49719445192.168.2.22105.188.18.126
                                        Mar 28, 2025 22:14:03.130176067 CET49720445192.168.2.2217.11.229.29
                                        Mar 28, 2025 22:14:03.221754074 CET49721445192.168.2.22119.227.153.127
                                        Mar 28, 2025 22:14:03.265835047 CET49722445192.168.2.2281.112.88.240
                                        Mar 28, 2025 22:14:03.313607931 CET49723445192.168.2.22151.239.25.241
                                        Mar 28, 2025 22:14:03.452584982 CET49724445192.168.2.2232.19.99.89
                                        Mar 28, 2025 22:14:03.499583006 CET49725445192.168.2.22215.131.137.201
                                        Mar 28, 2025 22:14:03.499583006 CET49726445192.168.2.22117.74.187.198
                                        Mar 28, 2025 22:14:03.546262980 CET49727445192.168.2.2279.218.7.244
                                        Mar 28, 2025 22:14:03.640002012 CET49728445192.168.2.22179.85.90.114
                                        Mar 28, 2025 22:14:03.687127113 CET49729445192.168.2.2258.190.51.61
                                        Mar 28, 2025 22:14:03.733638048 CET49730445192.168.2.22124.204.172.161
                                        Mar 28, 2025 22:14:03.796109915 CET49731445192.168.2.22140.117.16.146
                                        Mar 28, 2025 22:14:03.827327967 CET49732445192.168.2.225.107.65.7
                                        Mar 28, 2025 22:14:03.967469931 CET49733445192.168.2.22177.62.190.125
                                        Mar 28, 2025 22:14:03.967637062 CET49734445192.168.2.2277.37.174.184
                                        Mar 28, 2025 22:14:03.967698097 CET49735445192.168.2.22211.101.65.97
                                        Mar 28, 2025 22:14:04.014791965 CET49736445192.168.2.22198.55.131.227
                                        Mar 28, 2025 22:14:04.170448065 CET49737445192.168.2.22121.232.66.202
                                        Mar 28, 2025 22:14:04.201523066 CET49738445192.168.2.2255.20.154.205
                                        Mar 28, 2025 22:14:04.248487949 CET49739445192.168.2.22195.19.209.153
                                        Mar 28, 2025 22:14:04.342057943 CET49740445192.168.2.2256.184.149.100
                                        Mar 28, 2025 22:14:04.388911963 CET49741445192.168.2.2256.0.236.94
                                        Mar 28, 2025 22:14:04.435477972 CET49742445192.168.2.22116.212.172.72
                                        Mar 28, 2025 22:14:04.576191902 CET49743445192.168.2.22180.97.207.116
                                        Mar 28, 2025 22:14:04.622618914 CET49744445192.168.2.2230.65.112.179
                                        Mar 28, 2025 22:14:04.631742954 CET49745445192.168.2.2294.79.216.186
                                        Mar 28, 2025 22:14:04.669892073 CET49746445192.168.2.2213.187.254.60
                                        Mar 28, 2025 22:14:04.778687000 CET49747445192.168.2.222.240.28.40
                                        Mar 28, 2025 22:14:04.810024977 CET49748445192.168.2.2270.112.22.118
                                        Mar 28, 2025 22:14:04.856762886 CET49749445192.168.2.2260.216.202.195
                                        Mar 28, 2025 22:14:04.919228077 CET49750445192.168.2.22119.104.89.81
                                        Mar 28, 2025 22:14:04.950361013 CET49751445192.168.2.2211.146.114.174
                                        Mar 28, 2025 22:14:05.090636015 CET49752445192.168.2.22123.213.178.25
                                        Mar 28, 2025 22:14:05.090723038 CET49753445192.168.2.2264.151.149.57
                                        Mar 28, 2025 22:14:05.090729952 CET49754445192.168.2.22209.126.172.117
                                        Mar 28, 2025 22:14:05.137893915 CET49755445192.168.2.2276.26.12.61
                                        Mar 28, 2025 22:14:05.293622971 CET49756445192.168.2.2270.175.152.137
                                        Mar 28, 2025 22:14:05.324640989 CET49757445192.168.2.22118.199.90.96
                                        Mar 28, 2025 22:14:05.371460915 CET49758445192.168.2.2296.221.221.195
                                        Mar 28, 2025 22:14:05.465092897 CET49759445192.168.2.22161.101.6.20
                                        Mar 28, 2025 22:14:05.511826992 CET49760445192.168.2.2254.116.157.253
                                        Mar 28, 2025 22:14:05.558607101 CET49761445192.168.2.2264.56.188.130
                                        Mar 28, 2025 22:14:05.699197054 CET49762445192.168.2.224.211.252.173
                                        Mar 28, 2025 22:14:05.745925903 CET49764445192.168.2.22107.97.18.21
                                        Mar 28, 2025 22:14:05.745938063 CET49765445192.168.2.2216.66.97.113
                                        Mar 28, 2025 22:14:05.792803049 CET49766445192.168.2.2286.33.109.167
                                        Mar 28, 2025 22:14:05.902098894 CET49767445192.168.2.22148.244.147.249
                                        Mar 28, 2025 22:14:05.933424950 CET49768445192.168.2.22196.169.51.8
                                        Mar 28, 2025 22:14:05.979998112 CET49769445192.168.2.22217.197.182.142
                                        Mar 28, 2025 22:14:06.042399883 CET49770445192.168.2.2286.93.45.86
                                        Mar 28, 2025 22:14:06.073699951 CET49771445192.168.2.2261.166.54.193
                                        Mar 28, 2025 22:14:06.213824987 CET49772445192.168.2.2216.167.124.252
                                        Mar 28, 2025 22:14:06.213892937 CET49773445192.168.2.22173.23.1.136
                                        Mar 28, 2025 22:14:06.213951111 CET49774445192.168.2.2272.73.209.74
                                        Mar 28, 2025 22:14:06.260663033 CET49775445192.168.2.225.20.72.217
                                        Mar 28, 2025 22:14:06.416676044 CET49776445192.168.2.22214.73.165.190
                                        Mar 28, 2025 22:14:06.447959900 CET49777445192.168.2.2246.2.124.48
                                        Mar 28, 2025 22:14:06.494719028 CET49778445192.168.2.22156.170.70.174
                                        Mar 28, 2025 22:14:06.588432074 CET49779445192.168.2.22144.229.123.52
                                        Mar 28, 2025 22:14:06.635065079 CET49780445192.168.2.2210.152.159.39
                                        Mar 28, 2025 22:14:06.688627958 CET49781445192.168.2.2289.171.168.190
                                        Mar 28, 2025 22:14:06.822247028 CET49782445192.168.2.2247.241.90.251
                                        Mar 28, 2025 22:14:06.837806940 CET49783445192.168.2.22214.171.118.121
                                        Mar 28, 2025 22:14:06.869122028 CET49784445192.168.2.22213.191.230.174
                                        Mar 28, 2025 22:14:06.869170904 CET49785445192.168.2.22216.246.125.169
                                        Mar 28, 2025 22:14:06.916043043 CET49786445192.168.2.22121.12.192.94
                                        Mar 28, 2025 22:14:07.029894114 CET49787445192.168.2.2283.18.190.61
                                        Mar 28, 2025 22:14:07.056329012 CET49788445192.168.2.22217.115.68.91
                                        Mar 28, 2025 22:14:07.103013039 CET49789445192.168.2.22175.91.47.217
                                        Mar 28, 2025 22:14:07.165540934 CET49790445192.168.2.22190.14.81.189
                                        Mar 28, 2025 22:14:07.197077036 CET49791445192.168.2.22104.251.109.116
                                        Mar 28, 2025 22:14:07.337059975 CET49793445192.168.2.2217.67.106.185
                                        Mar 28, 2025 22:14:07.337116003 CET49794445192.168.2.22149.199.203.42
                                        Mar 28, 2025 22:14:07.337158918 CET49792445192.168.2.22170.11.234.127
                                        Mar 28, 2025 22:14:07.353235960 CET49795445192.168.2.2214.240.235.145
                                        Mar 28, 2025 22:14:07.384001970 CET49796445192.168.2.22174.214.185.202
                                        Mar 28, 2025 22:14:07.539958954 CET49797445192.168.2.22104.2.193.15
                                        Mar 28, 2025 22:14:07.571019888 CET49798445192.168.2.2225.159.164.56
                                        Mar 28, 2025 22:14:07.617892981 CET49799445192.168.2.221.198.205.72
                                        Mar 28, 2025 22:14:07.719489098 CET49800445192.168.2.22142.174.236.144
                                        Mar 28, 2025 22:14:07.758339882 CET49801445192.168.2.22110.67.233.108
                                        Mar 28, 2025 22:14:07.805211067 CET49802445192.168.2.2278.95.54.178
                                        Mar 28, 2025 22:14:07.945447922 CET49803445192.168.2.2262.245.232.254
                                        Mar 28, 2025 22:14:07.961020947 CET49804445192.168.2.22133.182.135.86
                                        Mar 28, 2025 22:14:07.992269039 CET49806445192.168.2.22169.217.120.143
                                        Mar 28, 2025 22:14:07.992405891 CET49805445192.168.2.22169.185.200.71
                                        Mar 28, 2025 22:14:08.039211988 CET49807445192.168.2.2241.170.97.86
                                        Mar 28, 2025 22:14:08.148825884 CET49808445192.168.2.2225.143.240.232
                                        Mar 28, 2025 22:14:08.179771900 CET49809445192.168.2.22148.223.9.136
                                        Mar 28, 2025 22:14:08.226232052 CET49810445192.168.2.2216.111.134.13
                                        Mar 28, 2025 22:14:08.288717031 CET49811445192.168.2.22217.206.25.159
                                        Mar 28, 2025 22:14:08.319868088 CET49812445192.168.2.22205.25.23.33
                                        Mar 28, 2025 22:14:08.460247040 CET49813445192.168.2.2264.124.151.170
                                        Mar 28, 2025 22:14:08.460329056 CET49815445192.168.2.22199.117.68.165
                                        Mar 28, 2025 22:14:08.464051962 CET49814445192.168.2.2237.174.65.106
                                        Mar 28, 2025 22:14:08.475855112 CET49816445192.168.2.22163.239.151.208
                                        Mar 28, 2025 22:14:08.507189035 CET49817445192.168.2.2238.203.154.71
                                        Mar 28, 2025 22:14:08.663135052 CET49818445192.168.2.228.120.186.134
                                        Mar 28, 2025 22:14:08.694230080 CET49819445192.168.2.2299.156.81.96
                                        Mar 28, 2025 22:14:08.746602058 CET49820445192.168.2.2298.232.68.241
