Edit tour

Windows Analysis Report
WizClient.exe

Overview

General Information

Sample name:WizClient.exe
Analysis ID:1652216
MD5:51dc79ac2451e7ad8809d28ee07602b4
SHA1:37a4efa21c4a98a45b75c8b6037bc8d719cdf45e
SHA256:dcbc3e96c538390d213875789f30feaeec238a512fc32b19e8f2c1216b89ad4c
Tags:exeuser-BastianHein
Infos:

Detection

XWorm
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected XWorm
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
C2 URLs / IPs found in malware configuration
Joe Sandbox ML detected suspicious sample
Sample uses string decryption to hide its real strings
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries the volume information (name, serial number etc) of a device
Uses 32bit PE files
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • WizClient.exe (PID: 6276 cmdline: "C:\Users\user\Desktop\WizClient.exe" MD5: 51DC79AC2451E7AD8809D28EE07602B4)
    • WerFault.exe (PID: 5560 cmdline: C:\Windows\system32\WerFault.exe -u -p 6276 -s 2280 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • cleanup
{
  "C2 url": [
    "127.0.0.1"
  ],
  "Port": 2323,
  "Aes key": "<123456789>",
  "SPL": "<Xwormmm>",
  "Install file": "USB.exe"
}
SourceRuleDescriptionAuthorStrings
WizClient.exeJoeSecurity_XWormYara detected XWormJoe Security
    WizClient.exerat_win_xworm_v3Finds XWorm (version XClient, v3) samples based on characteristic stringsSekoia.io
    • 0x524f:$str01: $VB$Local_Port
    • 0x5240:$str02: $VB$Local_Host
    • 0x5462:$str03: get_Jpeg
    • 0x4f93:$str04: get_ServicePack
    • 0x5efa:$str05: Select * from AntivirusProduct
    • 0x601c:$str06: PCRestart
    • 0x6030:$str07: shutdown.exe /f /r /t 0
    • 0x60d0:$str08: StopReport
    • 0x60a6:$str09: StopDDos
    • 0x6116:$str10: sendPlugin
    • 0x6158:$str11: OfflineKeylogger Not Enabled
    • 0x62de:$str12: -ExecutionPolicy Bypass -File "
    • 0x6413:$str13: Content-length: 5235
    WizClient.exeMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
    • 0x64be:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
    • 0x655b:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
    • 0x6670:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
    • 0x632e:$cnc4: POST / HTTP/1.1
    SourceRuleDescriptionAuthorStrings
    00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_XWormYara detected XWormJoe Security
      00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmpMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
      • 0x62be:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
      • 0x635b:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
      • 0x6470:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
      • 0x612e:$cnc4: POST / HTTP/1.1
      Process Memory Space: WizClient.exe PID: 6276JoeSecurity_XWormYara detected XWormJoe Security
        SourceRuleDescriptionAuthorStrings
        0.0.WizClient.exe.7d0000.0.unpackJoeSecurity_XWormYara detected XWormJoe Security
          0.0.WizClient.exe.7d0000.0.unpackrat_win_xworm_v3Finds XWorm (version XClient, v3) samples based on characteristic stringsSekoia.io
          • 0x524f:$str01: $VB$Local_Port
          • 0x5240:$str02: $VB$Local_Host
          • 0x5462:$str03: get_Jpeg
          • 0x4f93:$str04: get_ServicePack
          • 0x5efa:$str05: Select * from AntivirusProduct
          • 0x601c:$str06: PCRestart
          • 0x6030:$str07: shutdown.exe /f /r /t 0
          • 0x60d0:$str08: StopReport
          • 0x60a6:$str09: StopDDos
          • 0x6116:$str10: sendPlugin
          • 0x6158:$str11: OfflineKeylogger Not Enabled
          • 0x62de:$str12: -ExecutionPolicy Bypass -File "
          • 0x6413:$str13: Content-length: 5235
          0.0.WizClient.exe.7d0000.0.unpackMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
          • 0x64be:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
          • 0x655b:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
          • 0x6670:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
          • 0x632e:$cnc4: POST / HTTP/1.1
          No Sigma rule has matched
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: WizClient.exeAvira: detected
          Source: WizClient.exeMalware Configuration Extractor: Xworm {"C2 url": ["127.0.0.1"], "Port": 2323, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe"}
          Source: WizClient.exeVirustotal: Detection: 76%Perma Link
          Source: WizClient.exeReversingLabs: Detection: 80%
          Source: Submited SampleNeural Call Log Analysis: 94.2%
          Source: WizClient.exeString decryptor: 127.0.0.1
          Source: WizClient.exeString decryptor: 2323
          Source: WizClient.exeString decryptor: <123456789>
          Source: WizClient.exeString decryptor: <Xwormmm>
          Source: WizClient.exeString decryptor: USB.exe
          Source: WizClient.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: unknownHTTPS traffic detected: 207.174.26.219:443 -> 192.168.2.7:49684 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 207.174.26.219:443 -> 192.168.2.7:49775 version: TLS 1.2
          Source: WizClient.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: Microsoft.VisualBasic.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Xml.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.ni.pdbRSDS source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.pdbzZ) source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.ni.pdbRSDS source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Xml.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: 0C:\Windows\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: System.Xml.ni.pdbRSDS# source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Core.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.pdb`J source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: Microsoft.VisualBasic.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.pdbWizClient.exe source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998953098.000000001BB14000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: System.pdbH source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Core.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.ni.pdbRSDScUN source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: symbols\dll\mscorlib.pdbpdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: indoC:\Windows\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: System.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Core.ni.pdbRSDS source: WERDC76.tmp.dmp.13.dr