                                        Mar 28, 2025 22:14:08.834692955 CET49821445192.168.2.22143.250.66.220
                                        Mar 28, 2025 22:14:08.881513119 CET49822445192.168.2.22124.161.37.82
                                        Mar 28, 2025 22:14:08.881869078 CET49823445192.168.2.22223.81.101.154
                                        Mar 28, 2025 22:14:08.928674936 CET49824445192.168.2.2279.83.39.175
                                        Mar 28, 2025 22:14:09.068797112 CET49825445192.168.2.22143.71.90.63
                                        Mar 28, 2025 22:14:09.084403992 CET49826445192.168.2.22139.182.15.135
                                        Mar 28, 2025 22:14:09.115492105 CET49827445192.168.2.22207.172.167.173
                                        Mar 28, 2025 22:14:09.115556002 CET49828445192.168.2.22109.223.95.158
                                        Mar 28, 2025 22:14:09.162312031 CET49829445192.168.2.22143.58.187.188
                                        Mar 28, 2025 22:14:09.271889925 CET49830445192.168.2.22151.64.206.64
                                        Mar 28, 2025 22:14:09.302819967 CET49831445192.168.2.2237.189.33.17
                                        Mar 28, 2025 22:14:09.349543095 CET49832445192.168.2.22208.201.59.228
                                        Mar 28, 2025 22:14:09.412558079 CET49833445192.168.2.22200.122.88.126
                                        Mar 28, 2025 22:14:09.443161964 CET49834445192.168.2.22174.122.19.31
                                        Mar 28, 2025 22:14:09.583533049 CET49835445192.168.2.22115.104.134.225
                                        Mar 28, 2025 22:14:09.583539009 CET49836445192.168.2.22150.22.40.160
                                        Mar 28, 2025 22:14:09.583833933 CET49837445192.168.2.2228.146.217.83
                                        Mar 28, 2025 22:14:09.599154949 CET49838445192.168.2.2233.5.91.95
                                        Mar 28, 2025 22:14:09.630285978 CET49839445192.168.2.2298.180.88.78
                                        Mar 28, 2025 22:14:09.786250114 CET49840445192.168.2.2220.58.226.233
                                        Mar 28, 2025 22:14:09.817466974 CET49841445192.168.2.22208.211.201.31
                                        Mar 28, 2025 22:14:09.864398003 CET49842445192.168.2.2231.164.110.242
                                        Mar 28, 2025 22:14:09.958070040 CET49843445192.168.2.2238.36.212.231
                                        Mar 28, 2025 22:14:10.004738092 CET49844445192.168.2.2250.146.154.127
                                        Mar 28, 2025 22:14:10.004854918 CET49845445192.168.2.22107.173.203.249
                                        Mar 28, 2025 22:14:10.051721096 CET49846445192.168.2.22144.198.56.8
                                        Mar 28, 2025 22:14:10.191853046 CET49847445192.168.2.22170.71.49.111
                                        Mar 28, 2025 22:14:10.207432985 CET49848445192.168.2.2227.253.113.223
                                        Mar 28, 2025 22:14:10.238637924 CET49849445192.168.2.2229.226.23.37
                                        Mar 28, 2025 22:14:10.238858938 CET49850445192.168.2.2250.121.233.130
                                        Mar 28, 2025 22:14:10.285561085 CET49851445192.168.2.22125.67.153.152
                                        Mar 28, 2025 22:14:10.301215887 CET49852445192.168.2.22196.72.69.115
                                        Mar 28, 2025 22:14:10.394664049 CET49853445192.168.2.22151.214.160.70
                                        Mar 28, 2025 22:14:10.426268101 CET49854445192.168.2.22128.229.192.41
                                        Mar 28, 2025 22:14:10.472646952 CET49855445192.168.2.22175.10.66.25
                                        Mar 28, 2025 22:14:10.535212994 CET49856445192.168.2.22186.154.33.206
                                        Mar 28, 2025 22:14:10.566225052 CET49857445192.168.2.222.77.212.5
                                        Mar 28, 2025 22:14:10.706703901 CET49858445192.168.2.2270.35.115.54
                                        Mar 28, 2025 22:14:10.706778049 CET49859445192.168.2.2299.8.119.98
                                        Mar 28, 2025 22:14:10.706945896 CET49860445192.168.2.22111.12.0.105
                                        Mar 28, 2025 22:14:10.722294092 CET49861445192.168.2.22137.154.207.100
                                        Mar 28, 2025 22:14:10.753439903 CET49862445192.168.2.2248.187.158.110
                                        Mar 28, 2025 22:14:10.909686089 CET49863445192.168.2.2266.36.157.4
                                        Mar 28, 2025 22:14:10.941123962 CET49864445192.168.2.2263.233.17.224
                                        Mar 28, 2025 22:14:10.987464905 CET49865445192.168.2.22108.213.84.209
                                        Mar 28, 2025 22:14:11.081010103 CET49866445192.168.2.22117.188.66.251
                                        Mar 28, 2025 22:14:11.127820015 CET49867445192.168.2.228.135.101.125
                                        Mar 28, 2025 22:14:11.127912998 CET49868445192.168.2.22186.234.182.151
                                        Mar 28, 2025 22:14:11.174618006 CET49869445192.168.2.22189.90.10.253
                                        Mar 28, 2025 22:14:11.315128088 CET49870445192.168.2.22196.197.155.250
                                        Mar 28, 2025 22:14:11.330611944 CET49871445192.168.2.22207.153.60.229
                                        Mar 28, 2025 22:14:11.361982107 CET49872445192.168.2.226.235.50.204
                                        Mar 28, 2025 22:14:11.362042904 CET49873445192.168.2.22162.105.4.70
                                        Mar 28, 2025 22:14:11.408696890 CET49874445192.168.2.22207.6.157.184
                                        Mar 28, 2025 22:14:11.424288034 CET49875445192.168.2.2245.232.151.42
                                        Mar 28, 2025 22:14:11.533500910 CET49876445192.168.2.2235.199.19.155
                                        Mar 28, 2025 22:14:11.549417973 CET49877445192.168.2.2263.212.207.142
                                        Mar 28, 2025 22:14:11.595825911 CET49878445192.168.2.2274.205.177.150
                                        Mar 28, 2025 22:14:11.627569914 CET49879445192.168.2.2292.254.221.45
                                        Mar 28, 2025 22:14:11.658437967 CET49880445192.168.2.22120.189.112.216
                                        Mar 28, 2025 22:14:11.689493895 CET49881445192.168.2.22185.40.187.101
                                        Mar 28, 2025 22:14:11.835566998 CET49882445192.168.2.2294.200.152.9
                                        Mar 28, 2025 22:14:11.835656881 CET49883445192.168.2.2275.135.62.95
                                        Mar 28, 2025 22:14:11.835724115 CET49884445192.168.2.22202.53.163.25
                                        Mar 28, 2025 22:14:11.845432997 CET49885445192.168.2.2255.29.17.240
                                        Mar 28, 2025 22:14:11.876828909 CET49886445192.168.2.22212.169.211.10
                                        Mar 28, 2025 22:14:12.032735109 CET49887445192.168.2.2247.11.218.69
                                        Mar 28, 2025 22:14:12.063822031 CET49888445192.168.2.22203.221.145.247
                                        Mar 28, 2025 22:14:12.110816002 CET49889445192.168.2.22147.50.158.238
                                        Mar 28, 2025 22:14:12.204245090 CET49890445192.168.2.2270.219.234.198
                                        Mar 28, 2025 22:14:12.251095057 CET49891445192.168.2.22183.10.186.193
                                        Mar 28, 2025 22:14:12.251281977 CET49892445192.168.2.22211.68.9.101
                                        Mar 28, 2025 22:14:12.297933102 CET49893445192.168.2.22126.87.75.240
                                        Mar 28, 2025 22:14:12.438461065 CET49894445192.168.2.22126.117.108.251
                                        Mar 28, 2025 22:14:12.454204082 CET49895445192.168.2.22215.12.247.67
                                        Mar 28, 2025 22:14:12.485029936 CET49896445192.168.2.2247.207.218.58
                                        Mar 28, 2025 22:14:12.485342026 CET49897445192.168.2.2247.197.102.42
                                        Mar 28, 2025 22:14:12.531908989 CET49898445192.168.2.22156.122.216.14
                                        Mar 28, 2025 22:14:12.547442913 CET49899445192.168.2.22181.230.197.20
                                        Mar 28, 2025 22:14:12.656708002 CET49900445192.168.2.22169.241.72.57
                                        Mar 28, 2025 22:14:12.672358036 CET49901445192.168.2.22124.98.183.174
                                        Mar 28, 2025 22:14:12.719041109 CET49902445192.168.2.22104.112.249.51
                                        Mar 28, 2025 22:14:12.750257969 CET49903445192.168.2.2247.230.199.147
                                        Mar 28, 2025 22:14:12.782010078 CET49904445192.168.2.22117.151.105.176
                                        Mar 28, 2025 22:14:12.812741041 CET49905445192.168.2.2236.90.49.41
                                        Mar 28, 2025 22:14:12.875585079 CET49906445192.168.2.22121.147.206.146
                                        Mar 28, 2025 22:14:12.953075886 CET49907445192.168.2.2286.216.57.180
                                        Mar 28, 2025 22:14:12.953131914 CET49908445192.168.2.22203.97.45.90
                                        Mar 28, 2025 22:14:12.953306913 CET49909445192.168.2.22121.48.7.159
                                        Mar 28, 2025 22:14:12.969079971 CET49910445192.168.2.2266.252.243.52
                                        Mar 28, 2025 22:14:12.999984980 CET49911445192.168.2.2251.197.221.157
                                        Mar 28, 2025 22:14:13.155848980 CET49912445192.168.2.22205.172.91.28
                                        Mar 28, 2025 22:14:13.187201977 CET49913445192.168.2.22145.78.143.197
                                        Mar 28, 2025 22:14:13.234009981 CET49914445192.168.2.2221.85.84.32
                                        Mar 28, 2025 22:14:13.327672005 CET49915445192.168.2.2216.95.233.205
                                        Mar 28, 2025 22:14:13.374372959 CET49916445192.168.2.22156.229.116.250
                                        Mar 28, 2025 22:14:13.374391079 CET49917445192.168.2.2227.144.251.234
                                        Mar 28, 2025 22:14:13.421144962 CET49918445192.168.2.22106.59.165.145
                                        Mar 28, 2025 22:14:13.561511040 CET49919445192.168.2.22165.193.201.120
                                        Mar 28, 2025 22:14:13.577152967 CET49920445192.168.2.22184.74.251.249
                                        Mar 28, 2025 22:14:13.608242035 CET49921445192.168.2.2219.6.74.59
                                        Mar 28, 2025 22:14:13.608392000 CET49922445192.168.2.22116.0.109.188
                                        Mar 28, 2025 22:14:13.655162096 CET49923445192.168.2.2255.7.69.106
                                        Mar 28, 2025 22:14:13.670770884 CET49924445192.168.2.2291.46.31.108
                                        Mar 28, 2025 22:14:13.780277967 CET49925445192.168.2.22118.213.19.178
                                        Mar 28, 2025 22:14:13.795794964 CET49926445192.168.2.2222.48.241.153
                                        Mar 28, 2025 22:14:13.842416048 CET49927445192.168.2.22117.74.54.182
                                        Mar 28, 2025 22:14:13.873544931 CET49928445192.168.2.22135.128.130.175
                                        Mar 28, 2025 22:14:13.904670954 CET49929445192.168.2.22202.112.30.110
                                        Mar 28, 2025 22:14:13.935883999 CET49930445192.168.2.2219.74.183.86
                                        Mar 28, 2025 22:14:13.998367071 CET49931445192.168.2.22184.46.67.170
                                        Mar 28, 2025 22:14:14.029695034 CET49932445192.168.2.2268.245.3.81
                                        Mar 28, 2025 22:14:14.076328039 CET49933445192.168.2.2278.124.58.31
                                        Mar 28, 2025 22:14:14.076425076 CET49934445192.168.2.22209.56.96.12
                                        Mar 28, 2025 22:14:14.076562881 CET49935445192.168.2.2289.13.81.186
                                        Mar 28, 2025 22:14:14.091886044 CET49936445192.168.2.2233.76.80.124
                                        Mar 28, 2025 22:14:14.123327971 CET49937445192.168.2.2262.52.254.240
                                        Mar 28, 2025 22:14:14.279186010 CET49938445192.168.2.22178.164.70.25
                                        Mar 28, 2025 22:14:14.310664892 CET49939445192.168.2.2282.49.48.18
                                        Mar 28, 2025 22:14:14.357240915 CET49940445192.168.2.22156.82.71.114
                                        Mar 28, 2025 22:14:14.450687885 CET49941445192.168.2.2247.243.144.80
                                        Mar 28, 2025 22:14:14.497549057 CET49942445192.168.2.2253.161.138.62
                                        Mar 28, 2025 22:14:14.497616053 CET49943445192.168.2.2218.41.93.69
                                        Mar 28, 2025 22:14:14.544469118 CET49944445192.168.2.22167.75.79.129
                                        Mar 28, 2025 22:14:14.684897900 CET49945445192.168.2.22182.103.143.195
                                        Mar 28, 2025 22:14:14.700339079 CET49946445192.168.2.22170.173.71.170
                                        Mar 28, 2025 22:14:14.731664896 CET49947445192.168.2.2251.81.41.81
                                        Mar 28, 2025 22:14:14.747375011 CET49948445192.168.2.2280.15.211.38
                                        Mar 28, 2025 22:14:14.778465986 CET49949445192.168.2.2245.102.118.15
                                        Mar 28, 2025 22:14:14.793910980 CET49950445192.168.2.22102.179.39.13
                                        Mar 28, 2025 22:14:14.903665066 CET49951445192.168.2.22199.185.175.151
                                        Mar 28, 2025 22:14:14.936167955 CET49952445192.168.2.22219.172.214.53
                                        Mar 28, 2025 22:14:14.965480089 CET49953445192.168.2.22102.80.111.162
                                        Mar 28, 2025 22:14:14.996640921 CET49954445192.168.2.22188.45.176.123
                                        Mar 28, 2025 22:14:15.043612003 CET49955445192.168.2.22159.217.23.174
                                        Mar 28, 2025 22:14:15.059103012 CET49956445192.168.2.2285.139.144.119
                                        Mar 28, 2025 22:14:15.106201887 CET49957445192.168.2.22120.72.76.192
                                        Mar 28, 2025 22:14:15.121486902 CET49958445192.168.2.22191.156.95.212
                                        Mar 28, 2025 22:14:15.152904987 CET49959445192.168.2.22185.239.73.26
                                        Mar 28, 2025 22:14:15.199532032 CET49961445192.168.2.2224.78.127.252
                                        Mar 28, 2025 22:14:15.199594021 CET49960445192.168.2.22182.186.63.165
                                        Mar 28, 2025 22:14:15.199719906 CET49962445192.168.2.22142.180.134.253
                                        Mar 28, 2025 22:14:15.215075016 CET49963445192.168.2.2244.189.41.201
                                        Mar 28, 2025 22:14:15.246630907 CET49964445192.168.2.2298.199.22.36
                                        Mar 28, 2025 22:14:15.402507067 CET49965445192.168.2.22147.125.159.183
                                        Mar 28, 2025 22:14:15.433494091 CET49966445192.168.2.2273.141.5.145
                                        Mar 28, 2025 22:14:15.480456114 CET49967445192.168.2.22216.68.198.77
                                        Mar 28, 2025 22:14:15.575391054 CET49968445192.168.2.22108.235.14.36
                                        Mar 28, 2025 22:14:15.620743036 CET49969445192.168.2.2297.130.9.97
                                        Mar 28, 2025 22:14:15.620755911 CET49970445192.168.2.22123.37.150.103
                                        Mar 28, 2025 22:14:15.667589903 CET49971445192.168.2.22150.245.40.217
                                        Mar 28, 2025 22:14:15.807910919 CET49972445192.168.2.2249.141.6.62
                                        Mar 28, 2025 22:14:15.823569059 CET49973445192.168.2.2241.81.4.138
                                        Mar 28, 2025 22:14:15.854760885 CET49974445192.168.2.22162.126.143.154
                                        Mar 28, 2025 22:14:15.870378971 CET49975445192.168.2.22135.51.182.90
                                        Mar 28, 2025 22:14:15.901473045 CET49976445192.168.2.22155.63.17.25
                                        Mar 28, 2025 22:14:15.917376995 CET49977445192.168.2.2294.153.197.134
                                        Mar 28, 2025 22:14:16.026586056 CET49978445192.168.2.22176.2.111.114
                                        Mar 28, 2025 22:14:16.057627916 CET49979445192.168.2.2285.139.95.208
                                        Mar 28, 2025 22:14:16.088749886 CET49980445192.168.2.22138.15.180.193
                                        Mar 28, 2025 22:14:16.119992971 CET49981445192.168.2.22115.85.31.40
                                        Mar 28, 2025 22:14:16.120702028 CET49982445192.168.2.2243.232.177.51
                                        Mar 28, 2025 22:14:16.167006969 CET49983445192.168.2.2259.161.137.239
                                        Mar 28, 2025 22:14:16.182588100 CET49984445192.168.2.2219.14.252.158
                                        Mar 28, 2025 22:14:16.229212999 CET49985445192.168.2.2266.21.249.237
                                        Mar 28, 2025 22:14:16.244752884 CET49986445192.168.2.22159.195.173.194
                                        Mar 28, 2025 22:14:16.276055098 CET49987445192.168.2.22223.213.88.65
                                        Mar 28, 2025 22:14:16.322721004 CET49988445192.168.2.22189.196.86.55
                                        Mar 28, 2025 22:14:16.322819948 CET49989445192.168.2.2225.91.124.110
                                        Mar 28, 2025 22:14:16.322892904 CET49990445192.168.2.228.148.113.223
                                        Mar 28, 2025 22:14:16.338376999 CET49991445192.168.2.2297.134.103.169
                                        Mar 28, 2025 22:14:16.369601011 CET49992445192.168.2.22152.232.70.182
                                        Mar 28, 2025 22:14:16.525727034 CET49993445192.168.2.2262.115.198.176
                                        Mar 28, 2025 22:14:16.556708097 CET49994445192.168.2.22147.73.77.6
                                        Mar 28, 2025 22:14:16.603621960 CET49995445192.168.2.22115.91.222.31
                                        Mar 28, 2025 22:14:16.697438955 CET49996445192.168.2.22208.205.10.136
                                        Mar 28, 2025 22:14:16.743901014 CET49997445192.168.2.22148.85.210.240
                                        Mar 28, 2025 22:14:16.744113922 CET49998445192.168.2.2231.242.154.11
                                        Mar 28, 2025 22:14:16.790627003 CET49999445192.168.2.2222.27.198.153
                                        Mar 28, 2025 22:14:16.931637049 CET50000445192.168.2.2257.84.125.211
                                        Mar 28, 2025 22:14:16.946640968 CET50001445192.168.2.2227.221.159.0
                                        Mar 28, 2025 22:14:16.979566097 CET50002445192.168.2.22165.161.252.167
                                        Mar 28, 2025 22:14:16.993490934 CET50003445192.168.2.2259.42.240.20
                                        Mar 28, 2025 22:14:17.025176048 CET50004445192.168.2.2221.4.66.204
                                        Mar 28, 2025 22:14:17.040527105 CET50005445192.168.2.22163.106.102.136
                                        Mar 28, 2025 22:14:17.056364059 CET50006445192.168.2.22111.27.199.193
                                        Mar 28, 2025 22:14:17.149513006 CET50007445192.168.2.22135.112.27.192
                                        Mar 28, 2025 22:14:17.180736065 CET50008445192.168.2.2262.245.117.106
                                        Mar 28, 2025 22:14:17.211985111 CET50009445192.168.2.22173.149.187.48
                                        Mar 28, 2025 22:14:17.243052006 CET50010445192.168.2.2282.77.172.47
                                        Mar 28, 2025 22:14:17.243134022 CET50011445192.168.2.2244.71.194.241
                                        Mar 28, 2025 22:14:17.290004969 CET50012445192.168.2.22128.24.67.56
                                        Mar 28, 2025 22:14:17.305712938 CET50013445192.168.2.22213.173.192.103
                                        Mar 28, 2025 22:14:17.352412939 CET50014445192.168.2.22147.246.18.67
                                        Mar 28, 2025 22:14:17.368222952 CET50015445192.168.2.2227.150.86.174
                                        Mar 28, 2025 22:14:17.399180889 CET50016445192.168.2.22137.6.233.187
                                        Mar 28, 2025 22:14:17.446253061 CET50017445192.168.2.22187.94.44.250
                                        Mar 28, 2025 22:14:17.446324110 CET50018445192.168.2.2222.105.130.185
                                        Mar 28, 2025 22:14:17.446387053 CET50019445192.168.2.224.108.224.115
                                        Mar 28, 2025 22:14:17.461577892 CET50020445192.168.2.2278.239.128.159
                                        Mar 28, 2025 22:14:17.493021965 CET50021445192.168.2.2269.179.66.105
                                        Mar 28, 2025 22:14:17.648638010 CET50022445192.168.2.2237.199.205.125