          Networking

          barindex
          Source: Malware configuration extractorURLs: 127.0.0.1
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: Joe Sandbox ViewIP Address: 207.174.26.219 207.174.26.219
          Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficHTTP traffic detected: GET /Dwrj41N/Image.png HTTP/1.1Host: i.ibb.coConnection: Keep-Alive
          Source: global trafficDNS traffic detected: DNS query: i.ibb.co
          Source: WizClient.exe, 00000000.00000002.1997275209.0000000002DF1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://i.ibb.co
          Source: WizClient.exe, 00000000.00000002.1997275209.0000000002CD1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
          Source: Amcache.hve.13.drString found in binary or memory: http://upx.sf.net
          Source: WizClient.exe, 00000000.00000002.1997275209.0000000002CD1000.00000004.00000800.00020000.00000000.sdmp, WizClient.exe, 00000000.00000002.1997275209.0000000002D3A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://i.ibb.co
          Source: WizClient.exeString found in binary or memory: https://i.ibb.co/Dwrj41N/Image.png
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
          Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
          Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
          Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
          Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49687
          Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49685
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49684
          Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
          Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
          Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
          Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49685 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
          Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
          Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
          Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49684 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
          Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
          Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
          Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49687 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
          Source: unknownHTTPS traffic detected: 207.174.26.219:443 -> 192.168.2.7:49684 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 207.174.26.219:443 -> 192.168.2.7:49775 version: TLS 1.2

          System Summary

          barindex
          Source: WizClient.exe, type: SAMPLEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
          Source: WizClient.exe, type: SAMPLEMatched rule: Detects AsyncRAT Author: ditekSHen
          Source: 0.0.WizClient.exe.7d0000.0.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
          Source: 0.0.WizClient.exe.7d0000.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
          Source: 00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
          Source: C:\Users\user\Desktop\WizClient.exeCode function: 0_2_00007FFB9AA61AF50_2_00007FFB9AA61AF5
          Source: C:\Users\user\Desktop\WizClient.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6276 -s 2280
          Source: WizClient.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: WizClient.exe, type: SAMPLEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
          Source: WizClient.exe, type: SAMPLEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
          Source: 0.0.WizClient.exe.7d0000.0.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
          Source: 0.0.WizClient.exe.7d0000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
          Source: 00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
          Source: WizClient.exe, Helper.csCryptographic APIs: 'TransformFinalBlock'
          Source: WizClient.exe, Helper.csCryptographic APIs: 'TransformFinalBlock'
          Source: WizClient.exe, AlgorithmAES.csCryptographic APIs: 'TransformFinalBlock'
          Source: classification engineClassification label: mal100.troj.evad.winEXE@2/5@1/2
          Source: C:\Users\user\Desktop\WizClient.exeMutant created: NULL
          Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6276
          Source: C:\Users\user\Desktop\WizClient.exeMutant created: \Sessions\1\BaseNamedObjects\R22i88TmQC829Rvr
          Source: C:\Windows\System32\WerFault.exeFile created: C:\ProgramData\Microsoft\Windows\WER\Temp\01e079df-7a01-40fc-a17b-f03cfbc7dc95Jump to behavior
          Source: WizClient.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: WizClient.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
          Source: C:\Users\user\Desktop\WizClient.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: WizClient.exeVirustotal: Detection: 76%
          Source: WizClient.exeReversingLabs: Detection: 80%
          Source: C:\Users\user\Desktop\WizClient.exeFile read: C:\Users\user\Desktop\WizClient.exeJump to behavior
          Source: unknownProcess created: C:\Users\user\Desktop\WizClient.exe "C:\Users\user\Desktop\WizClient.exe"
          Source: C:\Users\user\Desktop\WizClient.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6276 -s 2280
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: mscoree.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: version.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: rasapi32.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: rasman.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: rtutils.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: dhcpcsvc6.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: dhcpcsvc.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: secur32.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
          Source: WizClient.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: WizClient.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: Microsoft.VisualBasic.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Xml.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.ni.pdbRSDS source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.pdbzZ) source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.ni.pdbRSDS source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Xml.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: 0C:\Windows\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: System.Xml.ni.pdbRSDS# source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Core.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.pdb`J source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: Microsoft.VisualBasic.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.pdbWizClient.exe source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998953098.000000001BB14000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: System.pdbH source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Drawing.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: mscorlib.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Core.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Configuration.ni.pdbRSDScUN source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: symbols\dll\mscorlib.pdbpdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: indoC:\Windows\mscorlib.pdb source: WizClient.exe, 00000000.00000002.1998771647.000000001B588000.00000004.00000010.00020000.00000000.sdmp
          Source: Binary string: System.ni.pdb source: WERDC76.tmp.dmp.13.dr
          Source: Binary string: System.Core.ni.pdbRSDS source: WERDC76.tmp.dmp.13.dr