                                        Mar 28, 2025 22:14:17.682518959 CET50023445192.168.2.22135.235.99.201
                                        Mar 28, 2025 22:14:17.726813078 CET50024445192.168.2.2272.218.101.113
                                        Mar 28, 2025 22:14:17.830388069 CET50025445192.168.2.2267.6.62.134
                                        Mar 28, 2025 22:14:17.867150068 CET50026445192.168.2.2238.142.43.146
                                        Mar 28, 2025 22:14:17.867305040 CET50027445192.168.2.2274.249.93.17
                                        Mar 28, 2025 22:14:17.929636002 CET50028445192.168.2.2287.20.15.134
                                        Mar 28, 2025 22:14:17.945380926 CET50029445192.168.2.22189.64.132.78
                                        Mar 28, 2025 22:14:18.064841032 CET50030445192.168.2.22169.172.68.228
                                        Mar 28, 2025 22:14:18.087707043 CET50031445192.168.2.22141.79.202.46
                                        Mar 28, 2025 22:14:18.102304935 CET50032445192.168.2.2236.126.112.180
                                        Mar 28, 2025 22:14:18.132325888 CET50033445192.168.2.22147.87.214.138
                                        Mar 28, 2025 22:14:18.166722059 CET50034445192.168.2.2288.14.141.209
                                        Mar 28, 2025 22:14:18.166919947 CET50035445192.168.2.22214.141.131.249
                                        Mar 28, 2025 22:14:18.180197954 CET50036445192.168.2.22209.226.61.154
                                        Mar 28, 2025 22:14:18.273698092 CET50037445192.168.2.22152.121.8.36
                                        Mar 28, 2025 22:14:18.304059029 CET50038445192.168.2.22121.89.173.141
                                        Mar 28, 2025 22:14:18.345340967 CET50039445192.168.2.22190.5.193.126
                                        Mar 28, 2025 22:14:18.370887041 CET50040445192.168.2.2246.226.114.119
                                        Mar 28, 2025 22:14:18.371005058 CET50041445192.168.2.22185.240.119.118
                                        Mar 28, 2025 22:14:18.413947105 CET50042445192.168.2.22185.165.83.67
                                        Mar 28, 2025 22:14:18.428822041 CET50043445192.168.2.2239.148.76.48
                                        Mar 28, 2025 22:14:18.478379011 CET50044445192.168.2.2221.113.156.36
                                        Mar 28, 2025 22:14:18.491060019 CET50045445192.168.2.22108.107.122.201
                                        Mar 28, 2025 22:14:18.524554968 CET50046445192.168.2.2257.185.196.119
                                        Mar 28, 2025 22:14:18.569066048 CET50047445192.168.2.2297.206.156.183
                                        Mar 28, 2025 22:14:18.569133043 CET50048445192.168.2.2250.76.102.155
                                        Mar 28, 2025 22:14:18.569188118 CET50049445192.168.2.228.228.157.230
                                        Mar 28, 2025 22:14:18.584815979 CET50050445192.168.2.2294.207.174.154
                                        Mar 28, 2025 22:14:18.615973949 CET50051445192.168.2.22137.244.13.17
                                        Mar 28, 2025 22:14:18.772042990 CET50052445192.168.2.2231.207.5.34
                                        Mar 28, 2025 22:14:18.772437096 CET50053445192.168.2.2229.249.198.11
                                        Mar 28, 2025 22:14:18.803181887 CET50054445192.168.2.2287.110.129.189
                                        Mar 28, 2025 22:14:18.849982023 CET50055445192.168.2.22209.100.246.168
                                        Mar 28, 2025 22:14:18.943800926 CET50056445192.168.2.22176.6.215.136
                                        Mar 28, 2025 22:14:18.990472078 CET50057445192.168.2.22200.238.35.241
                                        Mar 28, 2025 22:14:18.990674019 CET50058445192.168.2.22214.151.189.223
                                        Mar 28, 2025 22:14:19.052687883 CET50059445192.168.2.22160.95.26.140
                                        Mar 28, 2025 22:14:19.068344116 CET50060445192.168.2.2272.102.0.146
                                        Mar 28, 2025 22:14:19.177656889 CET50061445192.168.2.2286.11.57.185
                                        Mar 28, 2025 22:14:19.208669901 CET50062445192.168.2.2279.169.84.52
                                        Mar 28, 2025 22:14:19.224334955 CET50063445192.168.2.2281.174.94.152
                                        Mar 28, 2025 22:14:19.255506039 CET50064445192.168.2.22177.175.183.201
                                        Mar 28, 2025 22:14:19.286884069 CET50065445192.168.2.2224.73.81.66
                                        Mar 28, 2025 22:14:19.286890984 CET50066445192.168.2.2273.62.122.29
                                        Mar 28, 2025 22:14:19.302294970 CET50067445192.168.2.22168.114.181.201
                                        Mar 28, 2025 22:14:19.395946980 CET50068445192.168.2.2221.208.212.95
                                        Mar 28, 2025 22:14:19.427258015 CET50069445192.168.2.22219.167.129.166
                                        Mar 28, 2025 22:14:19.458324909 CET50070445192.168.2.2251.4.42.158
                                        Mar 28, 2025 22:14:19.489485025 CET50071445192.168.2.22132.166.66.183
                                        Mar 28, 2025 22:14:19.489563942 CET50072445192.168.2.22111.142.37.135
                                        Mar 28, 2025 22:14:19.536324024 CET50073445192.168.2.2268.149.251.220
                                        Mar 28, 2025 22:14:19.536699057 CET50074445192.168.2.22168.235.124.41
                                        Mar 28, 2025 22:14:19.552109003 CET50075445192.168.2.22172.56.64.223
                                        Mar 28, 2025 22:14:19.598699093 CET50076445192.168.2.22211.150.254.214
                                        Mar 28, 2025 22:14:19.614341974 CET50077445192.168.2.22112.175.145.0
                                        Mar 28, 2025 22:14:19.645431042 CET50078445192.168.2.2217.200.210.30
                                        Mar 28, 2025 22:14:19.692292929 CET50079445192.168.2.22173.87.90.34
                                        Mar 28, 2025 22:14:19.692373037 CET50080445192.168.2.2252.158.59.152
                                        Mar 28, 2025 22:14:19.692374945 CET50081445192.168.2.22131.152.5.181
                                        Mar 28, 2025 22:14:19.707976103 CET50082445192.168.2.22187.239.131.71
                                        Mar 28, 2025 22:14:19.739350080 CET50083445192.168.2.22135.173.63.245
                                        Mar 28, 2025 22:14:19.895212889 CET50084445192.168.2.2286.153.190.190
                                        Mar 28, 2025 22:14:19.895243883 CET50085445192.168.2.22107.232.1.150
                                        Mar 28, 2025 22:14:19.926626921 CET50086445192.168.2.2224.66.252.97
                                        Mar 28, 2025 22:14:19.973377943 CET50087445192.168.2.2246.12.101.175
                                        Mar 28, 2025 22:14:20.066796064 CET50088445192.168.2.22200.134.68.94
                                        Mar 28, 2025 22:14:20.113478899 CET50089445192.168.2.22132.83.64.149
                                        Mar 28, 2025 22:14:20.113575935 CET50090445192.168.2.2227.5.84.185
                                        Mar 28, 2025 22:14:20.175898075 CET50091445192.168.2.22129.97.205.5
                                        Mar 28, 2025 22:14:20.191478014 CET50092445192.168.2.2256.202.114.161
                                        Mar 28, 2025 22:14:20.300762892 CET50094445192.168.2.22131.211.170.64
                                        Mar 28, 2025 22:14:20.332094908 CET50095445192.168.2.22115.53.69.235
                                        Mar 28, 2025 22:14:20.347445011 CET50096445192.168.2.2228.152.28.163
                                        Mar 28, 2025 22:14:20.378726959 CET50097445192.168.2.2244.139.142.117
                                        Mar 28, 2025 22:14:20.410799026 CET50098445192.168.2.2260.10.23.107
                                        Mar 28, 2025 22:14:20.410959005 CET50099445192.168.2.22137.225.75.11
                                        Mar 28, 2025 22:14:20.425657034 CET50100445192.168.2.22200.35.14.250
                                        Mar 28, 2025 22:14:20.519185066 CET50101445192.168.2.2257.231.203.199
                                        Mar 28, 2025 22:14:20.550446033 CET50102445192.168.2.22140.252.245.97
                                        Mar 28, 2025 22:14:20.612684011 CET50104445192.168.2.22219.247.152.139
                                        Mar 28, 2025 22:14:20.612782001 CET50105445192.168.2.2299.17.1.200
                                        Mar 28, 2025 22:14:20.659495115 CET50106445192.168.2.2255.137.194.75
                                        Mar 28, 2025 22:14:20.659699917 CET50107445192.168.2.2234.70.95.120
                                        Mar 28, 2025 22:14:20.675266981 CET50108445192.168.2.22134.45.187.19
                                        Mar 28, 2025 22:14:20.722126961 CET50109445192.168.2.2225.12.36.67
                                        Mar 28, 2025 22:14:20.738653898 CET50110445192.168.2.2230.239.238.164
                                        Mar 28, 2025 22:14:20.768868923 CET50111445192.168.2.22152.87.123.137
                                        Mar 28, 2025 22:14:20.815598965 CET50112445192.168.2.2297.218.59.56
                                        Mar 28, 2025 22:14:20.815814018 CET50113445192.168.2.22178.153.4.50
                                        Mar 28, 2025 22:14:20.815922022 CET50114445192.168.2.2299.55.60.91
                                        Mar 28, 2025 22:14:20.831101894 CET50115445192.168.2.2242.156.186.219
                                        Mar 28, 2025 22:14:20.862420082 CET50116445192.168.2.22221.84.75.128
                                        Mar 28, 2025 22:14:21.018310070 CET50118445192.168.2.22150.24.78.160
                                        Mar 28, 2025 22:14:21.018800020 CET50119445192.168.2.222.142.134.135
                                        Mar 28, 2025 22:14:21.067492008 CET50120445192.168.2.22194.143.116.134
                                        Mar 28, 2025 22:14:21.101151943 CET50121445192.168.2.22141.82.33.28
                                        Mar 28, 2025 22:14:21.240295887 CET50122445192.168.2.2215.120.78.47
                                        Mar 28, 2025 22:14:21.253428936 CET50123445192.168.2.22146.81.53.98
                                        Mar 28, 2025 22:14:21.257559061 CET50124445192.168.2.22157.134.108.216
                                        Mar 28, 2025 22:14:21.299031973 CET50125445192.168.2.22216.18.244.47
                                        Mar 28, 2025 22:14:21.314627886 CET50126445192.168.2.22149.166.222.171