          Data Obfuscation

          barindex
          Source: WizClient.exe, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
          Source: WizClient.exe, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
          Source: WizClient.exe, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[1] { Pack[2] }}, (string[])null, (Type[])null, (bool[])null, true)
          Source: WizClient.exe, Helper.cs.Net Code: XMemory System.AppDomain.Load(byte[])
          Source: WizClient.exe, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
          Source: WizClient.exe, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
          Source: WizClient.exe, Messages.cs.Net Code: Memory
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeMemory allocated: F10000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeMemory allocated: 1ACD0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 600000Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599891Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599750Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599641Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599500Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599391Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599277Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599163Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599047Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598834Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598719Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598609Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598500Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598391Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598250Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598141Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598031Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597922Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597813Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597704Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597579Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597469Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597344Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597235Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597110Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596985Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596860Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596735Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596610Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596467Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596359Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596224Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596077Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595953Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595844Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595719Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595610Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595485Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595360Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595235Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595110Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594985Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594860Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594735Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594610Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594485Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594360Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594235Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594110Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 593985Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 593860Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeWindow / User API: threadDelayed 7992Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeWindow / User API: threadDelayed 1818Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep count: 35 > 30Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -32281802128991695s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -600000s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599891s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6640Thread sleep count: 7992 > 30Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6640Thread sleep count: 1818 > 30Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599750s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599641s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599500s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599391s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599277s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599163s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -599047s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598834s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598719s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598609s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598500s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598391s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598250s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598141s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -598031s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597922s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597813s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597704s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597579s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597469s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597344s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597235s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -597110s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596985s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596860s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596735s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596610s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596467s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596359s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596224s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -596077s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595953s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595844s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595719s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595610s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595485s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595360s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595235s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -595110s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594985s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594860s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594735s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594610s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594485s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594360s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594235s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -594110s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -593985s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exe TID: 6660Thread sleep time: -593860s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 600000Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599891Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599750Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599641Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599500Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599391Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599277Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599163Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 599047Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598834Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598719Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598609Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598500Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598391Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598250Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598141Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 598031Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597922Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597813Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597704Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597579Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597469Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597344Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597235Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 597110Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596985Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596860Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596735Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596610Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596467Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596359Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596224Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 596077Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595953Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595844Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595719Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595610Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595485Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595360Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595235Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 595110Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594985Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594860Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594735Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594610Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594485Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594360Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594235Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 594110Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 593985Jump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeThread delayed: delay time: 593860Jump to behavior
          Source: Amcache.hve.13.drBinary or memory string: VMware
          Source: Amcache.hve.13.drBinary or memory string: VMware Virtual USB Mouse
          Source: Amcache.hve.13.drBinary or memory string: vmci.syshbin
          Source: Amcache.hve.13.drBinary or memory string: VMware, Inc.
          Source: Amcache.hve.13.drBinary or memory string: VMware20,1hbin@
          Source: Amcache.hve.13.drBinary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
          Source: Amcache.hve.13.drBinary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
          Source: Amcache.hve.13.drBinary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
          Source: Amcache.hve.13.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
          Source: Amcache.hve.13.drBinary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
          Source: Amcache.hve.13.drBinary or memory string: c:/windows/system32/drivers/vmci.sys
          Source: Amcache.hve.13.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
          Source: WizClient.exe, 00000000.00000002.1996643212.0000000000CD1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
          Source: Amcache.hve.13.drBinary or memory string: vmci.sys
          Source: Amcache.hve.13.drBinary or memory string: vmci.syshbin`
          Source: Amcache.hve.13.drBinary or memory string: \driver\vmci,\driver\pci
          Source: Amcache.hve.13.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
          Source: Amcache.hve.13.drBinary or memory string: VMware20,1
          Source: Amcache.hve.13.drBinary or memory string: Microsoft Hyper-V Generation Counter
          Source: Amcache.hve.13.drBinary or memory string: NECVMWar VMware SATA CD00
          Source: Amcache.hve.13.drBinary or memory string: VMware Virtual disk SCSI Disk Device
          Source: Amcache.hve.13.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
          Source: Amcache.hve.13.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
          Source: Amcache.hve.13.drBinary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
          Source: Amcache.hve.13.drBinary or memory string: VMware PCI VMCI Bus Device
          Source: Amcache.hve.13.drBinary or memory string: VMware VMCI Bus Device
          Source: Amcache.hve.13.drBinary or memory string: VMware Virtual RAM
          Source: Amcache.hve.13.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
          Source: Amcache.hve.13.drBinary or memory string: VMware-42 27 88 19 56 cc 59 1a-97 79 fb 8c bf a1 e2 9d
          Source: Amcache.hve.13.drBinary or memory string: vmci.inf_amd64_68ed49469341f563
          Source: C:\Users\user\Desktop\WizClient.exeProcess queried: DebugPortJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess queried: DebugPortJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeProcess token adjusted: DebugJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeMemory allocated: page read and write | page guardJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeQueries volume information: C:\Users\user\Desktop\WizClient.exe VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\WizClient.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
          Source: Amcache.hve.13.drBinary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
          Source: Amcache.hve.13.drBinary or memory string: msmpeng.exe
          Source: Amcache.hve.13.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
          Source: Amcache.hve.13.drBinary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23090.2008-0\msmpeng.exe
          Source: Amcache.hve.13.drBinary or memory string: MsMpEng.exe

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: WizClient.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.WizClient.exe.7d0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: WizClient.exe PID: 6276, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: WizClient.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.WizClient.exe.7d0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: WizClient.exe PID: 6276, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
          DLL Side-Loading
          1
          Process Injection
          1
          Disable or Modify Tools
          OS Credential Dumping21
          Security Software Discovery
          Remote Services11
          Archive Collected Data
          11
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
          DLL Side-Loading
          41
          Virtualization/Sandbox Evasion
          LSASS Memory41
          Virtualization/Sandbox Evasion
          Remote Desktop ProtocolData from Removable Media1
          Ingress Tool Transfer
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
          Process Injection
          Security Account Manager1
          Application Window Discovery
          SMB/Windows Admin SharesData from Network Shared Drive2
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
          Deobfuscate/Decode Files or Information
          NTDS13
          System Information Discovery
          Distributed Component Object ModelInput Capture13
          Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
          Software Packing
          LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
          DLL Side-Loading
          Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1652216 Sample: WizClient.exe Startdate: 30/03/2025 Architecture: WINDOWS Score: 100 15 i.ibb.co 2->15 21 Found malware configuration 2->21 23 Malicious sample detected (through community Yara rule) 2->23 25 Antivirus / Scanner detection for submitted sample 2->25 27 7 other signatures 2->27 7 WizClient.exe 14 2 2->7         started        signatures3 process4 dnsIp5 17 127.0.0.1 unknown unknown 7->17 19 i.ibb.co 207.174.26.219, 443, 49684, 49685 RCN-ASUS United States 7->19 10 WerFault.exe 19 16 7->10         started        process6 file7 13 C:\ProgramData\Microsoft\...\Report.wer, Unicode 10->13 dropped

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          WizClient.exe76%VirustotalBrowse
          WizClient.exe81%ReversingLabsByteCode-MSIL.Trojan.Jalapeno
          WizClient.exe100%AviraHEUR/AGEN.1305769
          SAMPLE100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches

          Download Network PCAP: filteredfull

          NameIPActiveMaliciousAntivirus DetectionReputation
          i.ibb.co
          207.174.26.219
          truefalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://i.ibb.co/Dwrj41N/Image.pngfalse
              high
              127.0.0.1false
                high
                NameSourceMaliciousAntivirus DetectionReputation
                http://upx.sf.netAmcache.hve.13.drfalse
                  high
                  https://i.ibb.coWizClient.exe, 00000000.00000002.1997275209.0000000002CD1000.00000004.00000800.00020000.00000000.sdmp, WizClient.exe, 00000000.00000002.1997275209.0000000002D3A000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://i.ibb.coWizClient.exe, 00000000.00000002.1997275209.0000000002DF1000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameWizClient.exe, 00000000.00000002.1997275209.0000000002CD1000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        207.174.26.219
                        i.ibb.coUnited States
                        6079RCN-ASUSfalse
                        IP
                        127.0.0.1
                        Joe Sandbox version:42.0.0 Malachite
                        Analysis ID:1652216
                        Start date and time:2025-03-30 18:03:05 +02:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 4m 39s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:default.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:15
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Sample name:WizClient.exe
                        Detection:MAL
                        Classification:mal100.troj.evad.winEXE@2/5@1/2
                        EGA Information:Failed
                        HCA Information:
                        • Successful, ratio: 100%
                        • Number of executed functions: 22
                        • Number of non-executed functions: 0
                        Cookbook Comments:
                        • Found application associated with file extension: .exe
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, sppsvc.exe, WerFault.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                        • Excluded IPs from analysis (whitelisted): 20.189.173.22, 4.175.87.197, 23.204.23.20, 20.190.190.131
                        • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, login.live.com, blobcollector.events.data.trafficmanager.net, onedsblobprdwus17.westus.cloudapp.azure.com, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
                        • Execution Graph export aborted for target WizClient.exe, PID 6276 because it is empty
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        • Report size getting too big, too many NtReadVirtualMemory calls found.
                        • Report size getting too big, too many NtSetInformationFile calls found.
                        TimeTypeDescription
                        12:04:10API Interceptor2390797x Sleep call for process: WizClient.exe modified
                        12:05:53API Interceptor1x Sleep call for process: WerFault.exe modified
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        207.174.26.219XC.exeGet hashmaliciousXWormBrowse
                          FINAL -Legal Notice Presentation (1).pptxGet hashmaliciousHTMLPhisherBrowse
                            Formal Legal Notice Presentation (Approved).pptxGet hashmaliciousHTMLPhisherBrowse
                              Presentation Of Legal Notice.pptxGet hashmaliciousHTMLPhisherBrowse
                                Filled-Summons Notice (2).docxGet hashmaliciousHTMLPhisherBrowse
                                  Legal_Notice _Letter.pdfGet hashmaliciousHTMLPhisherBrowse
                                    https://ossin7fot.pelosfilhos.com.br?hbyf=YW5nZWxhLm0ucm9lbGxAeGNlbGVuZXJneS5jb20=Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                      25 03 2025 Legal Notice Presentation.pptxGet hashmaliciousUnknownBrowse
                                        https://drive.usercontent.google.com/download?id=1D-lVkrj-b014caeCIdakZBdw2yekeEO1&export=downloadGet hashmaliciousHTMLPhisherBrowse
                                          https://medpetroenergydmcc.com/court/Get hashmaliciousHTMLPhisherBrowse
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            i.ibb.coXC.exeGet hashmaliciousXWormBrowse
                                            • 207.174.26.219
                                            FINAL -Legal Notice Presentation (1).pptxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            Formal Legal Notice Presentation (Approved).pptxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            Presentation Of Legal Notice.pptxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            Filled-Summons Notice (2).docxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            Legal_Notice _Letter.pdfGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            https://ossin7fot.pelosfilhos.com.br?hbyf=YW5nZWxhLm0ucm9lbGxAeGNlbGVuZXJneS5jb20=Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                            • 207.174.26.219
                                            25 03 2025 Legal Notice Presentation.pptxGet hashmaliciousUnknownBrowse
                                            • 207.174.26.219
                                            25 03 2025 Legal Notice Presentation.pptxGet hashmaliciousUnknownBrowse
                                            • 108.181.22.211
                                            https://drive.usercontent.google.com/download?id=1D-lVkrj-b014caeCIdakZBdw2yekeEO1&export=downloadGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            RCN-ASUSXC.exeGet hashmaliciousXWormBrowse
                                            • 207.174.26.219
                                            FINAL -Legal Notice Presentation (1).pptxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            Formal Legal Notice Presentation (Approved).pptxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            k03ldc.arm.elfGet hashmaliciousUnknownBrowse
                                            • 208.59.25.232
                                            k03ldc.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 207.175.27.218
                                            Presentation Of Legal Notice.pptxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            core.vapvapGet hashmaliciousUnknownBrowse
                                            • 207.174.61.1
                                            Filled-Summons Notice (2).docxGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            Legal_Notice _Letter.pdfGet hashmaliciousHTMLPhisherBrowse
                                            • 207.174.26.219
                                            https://ossin7fot.pelosfilhos.com.br?hbyf=YW5nZWxhLm0ucm9lbGxAeGNlbGVuZXJneS5jb20=Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                            • 207.174.26.219
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            3b5074b1b5d032e5620f69f9f700ff0eXC.exeGet hashmaliciousXWormBrowse
                                            • 207.174.26.219