                                        Mar 28, 2025 22:14:21.455065012 CET50128445192.168.2.229.175.153.233
                                        Mar 28, 2025 22:14:21.458453894 CET50129445192.168.2.22193.26.101.28
                                        Mar 28, 2025 22:14:21.473984003 CET50130445192.168.2.22213.83.93.55
                                        Mar 28, 2025 22:14:21.501935005 CET50131445192.168.2.22189.222.68.85
                                        Mar 28, 2025 22:14:21.577586889 CET50132445192.168.2.2221.220.217.97
                                        Mar 28, 2025 22:14:21.577696085 CET50133445192.168.2.2285.114.199.76
                                        Mar 28, 2025 22:14:21.577892065 CET50134445192.168.2.22187.82.63.113
                                        Mar 28, 2025 22:14:21.727118969 CET50136445192.168.2.2227.1.102.204
                                        Mar 28, 2025 22:14:21.727199078 CET50137445192.168.2.2244.208.34.213
                                        Mar 28, 2025 22:14:21.727241993 CET50138445192.168.2.22153.219.118.241
                                        Mar 28, 2025 22:14:21.829514027 CET50139445192.168.2.2210.143.208.63
                                        Mar 28, 2025 22:14:21.829596996 CET50140445192.168.2.224.158.189.36
                                        Mar 28, 2025 22:14:21.829725027 CET50141445192.168.2.2266.168.134.26
                                        Mar 28, 2025 22:14:21.829785109 CET50142445192.168.2.22101.224.25.68
                                        Mar 28, 2025 22:14:21.829838037 CET50143445192.168.2.2230.29.156.249
                                        Mar 28, 2025 22:14:21.845283031 CET50144445192.168.2.22190.219.15.10
                                        Mar 28, 2025 22:14:21.860676050 CET50145445192.168.2.2231.104.246.164
                                        Mar 28, 2025 22:14:21.891894102 CET50146445192.168.2.22197.208.222.185
                                        Mar 28, 2025 22:14:21.940146923 CET50147445192.168.2.22204.228.114.158
                                        Mar 28, 2025 22:14:21.940321922 CET50148445192.168.2.22202.230.229.227
                                        Mar 28, 2025 22:14:21.940407991 CET50149445192.168.2.22207.148.103.50
                                        Mar 28, 2025 22:14:21.954452038 CET50150445192.168.2.22192.13.222.69
                                        Mar 28, 2025 22:14:21.985549927 CET50151445192.168.2.2298.98.50.93
                                        Mar 28, 2025 22:14:22.141563892 CET50154445192.168.2.22220.63.78.217
                                        Mar 28, 2025 22:14:22.143254042 CET50155445192.168.2.22148.209.102.161
                                        Mar 28, 2025 22:14:22.188360929 CET50156445192.168.2.2261.52.251.189
                                        Mar 28, 2025 22:14:22.219893932 CET50157445192.168.2.22150.98.53.161
                                        Mar 28, 2025 22:14:22.360109091 CET50158445192.168.2.2218.58.104.49
                                        Mar 28, 2025 22:14:22.375518084 CET50160445192.168.2.22131.242.106.129
                                        Mar 28, 2025 22:14:22.375525951 CET50159445192.168.2.22129.235.121.61
                                        Mar 28, 2025 22:14:22.422422886 CET50161445192.168.2.2225.142.51.230
                                        Mar 28, 2025 22:14:22.438036919 CET50162445192.168.2.2262.48.222.133
                                        Mar 28, 2025 22:14:22.578428030 CET50164445192.168.2.2243.25.58.169
                                        Mar 28, 2025 22:14:22.578454971 CET50165445192.168.2.22163.158.157.127
                                        Mar 28, 2025 22:14:22.593913078 CET50166445192.168.2.2299.117.73.225
                                        Mar 28, 2025 22:14:22.625144958 CET50167445192.168.2.22202.143.76.195
                                        Mar 28, 2025 22:14:22.687714100 CET50169445192.168.2.22212.70.176.126
                                        Mar 28, 2025 22:14:22.687815905 CET50170445192.168.2.2227.5.68.51
                                        Mar 28, 2025 22:14:22.688095093 CET50171445192.168.2.2214.254.108.244
                                        Mar 28, 2025 22:14:22.843686104 CET50173445192.168.2.2268.191.28.160
                                        Mar 28, 2025 22:14:22.843750954 CET50174445192.168.2.2295.98.219.238
                                        Mar 28, 2025 22:14:22.843875885 CET50175445192.168.2.22173.148.201.48
                                        Mar 28, 2025 22:14:22.952692986 CET50176445192.168.2.22121.218.49.86
                                        Mar 28, 2025 22:14:22.952769041 CET50177445192.168.2.22126.156.67.248
                                        Mar 28, 2025 22:14:22.952889919 CET50178445192.168.2.22173.31.151.14
                                        Mar 28, 2025 22:14:22.952950954 CET50179445192.168.2.2233.53.195.32
                                        Mar 28, 2025 22:14:22.953043938 CET50180445192.168.2.22222.26.184.177
                                        Mar 28, 2025 22:14:22.968446016 CET50181445192.168.2.22202.58.90.173
                                        Mar 28, 2025 22:14:22.983918905 CET50182445192.168.2.2239.121.127.147
                                        Mar 28, 2025 22:14:23.015178919 CET50183445192.168.2.22138.208.93.211
                                        Mar 28, 2025 22:14:23.061958075 CET50184445192.168.2.2239.240.211.237
                                        Mar 28, 2025 22:14:23.062165022 CET50185445192.168.2.22119.67.112.212
                                        Mar 28, 2025 22:14:23.062397957 CET50186445192.168.2.2273.155.117.138
                                        Mar 28, 2025 22:14:23.077652931 CET50187445192.168.2.22130.239.204.214
                                        Mar 28, 2025 22:14:23.109257936 CET50188445192.168.2.22173.27.55.28
                                        Mar 28, 2025 22:14:23.264878988 CET50193445192.168.2.2248.44.206.254
                                        Mar 28, 2025 22:14:23.264884949 CET50192445192.168.2.22142.242.86.242
                                        Mar 28, 2025 22:14:23.311609983 CET50194445192.168.2.22133.23.228.237
                                        Mar 28, 2025 22:14:23.342984915 CET50195445192.168.2.2244.71.32.71
                                        Mar 28, 2025 22:14:23.498651028 CET50197445192.168.2.22145.131.37.52
                                        Mar 28, 2025 22:14:23.509231091 CET50198445192.168.2.22131.250.114.114
                                        Mar 28, 2025 22:14:23.545617104 CET50199445192.168.2.2221.15.35.184
                                        Mar 28, 2025 22:14:23.561105967 CET50200445192.168.2.22207.67.81.91
                                        Mar 28, 2025 22:14:23.701483965 CET50203445192.168.2.2213.119.156.245
                                        Mar 28, 2025 22:14:23.701699972 CET50204445192.168.2.2224.224.79.181
                                        Mar 28, 2025 22:14:23.717159033 CET50205445192.168.2.22148.113.251.220
                                        Mar 28, 2025 22:14:23.748378038 CET50206445192.168.2.22148.209.107.218
                                        Mar 28, 2025 22:14:23.810770035 CET50208445192.168.2.22169.15.157.229
                                        Mar 28, 2025 22:14:23.810929060 CET50210445192.168.2.2294.171.178.161
                                        Mar 28, 2025 22:14:23.810976982 CET50211445192.168.2.22212.187.46.45
                                        Mar 28, 2025 22:14:23.966981888 CET50213445192.168.2.2253.73.166.166
                                        Mar 28, 2025 22:14:23.967056990 CET50212445192.168.2.22112.79.67.193
                                        Mar 28, 2025 22:14:23.967056990 CET50214445192.168.2.2251.175.168.78
                                        Mar 28, 2025 22:14:24.076102972 CET50215445192.168.2.22218.187.43.247
                                        Mar 28, 2025 22:14:24.076225996 CET50216445192.168.2.2294.17.57.2
                                        Mar 28, 2025 22:14:24.076229095 CET50217445192.168.2.224.92.249.84
                                        Mar 28, 2025 22:14:24.076307058 CET50218445192.168.2.22141.148.64.122
                                        Mar 28, 2025 22:14:24.076334000 CET50219445192.168.2.2290.246.29.34
                                        Mar 28, 2025 22:14:24.091763973 CET50220445192.168.2.22179.32.8.154
                                        Mar 28, 2025 22:14:24.107135057 CET50221445192.168.2.2257.213.237.203
                                        Mar 28, 2025 22:14:24.138288021 CET50223445192.168.2.22104.251.21.99
                                        Mar 28, 2025 22:14:24.185144901 CET50224445192.168.2.2212.37.17.219
                                        Mar 28, 2025 22:14:24.185237885 CET50225445192.168.2.22202.246.22.14
                                        Mar 28, 2025 22:14:24.185412884 CET50226445192.168.2.22223.103.176.6
                                        Mar 28, 2025 22:14:24.200867891 CET50227445192.168.2.22172.202.65.244
                                        Mar 28, 2025 22:14:24.232249022 CET50228445192.168.2.22109.99.87.167
                                        Mar 28, 2025 22:14:24.387939930 CET50232445192.168.2.22208.188.100.246
                                        Mar 28, 2025 22:14:24.388003111 CET50233445192.168.2.2257.238.236.78
                                        Mar 28, 2025 22:14:24.434962034 CET50234445192.168.2.2272.157.59.44
                                        Mar 28, 2025 22:14:24.465929985 CET50235445192.168.2.2251.121.106.166
                                        Mar 28, 2025 22:14:24.606297970 CET50237445192.168.2.2272.105.18.173
                                        Mar 28, 2025 22:14:24.621917963 CET50238445192.168.2.22199.33.228.62
                                        Mar 28, 2025 22:14:24.622036934 CET50239445192.168.2.22146.205.176.228
                                        Mar 28, 2025 22:14:24.668731928 CET50240445192.168.2.2292.87.35.20
                                        Mar 28, 2025 22:14:24.684511900 CET50241445192.168.2.2271.94.224.149
                                        Mar 28, 2025 22:14:24.824922085 CET50244445192.168.2.22104.251.42.133
                                        Mar 28, 2025 22:14:24.825025082 CET50245445192.168.2.2283.60.138.245
                                        Mar 28, 2025 22:14:24.840290070 CET50246445192.168.2.2220.205.177.93
                                        Mar 28, 2025 22:14:24.871562958 CET50247445192.168.2.228.125.91.29
                                        Mar 28, 2025 22:14:24.934173107 CET50249445192.168.2.2214.83.1.106
                                        Mar 28, 2025 22:14:24.934319019 CET50250445192.168.2.22108.144.28.81