                                            FvkRadar Intel.exeGet hashmaliciousXWormBrowse
                                            • 207.174.26.219
                                            nursultan_fix.exeGet hashmaliciousXWormBrowse
                                            • 207.174.26.219
                                            AVCXw0587P.exeGet hashmaliciousAmadey, Babadeda, Batch InjectorBrowse
                                            • 207.174.26.219
                                            JetProgram.exeGet hashmaliciousXmrigBrowse
                                            • 207.174.26.219
                                            LU3J3mZT5y.exeGet hashmaliciousLummaC StealerBrowse
                                            • 207.174.26.219
                                            RuntimeBroker.exeGet hashmaliciousUnknownBrowse
                                            • 207.174.26.219
                                            RuntimeBroker.exeGet hashmaliciousUnknownBrowse
                                            • 207.174.26.219
                                            climb.exeGet hashmaliciousLummaC StealerBrowse
                                            • 207.174.26.219
                                            t3333-03-2825.batGet hashmaliciousBraodoBrowse
                                            • 207.174.26.219
                                            No context
                                            Process:C:\Windows\System32\WerFault.exe
                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                            Category:dropped
                                            Size (bytes):65536
                                            Entropy (8bit):1.188254775015482
                                            Encrypted:false
                                            SSDEEP:192:3YmEkez0SthpaWz8iyrelhESzuiFVZ24lO8Wjx:PEkpSthpa48iNiSzuiFVY4lO8WV
                                            MD5:536314B3C9587917722C62FB9F502263
                                            SHA1:A05D212670F59CBFB087F912F3F96ADE81A29B9C
                                            SHA-256:3EE31D831063607C87E9247EA8ADD8710C2A9C080BA3C60181D89CB868D6534B
                                            SHA-512:79B9C461358FE27E3C0CFAB6385C8859A36DC9D8FA864C18FC0DA3A3736557B1D404F5F3DF239B8170AF00B3947A3ED1C79BDDC57E3113464D7E8EC39E9C072A
                                            Malicious:true
                                            Reputation:low
                                            Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.C.L.R.2.0.r.3.....E.v.e.n.t.T.i.m.e.=.1.3.3.8.7.8.2.4.3.4.9.6.1.4.1.1.7.4.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.8.7.8.2.4.3.5.0.8.6.4.1.1.7.0.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.5.5.e.6.a.8.8.2.-.5.0.c.0.-.4.a.2.8.-.b.8.7.7.-.4.2.a.8.4.1.f.3.b.a.d.5.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.1.1.5.9.b.2.d.4.-.7.f.7.5.-.4.3.1.7.-.8.0.0.0.-.8.4.8.3.5.d.3.6.f.a.f.c.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....N.s.A.p.p.N.a.m.e.=.W.i.z.C.l.i.e.n.t...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.W.i.z.C.l.i.e.n.t...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.8.8.4.-.0.0.0.1.-.0.0.1.8.-.9.0.9.3.-.c.c.5.d.8.d.a.1.d.b.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.6.c.e.2.6.8.4.b.a.f.a.3.f.c.d.a.b.1.4.6.8.2.6.5.1.2.0.8.6.f.4.7.4.0.0.0.0.0.0.0.0.!.0.0.0.0.3.7.a.4.e.f.a.2.1.c.4.a.9.8.a.4.5.b.7.5.c.8.b.6.0.3.7.b.c.8.d.7.1.9.c.d.f.4.5.e.!.W.i.z.C.l.i.e.n.t...e.
                                            Process:C:\Windows\System32\WerFault.exe
                                            File Type:Mini DuMP crash report, 16 streams, Sun Mar 30 16:05:49 2025, 0x1205a4 type
                                            Category:dropped
                                            Size (bytes):605220
                                            Entropy (8bit):3.218995659726747
                                            Encrypted:false
                                            SSDEEP:3072:7YBfHYRQ+mRTsHpQ5iY1CCqdTH/33+vt8QoVmfyBOXpIymdSZevXdiW54vrylgcC:7qvH+A4zWqh/33Qt8hdiYerwsHLE
                                            MD5:FB9B2DFA8EAB144AC1D4FCA4382490D0
                                            SHA1:BB8CFFEED821B7875A7705C873DA97954836B98E
                                            SHA-256:48552A3E776CDAB40DEA868D7AA9A25E41CB3FF928EDF35770AD2FD4F55C27F2
                                            SHA-512:DDF7D272DC7131B01250F015BA20176C1A950DB244C0F23332DF422EBBCAEFE00785B8D593E88C04F9C8C4185945BAA79706E6F0B4DE2320E9CF1759ABA1F416
                                            Malicious:false
                                            Reputation:low
                                            Preview:MDMP..a..... ........k.g....................................<...p(...........(......tQ..............l.......8...........T............W..l............3...........5..............................................................................eJ......$6......Lw......................T...........wk.g.............................0..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................
                                            Process:C:\Windows\System32\WerFault.exe
                                            File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                            Category:dropped
                                            Size (bytes):8906
                                            Entropy (8bit):3.697849072179655
                                            Encrypted:false
                                            SSDEEP:192:R6l7wVeJxjDqcwa6Y+AxyOipgmfZIBprs89bAb0f57Am:R6lXJ1DqU6YZzipgmfClA4fH
                                            MD5:9B9B960E1E1C5A37E60CB2DFAEF35249
                                            SHA1:9E5D78DA98DB14ACD3AC120D2EAA7103A60D51A1
                                            SHA-256:C210C3ED0E36B00231A7E03E4DAC41C83C0DE520F74060F6924E796D469219FC
                                            SHA-512:7BA0582FC7ADB0DA7F3A5A116802CD241EA2C3AFDA53A942E5D01AE723E5F19E1F41F76F8526935B8D4A717F71BFF5434EFB3D238B0748A5E1258C36DBD86956
                                            Malicious:false
                                            Reputation:low
                                            Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.9.0.4.5.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.9.0.4.1...2.0.0.6...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.2.0.0.6.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.2.0.5.7.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.6.2.7.6.<./.P.i.
                                            Process:C:\Windows\System32\WerFault.exe
                                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                            Category:dropped
                                            Size (bytes):4781
                                            Entropy (8bit):4.452582001296201
                                            Encrypted:false
                                            SSDEEP:48:cvIwWl8zsTzJg771I9f8WpW8VYfYm8M4J+BFwyq8vpZhQVeEd:uIjfTNI7Y17VnJLWbhQoEd
                                            MD5:08589C9772CF511AB9030E976977540E
                                            SHA1:A4431848830122DD559C139904321402C18F3104
                                            SHA-256:E7E3FB1D5BB85DA6BBD539E423C0D33B660F6AB4901C40ED59E88154CF4EF7A1
                                            SHA-512:FB74110BADAA0125A6D6EFF3C3C5191C8DBF1A2592B55E972C5FBC49B10DCF7FCFEC424C80C6DAC8D1E5CBAD09E78857FD5776FC38749FCEFC3CCE4D7ED880EF
                                            Malicious:false
                                            Reputation:low
                                            Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="19045" />.. <arg nm="vercsdbld" val="2006" />.. <arg nm="verqfe" val="2006" />.. <arg nm="csdbld" val="2006" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="2057" />.. <arg nm="geoid" val="223" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="783788" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.789.19041.0-11.0.1000" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="409
                                            Process:C:\Windows\System32\WerFault.exe
                                            File Type:MS Windows registry file, NT/2000 or above
                                            Category:dropped
                                            Size (bytes):1835008
                                            Entropy (8bit):4.419954234821631
                                            Encrypted:false
                                            SSDEEP:6144:jcifpi6ceLPL9skLmb0mgSWSPtaJG8nAgex285i2MMhA20X4WABlUuNT5+7:Yi58gSWIZBk2MM6AFn9o
                                            MD5:9A3F7C6C59DF1C3BC1B67DA443B5C614
                                            SHA1:FBB1054C47668376D49399D89D250236D633FE15
                                            SHA-256:F607E13BBBC985F6A43F437B2508FF337597FB852E41AFC084BD7EF48127EE27
                                            SHA-512:25270B039F150A2A6FF644E4A09074EFEC2C34840673D81AEA30EE5B8C839B10BE535A80A90D39CED96550978D42B03C335C53BD7BA088B484CE29D437A1C335
                                            Malicious:false
                                            Reputation:low
                                            Preview:regfH...H....\.Z.................... ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e....c...b...#.......c...b...#...........c...b...#......rmtm6..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                            File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                            Entropy (8bit):5.598583777406854
                                            TrID:
                                            • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                                            • Win32 Executable (generic) a (10002005/4) 49.75%
                                            • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                            • Windows Screen Saver (13104/52) 0.07%
                                            • Generic Win/DOS Executable (2004/3) 0.01%
                                            File name:WizClient.exe
                                            File size:31'232 bytes
                                            MD5:51dc79ac2451e7ad8809d28ee07602b4
                                            SHA1:37a4efa21c4a98a45b75c8b6037bc8d719cdf45e
                                            SHA256:dcbc3e96c538390d213875789f30feaeec238a512fc32b19e8f2c1216b89ad4c
                                            SHA512:6e737cb3b034a4f7979b99614adbd71d9fab76b4397501f165815bcf1646dd763fe7ea9544a3c66a1967ba80598bf2287ee0cd53d6cbeaebd8ad25abdeeeb65a
                                            SSDEEP:384:N2458Ytf+1mOEUehuzD2LZX01uYTEXXQmRuptFlBLTIOZw/W2Zvn9Ikn1W2kxOq8:9+1mOE1yG6u4QAm0FG9L4nOqhFbg
                                            TLSH:1AE23B487BA88326D6FE1FF219B3910102749513E913EF9F4CD595EB6B6BAC046013EA
                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....O.g.................p............... ........@.. ....................................@................................
                                            Icon Hash:90cececece8e8eb0
                                            Entrypoint:0x408fce
                                            Entrypoint Section:.text
                                            Digitally signed:false
                                            Imagebase:0x400000
                                            Subsystem:windows gui
                                            Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                            Time Stamp:0x67E94F90 [Sun Mar 30 14:05:04 2025 UTC]
                                            TLS Callbacks:
                                            CLR (.Net) Version:
                                            OS Version Major:4
                                            OS Version Minor:0
                                            File Version Major:4
                                            File Version Minor:0
                                            Subsystem Version Major:4
                                            Subsystem Version Minor:0
                                            Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                            Instruction
                                            jmp dword ptr [00402000h]
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x8f780x53.text
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0xa0000x4e0.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0xc0000xc.reloc
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            .text0x20000x6fd40x70006ec5d5c0e42371ad4d5899e55b79bb0eFalse0.5057896205357143data5.760275569586321IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                            .rsrc0xa0000x4e00x600235e94540ed2bb03f2399871a29cec24False0.376953125data3.7387328467315477IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .reloc0xc0000xc0x20031ca38b3f46e1c56e0678c2fc19748f8False0.044921875data0.08153941234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                            RT_VERSION0xa0a00x24cdata0.47619047619047616
                                            RT_MANIFEST0xa2f00x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5469387755102041
                                            DLLImport
                                            mscoree.dll_CorExeMain
                                            DescriptionData
                                            Translation0x0000 0x04b0
                                            FileDescription
                                            FileVersion1.0.0.0
                                            InternalNameWizClient.exe
                                            LegalCopyright
                                            OriginalFilenameWizClient.exe
                                            ProductVersion1.0.0.0
                                            Assembly Version1.0.0.0