                                        Mar 28, 2025 22:14:24.934439898 CET50252445192.168.2.22144.204.114.52
                                        Mar 28, 2025 22:14:25.090070963 CET50254445192.168.2.22180.238.106.70
                                        Mar 28, 2025 22:14:25.090143919 CET50255445192.168.2.22218.156.208.206
                                        Mar 28, 2025 22:14:25.090182066 CET50256445192.168.2.2272.150.165.208
                                        Mar 28, 2025 22:14:25.199096918 CET50257445192.168.2.2278.199.144.224
                                        Mar 28, 2025 22:14:25.199256897 CET50258445192.168.2.22102.225.137.187
                                        Mar 28, 2025 22:14:25.199309111 CET50259445192.168.2.2278.98.174.211
                                        Mar 28, 2025 22:14:25.199409962 CET50260445192.168.2.2278.85.4.49
                                        Mar 28, 2025 22:14:25.199477911 CET50261445192.168.2.22185.22.86.4
                                        Mar 28, 2025 22:14:25.214653969 CET50262445192.168.2.2262.26.136.198
                                        Mar 28, 2025 22:14:25.236248970 CET50263445192.168.2.22172.174.65.158
                                        Mar 28, 2025 22:14:25.261471987 CET50265445192.168.2.22177.96.212.163
                                        Mar 28, 2025 22:14:25.308285952 CET50267445192.168.2.22204.6.117.192
                                        Mar 28, 2025 22:14:25.308399916 CET50268445192.168.2.2251.66.26.254
                                        Mar 28, 2025 22:14:25.308459997 CET50269445192.168.2.22152.168.131.180
                                        Mar 28, 2025 22:14:25.323838949 CET50270445192.168.2.22137.79.23.114
                                        Mar 28, 2025 22:14:25.355108976 CET50271445192.168.2.223.156.204.173
                                        Mar 28, 2025 22:14:25.511071920 CET50275445192.168.2.2250.122.208.148
                                        Mar 28, 2025 22:14:25.512089968 CET50276445192.168.2.22160.200.72.130
                                        Mar 28, 2025 22:14:25.557926893 CET50277445192.168.2.22114.122.239.93
                                        Mar 28, 2025 22:14:25.589173079 CET50278445192.168.2.2237.215.166.126
                                        Mar 28, 2025 22:14:25.729501009 CET50281445192.168.2.22138.70.156.211
                                        Mar 28, 2025 22:14:25.745049953 CET50282445192.168.2.22199.186.74.95
                                        Mar 28, 2025 22:14:25.745090008 CET50283445192.168.2.2274.194.210.32
                                        Mar 28, 2025 22:14:25.792887926 CET50284445192.168.2.22183.38.125.196
                                        Mar 28, 2025 22:14:25.807542086 CET50285445192.168.2.22222.56.42.128
                                        Mar 28, 2025 22:14:25.947992086 CET50288445192.168.2.222.67.164.53
                                        Mar 28, 2025 22:14:25.948529959 CET50289445192.168.2.2227.221.201.142
                                        Mar 28, 2025 22:14:25.963531017 CET50291445192.168.2.2276.24.245.15
                                        Mar 28, 2025 22:14:25.994997025 CET50292445192.168.2.22164.188.90.230
                                        Mar 28, 2025 22:14:26.057190895 CET50294445192.168.2.22102.64.44.90
                                        Mar 28, 2025 22:14:26.057421923 CET50296445192.168.2.22106.20.173.206
                                        Mar 28, 2025 22:14:26.057549953 CET50297445192.168.2.22158.23.19.165
                                        Mar 28, 2025 22:14:26.213371992 CET50299445192.168.2.2264.72.97.103
                                        Mar 28, 2025 22:14:26.213418961 CET50301445192.168.2.2288.88.35.227
                                        Mar 28, 2025 22:14:26.213445902 CET50300445192.168.2.2246.43.139.115
                                        Mar 28, 2025 22:14:26.322483063 CET50303445192.168.2.22161.250.41.119
                                        Mar 28, 2025 22:14:26.322586060 CET50304445192.168.2.22122.31.112.114
                                        Mar 28, 2025 22:14:26.322707891 CET50306445192.168.2.22193.119.72.99
                                        Mar 28, 2025 22:14:26.322766066 CET50305445192.168.2.22120.89.34.53
                                        Mar 28, 2025 22:14:26.322839975 CET50307445192.168.2.22100.130.241.183
                                        Mar 28, 2025 22:14:26.338035107 CET50308445192.168.2.22190.44.48.60
                                        Mar 28, 2025 22:14:26.353503942 CET50309445192.168.2.22201.5.147.129
                                        Mar 28, 2025 22:14:26.384800911 CET50311445192.168.2.22218.42.160.173
                                        Mar 28, 2025 22:14:26.431577921 CET50314445192.168.2.22216.103.247.11
                                        Mar 28, 2025 22:14:26.431643963 CET50315445192.168.2.22200.232.5.60
                                        Mar 28, 2025 22:14:26.431682110 CET50313445192.168.2.2291.142.77.43
                                        Mar 28, 2025 22:14:26.447117090 CET50316445192.168.2.2280.202.132.8
                                        Mar 28, 2025 22:14:26.478348017 CET50317445192.168.2.22223.118.53.100
                                        Mar 28, 2025 22:14:26.634315968 CET50322445192.168.2.2252.235.251.120
                                        Mar 28, 2025 22:14:26.634444952 CET50323445192.168.2.22196.200.158.174
                                        Mar 28, 2025 22:14:26.681127071 CET50324445192.168.2.2276.219.119.33
                                        Mar 28, 2025 22:14:26.712378025 CET50325445192.168.2.22191.155.73.129
                                        Mar 28, 2025 22:14:26.852777958 CET50329445192.168.2.22114.86.40.249
                                        Mar 28, 2025 22:14:26.868366003 CET50330445192.168.2.22114.77.51.125
                                        Mar 28, 2025 22:14:26.868376970 CET50331445192.168.2.22182.187.117.13
                                        Mar 28, 2025 22:14:26.915199041 CET50332445192.168.2.2233.171.101.209
                                        Mar 28, 2025 22:14:26.931832075 CET50333445192.168.2.223.124.189.30
                                        Mar 28, 2025 22:14:27.071202040 CET50337445192.168.2.22216.96.141.36
                                        Mar 28, 2025 22:14:27.071516991 CET50339445192.168.2.22191.198.52.231
                                        Mar 28, 2025 22:14:27.086782932 CET50340445192.168.2.2244.26.48.158
                                        Mar 28, 2025 22:14:27.180341959 CET50344445192.168.2.22220.160.74.173
                                        Mar 28, 2025 22:14:27.180486917 CET50345445192.168.2.22194.228.220.46
                                        Mar 28, 2025 22:14:27.180627108 CET50347445192.168.2.2289.1.134.73
                                        Mar 28, 2025 22:14:27.336503983 CET50349445192.168.2.2282.214.226.99
                                        Mar 28, 2025 22:14:27.336503983 CET50350445192.168.2.22175.118.203.230
                                        Mar 28, 2025 22:14:27.336517096 CET50351445192.168.2.2269.63.19.94
                                        Mar 28, 2025 22:14:27.445633888 CET50353445192.168.2.22204.234.225.158
                                        Mar 28, 2025 22:14:27.445637941 CET50354445192.168.2.2241.203.188.25
                                        Mar 28, 2025 22:14:27.445698977 CET50355445192.168.2.2221.9.75.14
                                        Mar 28, 2025 22:14:27.445724964 CET50356445192.168.2.22187.60.112.227
                                        Mar 28, 2025 22:14:27.445784092 CET50357445192.168.2.2218.13.185.125
                                        Mar 28, 2025 22:14:27.461460114 CET50358445192.168.2.2241.116.102.50
                                        Mar 28, 2025 22:14:27.476718903 CET50359445192.168.2.22118.186.161.104
                                        Mar 28, 2025 22:14:27.507862091 CET50362445192.168.2.22219.232.46.211
                                        Mar 28, 2025 22:14:27.554689884 CET50364445192.168.2.2236.252.138.242
                                        Mar 28, 2025 22:14:27.554785013 CET50365445192.168.2.2238.120.130.175
                                        Mar 28, 2025 22:14:27.554785013 CET50366445192.168.2.22190.191.220.211
                                        Mar 28, 2025 22:14:27.570324898 CET50367445192.168.2.22128.19.193.213
                                        Mar 28, 2025 22:14:27.601742983 CET50368445192.168.2.22194.160.98.245
                                        Mar 28, 2025 22:14:27.757482052 CET50374445192.168.2.22194.147.142.88
                                        Mar 28, 2025 22:14:27.757565022 CET50375445192.168.2.228.82.35.33
                                        Mar 28, 2025 22:14:27.804328918 CET50376445192.168.2.2220.29.5.246
                                        Mar 28, 2025 22:14:27.835599899 CET50377445192.168.2.2247.58.142.140
                                        Mar 28, 2025 22:14:27.975959063 CET50382445192.168.2.2246.200.68.119
                                        Mar 28, 2025 22:14:27.991447926 CET50383445192.168.2.22183.235.162.186
                                        Mar 28, 2025 22:14:27.991641045 CET50384445192.168.2.22198.28.216.81
                                        Mar 28, 2025 22:14:28.049962044 CET50385445192.168.2.22131.30.93.170
                                        Mar 28, 2025 22:14:28.053904057 CET50386445192.168.2.22143.185.116.97
                                        Mar 28, 2025 22:14:28.197324991 CET50392445192.168.2.22107.88.85.160
                                        Mar 28, 2025 22:14:28.202049971 CET50393445192.168.2.22175.220.61.126
                                        Mar 28, 2025 22:14:28.210180998 CET50394445192.168.2.2293.22.56.59
                                        Mar 28, 2025 22:14:28.243211985 CET50396445192.168.2.222.192.247.184
                                        Mar 28, 2025 22:14:28.305279016 CET50398445192.168.2.22219.215.120.65
                                        Mar 28, 2025 22:14:28.305464983 CET50400445192.168.2.22217.140.69.34
                                        Mar 28, 2025 22:14:28.305521011 CET50401445192.168.2.2257.158.96.19
                                        Mar 28, 2025 22:14:28.584388018 CET50404445192.168.2.22117.141.171.30
                                        Mar 28, 2025 22:14:28.599984884 CET50405445192.168.2.22185.74.7.174
                                        Mar 28, 2025 22:14:28.645924091 CET50408445192.168.2.22163.220.84.54
                                        Mar 28, 2025 22:14:28.645982981 CET50409445192.168.2.2280.174.3.149
                                        Mar 28, 2025 22:14:28.646049976 CET50410445192.168.2.2270.113.196.179
                                        Mar 28, 2025 22:14:28.646631956 CET50412445192.168.2.22182.87.193.30
                                        Mar 28, 2025 22:14:28.646728039 CET50413445192.168.2.22126.185.13.228
                                        Mar 28, 2025 22:14:28.646807909 CET50414445192.168.2.22170.42.38.154
                                        Mar 28, 2025 22:14:28.646891117 CET50415445192.168.2.225.204.215.212
                                        Mar 28, 2025 22:14:28.646923065 CET50416445192.168.2.2265.170.147.234
                                        Mar 28, 2025 22:14:28.688793898 CET50419445192.168.2.22125.243.60.189
                                        Mar 28, 2025 22:14:28.688865900 CET50420445192.168.2.227.59.221.188
                                        Mar 28, 2025 22:14:28.688956022 CET50421445192.168.2.225.19.71.212
                                        Mar 28, 2025 22:14:28.694664955 CET50422445192.168.2.22166.235.162.153
                                        Mar 28, 2025 22:14:28.724889040 CET50423445192.168.2.22166.171.7.58
                                        Mar 28, 2025 22:14:28.789995909 CET50426445192.168.2.22119.204.138.174
                                        Mar 28, 2025 22:14:28.880856037 CET50430445192.168.2.223.105.208.18
                                        Mar 28, 2025 22:14:28.896408081 CET50433445192.168.2.2237.89.94.74
                                        Mar 28, 2025 22:14:28.927809954 CET50435445192.168.2.2291.28.19.136
                                        Mar 28, 2025 22:14:28.958743095 CET50436445192.168.2.22159.182.182.66
                                        Mar 28, 2025 22:14:29.099195004 CET50442445192.168.2.2291.75.110.35
                                        Mar 28, 2025 22:14:29.114748955 CET50443445192.168.2.22106.189.51.238
                                        Mar 28, 2025 22:14:29.114810944 CET50444445192.168.2.22196.113.17.91
                                        Mar 28, 2025 22:14:29.161601067 CET50446445192.168.2.2237.163.254.74
                                        Mar 28, 2025 22:14:29.177097082 CET50448445192.168.2.22149.225.219.72
                                        Mar 28, 2025 22:14:29.317584991 CET50453445192.168.2.2283.127.145.165
                                        Mar 28, 2025 22:14:29.317703962 CET50455445192.168.2.2272.119.243.39
                                        Mar 28, 2025 22:14:29.333285093 CET50457445192.168.2.2215.109.41.140
                                        Mar 28, 2025 22:14:29.364358902 CET50459445192.168.2.22220.230.99.53
                                        Mar 28, 2025 22:14:29.426714897 CET50461445192.168.2.2251.246.156.131
                                        Mar 28, 2025 22:14:29.426795006 CET50462445192.168.2.22223.176.250.208
                                        Mar 28, 2025 22:14:29.426855087 CET50464445192.168.2.22174.202.66.27
                                        Mar 28, 2025 22:14:29.707740068 CET50471445192.168.2.22130.82.143.12
                                        Mar 28, 2025 22:14:29.723124027 CET50472445192.168.2.2248.10.84.62
                                        Mar 28, 2025 22:14:29.754313946 CET50474445192.168.2.22209.80.251.47
                                        Mar 28, 2025 22:14:29.754420996 CET50475445192.168.2.22145.75.242.125
                                        Mar 28, 2025 22:14:29.754513025 CET50476445192.168.2.2291.167.152.5
                                        Mar 28, 2025 22:14:29.769933939 CET50481445192.168.2.22150.46.94.249
                                        Mar 28, 2025 22:14:29.769937992 CET50482445192.168.2.22115.80.21.32
                                        Mar 28, 2025 22:14:29.770006895 CET50483445192.168.2.22165.33.193.37
                                        Mar 28, 2025 22:14:29.770037889 CET50484445192.168.2.22181.209.132.151
                                        Mar 28, 2025 22:14:29.770107985 CET50485445192.168.2.22135.67.212.252
                                        Mar 28, 2025 22:14:29.801134109 CET50487445192.168.2.22205.137.204.58
                                        Mar 28, 2025 22:14:29.801168919 CET50488445192.168.2.2223.140.6.174
                                        Mar 28, 2025 22:14:29.801249981 CET50489445192.168.2.2242.230.93.223
                                        Mar 28, 2025 22:14:29.816888094 CET50490445192.168.2.2214.173.57.169
                                        Mar 28, 2025 22:14:29.847960949 CET50492445192.168.2.22157.173.245.226
                                        Mar 28, 2025 22:14:29.910542965 CET50498445192.168.2.22195.82.177.71
                                        Mar 28, 2025 22:14:30.004040003 CET50501445192.168.2.22186.70.211.214
                                        Mar 28, 2025 22:14:30.019620895 CET50504445192.168.2.22216.251.158.207
                                        Mar 28, 2025 22:14:30.050709963 CET50507445192.168.2.2246.176.197.228
                                        Mar 28, 2025 22:14:30.081911087 CET50509445192.168.2.22192.36.236.145
                                        Mar 28, 2025 22:14:30.222676039 CET50518445192.168.2.22112.128.196.232
                                        Mar 28, 2025 22:14:30.237914085 CET50519445192.168.2.2258.211.70.60
                                        Mar 28, 2025 22:14:30.238028049 CET50520445192.168.2.2292.224.191.117
                                        Mar 28, 2025 22:14:30.284754992 CET50523445192.168.2.2216.47.227.39
                                        Mar 28, 2025 22:14:30.300293922 CET50525445192.168.2.22171.176.151.176
                                        Mar 28, 2025 22:14:30.440802097 CET50535445192.168.2.2252.204.43.17
                                        Mar 28, 2025 22:14:30.440849066 CET50536445192.168.2.2211.228.141.243
                                        Mar 28, 2025 22:14:30.456329107 CET50540445192.168.2.2217.91.170.16
                                        Mar 28, 2025 22:14:30.487591028 CET50543445192.168.2.22118.12.118.193
                                        Mar 28, 2025 22:14:30.550000906 CET50550445192.168.2.22108.96.243.23
                                        Mar 28, 2025 22:14:30.550005913 CET50547445192.168.2.22107.83.51.13
                                        Mar 28, 2025 22:14:30.550065041 CET50548445192.168.2.2248.4.52.42
                                        Mar 28, 2025 22:14:30.830841064 CET50573445192.168.2.2210.221.8.60
                                        Mar 28, 2025 22:14:30.846326113 CET50575445192.168.2.22116.130.153.253
                                        Mar 28, 2025 22:14:30.877613068 CET50582445192.168.2.2223.21.155.227
                                        Mar 28, 2025 22:14:30.877676010 CET50583445192.168.2.2293.247.152.166
                                        Mar 28, 2025 22:14:30.877890110 CET50584445192.168.2.22199.70.227.96
                                        Mar 28, 2025 22:14:30.893143892 CET50587445192.168.2.22116.135.110.189
                                        Mar 28, 2025 22:14:30.893239021 CET50588445192.168.2.22211.218.118.105
                                        Mar 28, 2025 22:14:30.893399000 CET50589445192.168.2.2272.102.68.207
                                        Mar 28, 2025 22:14:30.893487930 CET50590445192.168.2.22222.22.30.2
                                        Mar 28, 2025 22:14:30.893569946 CET50591445192.168.2.2230.248.18.68
                                        Mar 28, 2025 22:14:30.924290895 CET50595445192.168.2.22156.220.226.104
                                        Mar 28, 2025 22:14:30.924362898 CET50596445192.168.2.22216.105.119.245
                                        Mar 28, 2025 22:14:30.924437046 CET50597445192.168.2.22122.160.235.160
                                        Mar 28, 2025 22:14:30.940538883 CET50599445192.168.2.22144.135.10.9
                                        Mar 28, 2025 22:14:31.033792019 CET50608445192.168.2.22206.49.114.153
                                        Mar 28, 2025 22:14:31.094676018 CET50612445192.168.2.2285.146.194.50
                                        Mar 28, 2025 22:14:31.151335001 CET50622445192.168.2.22213.44.244.2
                                        Mar 28, 2025 22:14:31.192218065 CET50624445192.168.2.2293.41.142.83
                                        Mar 28, 2025 22:14:31.192378044 CET50627445192.168.2.2255.220.240.108
                                        Mar 28, 2025 22:14:31.230926037 CET50630445192.168.2.2283.92.206.221
                                        Mar 28, 2025 22:14:31.361129999 CET50637445192.168.2.22158.114.65.85
                                        Mar 28, 2025 22:14:31.555315971 CET50649445192.168.2.2299.228.158.91
                                        Mar 28, 2025 22:14:31.555403948 CET50650445192.168.2.2290.252.219.199
                                        Mar 28, 2025 22:14:31.555509090 CET50652445192.168.2.2277.61.207.41
                                        Mar 28, 2025 22:14:31.555608988 CET50654445192.168.2.226.34.34.94
                                        Mar 28, 2025 22:14:31.564456940 CET50658445192.168.2.22113.231.151.182
                                        Mar 28, 2025 22:14:31.579549074 CET50662445192.168.2.2272.151.104.17
                                        Mar 28, 2025 22:14:31.673201084 CET50667445192.168.2.2274.216.57.38
                                        Mar 28, 2025 22:14:31.673448086 CET50670445192.168.2.22111.165.217.158
                                        Mar 28, 2025 22:14:31.673501968 CET50669445192.168.2.22169.215.77.25
                                        Mar 28, 2025 22:14:31.715662956 CET50672445192.168.2.22122.215.71.140
                                        Mar 28, 2025 22:14:31.715899944 CET50674445192.168.2.22158.59.167.61
                                        TimestampSource PortDest PortSource IPDest IP
                                        Mar 28, 2025 22:13:26.695034981 CET5456253192.168.2.228.8.8.8
                                        Mar 28, 2025 22:13:26.782948971 CET53545628.8.8.8192.168.2.22
                                        Mar 28, 2025 22:13:27.565802097 CET5291753192.168.2.228.8.8.8
                                        Mar 28, 2025 22:13:27.650319099 CET53529178.8.8.8192.168.2.22
                                        Mar 28, 2025 22:15:18.835329056 CET138138192.168.2.22192.168.2.255
                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                        Mar 28, 2025 22:13:26.695034981 CET192.168.2.228.8.8.80x5b7cStandard query (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comA (IP address)IN (0x0001)false
                                        Mar 28, 2025 22:13:27.565802097 CET192.168.2.228.8.8.80x3a89Standard query (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.comA (IP address)IN (0x0001)false
                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                        Mar 28, 2025 22:13:26.782948971 CET8.8.8.8192.168.2.220x5b7cNo error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com104.16.166.228A (IP address)IN (0x0001)false
                                        Mar 28, 2025 22:13:26.782948971 CET8.8.8.8192.168.2.220x5b7cNo error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com104.16.167.228A (IP address)IN (0x0001)false
                                        Mar 28, 2025 22:13:27.650319099 CET8.8.8.8192.168.2.220x3a89No error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com104.16.166.228A (IP address)IN (0x0001)false
                                        Mar 28, 2025 22:13:27.650319099 CET8.8.8.8192.168.2.220x3a89No error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com104.16.167.228A (IP address)IN (0x0001)false
                                        • www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        0192.168.2.2249161104.16.166.228803504C:\Users\user\Desktop\mssecsvc.exe.exe
                                        TimestampBytes transferredDirectionData
                                        Mar 28, 2025 22:13:26.896770954 CET100OUTGET / HTTP/1.1
                                        Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
                                        Cache-Control: no-cache
                                        Mar 28, 2025 22:13:26.998145103 CET778INHTTP/1.1 200 OK
                                        Date: Fri, 28 Mar 2025 21:13:26 GMT
                                        Content-Type: text/html
                                        Content-Length: 607
                                        Connection: close
                                        Server: cloudflare
                                        CF-RAY: 927a21a75da023ce-EWR
                                        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 2d 75 73 22 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 3c 74 69 74 6c 65 3e 53 69 6e 6b 68 6f 6c 65 64 20 62 79 20 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 3c 2f 74 69 74 6c 65 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 20 53 69 6e 6b 68 6f 6c 65 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 73 74 61 74 69 63 2e 6b 72 79 70 74 6f 73 6c 6f 67 69 63 73 69 6e 6b 68 6f 6c 65 2e 63 6f 6d 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 2f 3e 3c 2f [TRUNCATED]
                                        Data Ascii: <!DOCTYPE html><html lang="en-us" class="no-js"><head><meta charset="utf-8"><title>Sinkholed by Kryptos Logic</title><meta name="description" content="Kryptos Logic Sinkhole"><meta name="viewport" content="width=device-width, initial-scale=1.0"><link href="//static.kryptoslogicsinkhole.com/style.css" rel="stylesheet" type="text/css"/></head><body class="flat"><div class="content"><div class="content-box"><div class="big-content"><div class="clear"></div></div><h1>Sinkholed!</h1><p>This domain has been sinkholed by <a href="https://www.kryptoslogic.com">Kryptos Logic</a>.</p></div></div></body></html>


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        1192.168.2.2249162104.16.166.228803676C:\Users\user\Desktop\mssecsvc.exe.exe
                                        TimestampBytes transferredDirectionData
                                        Mar 28, 2025 22:13:27.765008926 CET100OUTGET / HTTP/1.1
                                        Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
                                        Cache-Control: no-cache
                                        Mar 28, 2025 22:13:27.867098093 CET778INHTTP/1.1 200 OK
                                        Date: Fri, 28 Mar 2025 21:13:27 GMT
                                        Content-Type: text/html
                                        Content-Length: 607
                                        Connection: close
                                        Server: cloudflare
                                        CF-RAY: 927a21accb51f797-EWR
                                        Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 2d 75 73 22 20 63 6c 61 73 73 3d 22 6e 6f 2d 6a 73 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 3c 74 69 74 6c 65 3e 53 69 6e 6b 68 6f 6c 65 64 20 62 79 20 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 3c 2f 74 69 74 6c 65 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 4b 72 79 70 74 6f 73 20 4c 6f 67 69 63 20 53 69 6e 6b 68 6f 6c 65 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 73 74 61 74 69 63 2e 6b 72 79 70 74 6f 73 6c 6f 67 69 63 73 69 6e 6b 68 6f 6c 65 2e 63 6f 6d 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 2f 3e 3c 2f [TRUNCATED]
                                        Data Ascii: <!DOCTYPE html><html lang="en-us" class="no-js"><head><meta charset="utf-8"><title>Sinkholed by Kryptos Logic</title><meta name="description" content="Kryptos Logic Sinkhole"><meta name="viewport" content="width=device-width, initial-scale=1.0"><link href="//static.kryptoslogicsinkhole.com/style.css" rel="stylesheet" type="text/css"/></head><body class="flat"><div class="content"><div class="content-box"><div class="big-content"><div class="clear"></div></div><h1>Sinkholed!</h1><p>This domain has been sinkholed by <a href="https://www.kryptoslogic.com">Kryptos Logic</a>.</p></div></div></body></html>


                                        Click to jump to process

                                        Click to jump to process

                                        • File
                                        • Network

                                        Click to dive into process behavior distribution

                                        Target ID:0
                                        Start time:17:13:23
                                        Start date:28/03/2025
                                        Path:C:\Users\user\Desktop\mssecsvc.exe.exe
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Users\user\Desktop\mssecsvc.exe.exe"
                                        Imagebase:0x400000
                                        File size:3'723'264 bytes
                                        MD5 hash:0C694193CEAC8BFB016491FFB534EB7C
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000002.358030594.000000000040F000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000000.350973560.000000000040F000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000000.350995207.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000000.00000000.350995207.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: us-cert code analysis team
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000002.358062507.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000000.00000002.358062507.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: us-cert code analysis team
                                        Reputation:low
                                        Has exited:true
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                        Target ID:4
                                        Start time:17:13:25
                                        Start date:28/03/2025
                                        Path:C:\Users\user\Desktop\mssecsvc.exe.exe
                                        Wow64 process (32bit):true
                                        Commandline:C:\Users\user\Desktop\mssecsvc.exe.exe -m security
                                        Imagebase:0x400000
                                        File size:3'723'264 bytes
                                        MD5 hash:0C694193CEAC8BFB016491FFB534EB7C
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000004.00000002.493697479.000000000042E000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000004.00000000.355043612.000000000040F000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000004.00000000.355162582.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000004.00000000.355162582.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: us-cert code analysis team
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000004.00000002.493989278.000000000289B000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000004.00000002.493989278.000000000289B000.00000004.00000020.00020000.00000000.sdmp, Author: us-cert code analysis team
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000004.00000002.493722594.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000004.00000002.493722594.0000000000710000.00000002.00000001.01000000.00000003.sdmp, Author: us-cert code analysis team
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000004.00000002.493920709.0000000002383000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000004.00000002.493920709.0000000002383000.00000004.00000020.00020000.00000000.sdmp, Author: us-cert code analysis team
                                        Reputation:low
                                        Has exited:true
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                        Target ID:5
                                        Start time:17:13:26
                                        Start date:28/03/2025
                                        Path:C:\Windows\tasksche.exe
                                        Wow64 process (32bit):false
                                        Commandline:C:\WINDOWS\tasksche.exe /i
                                        Imagebase:0x400000
                                        File size:3'514'368 bytes
                                        MD5 hash:7F7CCAA16FB15EB1C7399D422F8363E8
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000005.00000000.357354210.000000000040E000.00000008.00000001.01000000.00000005.sdmp, Author: us-cert code analysis team
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000005.00000002.357560055.000000000040E000.00000008.00000001.01000000.00000005.sdmp, Author: us-cert code analysis team
                                        • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Windows\tasksche.exe, Author: Joe Security
                                        • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\tasksche.exe, Author: Florian Roth (with the help of binar.ly)
                                        • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: C:\Windows\tasksche.exe, Author: us-cert code analysis team
                                        • Rule: Win32_Ransomware_WannaCry, Description: unknown, Source: C:\Windows\tasksche.exe, Author: ReversingLabs
                                        Antivirus matches:
                                        • Detection: 100%, Avira
                                        • Detection: 100%, ReversingLabs
                                        Reputation:moderate
                                        Has exited:true

                                        No disassembly