                                            Download Network PCAP: filteredfull

                                            • Total Packets: 317
                                            • 443 (HTTPS)
                                            • 53 (DNS)
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 30, 2025 18:04:17.673163891 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:17.673202991 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:17.673337936 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:17.692189932 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:17.692220926 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:17.915535927 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:17.915741920 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:17.921082020 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:17.921097994 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:17.921354055 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:17.974210978 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:17.987999916 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.032272100 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.119215012 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.119268894 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.119395971 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.179507017 CEST49684443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.179543972 CEST44349684207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.184154987 CEST49685443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.184201956 CEST44349685207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.184264898 CEST49685443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.184787035 CEST49685443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.184801102 CEST44349685207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.394051075 CEST44349685207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.397830009 CEST49685443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.397855043 CEST44349685207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.601603031 CEST44349685207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.601665020 CEST44349685207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:18.601728916 CEST49685443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.602255106 CEST49685443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:18.602272034 CEST44349685207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:20.615942955 CEST49687443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:20.615998030 CEST44349687207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:20.616117954 CEST49687443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:20.616400003 CEST49687443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:20.616413116 CEST44349687207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:20.822911024 CEST44349687207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:20.824234962 CEST49687443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:20.824273109 CEST44349687207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.033524990 CEST44349687207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.033615112 CEST44349687207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.033721924 CEST49687443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.034224987 CEST49687443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.034241915 CEST44349687207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.035322905 CEST49688443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.035370111 CEST44349688207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.035444975 CEST49688443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.035706997 CEST49688443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.035713911 CEST44349688207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.255697012 CEST44349688207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.258517027 CEST49688443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.258548021 CEST44349688207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.456410885 CEST44349688207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.456518888 CEST44349688207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:21.456602097 CEST49688443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.457154989 CEST49688443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:21.457175970 CEST44349688207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:23.460273981 CEST49689443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:23.460323095 CEST44349689207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:23.460428953 CEST49689443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:23.460892916 CEST49689443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:23.460906982 CEST44349689207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.383944035 CEST44349689207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.385226965 CEST49689443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:24.385251999 CEST44349689207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.590948105 CEST44349689207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.591008902 CEST44349689207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.591064930 CEST49689443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:24.652394056 CEST49689443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:24.652416945 CEST44349689207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.653264046 CEST49690443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:24.653304100 CEST44349690207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.653389931 CEST49690443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:24.653623104 CEST49690443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:24.653640985 CEST44349690207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.871927023 CEST44349690207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:24.881068945 CEST49690443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:24.881088972 CEST44349690207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:25.080022097 CEST44349690207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:25.080075979 CEST44349690207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:25.080209017 CEST49690443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:25.080815077 CEST49690443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:25.080837011 CEST44349690207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.084832907 CEST49693443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.084871054 CEST44349693207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.085019112 CEST49693443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.085342884 CEST49693443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.085357904 CEST44349693207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.298055887 CEST44349693207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.299992085 CEST49693443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.300015926 CEST44349693207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.504550934 CEST44349693207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.504615068 CEST44349693207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.504743099 CEST49693443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.505143881 CEST49693443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.505163908 CEST44349693207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.506323099 CEST49694443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.506376028 CEST44349694207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:27.506447077 CEST49694443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.506767035 CEST49694443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:27.506783009 CEST44349694207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:28.720325947 CEST44349694207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:28.721766949 CEST49694443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:28.721791029 CEST44349694207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:29.280065060 CEST44349694207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:29.280122995 CEST44349694207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:29.280168056 CEST49694443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:29.280747890 CEST49694443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:29.280766964 CEST44349694207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:31.289418936 CEST49701443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:31.289467096 CEST44349701207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:31.289560080 CEST49701443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:31.289853096 CEST49701443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:31.289865017 CEST44349701207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:31.929954052 CEST44349701207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:31.939717054 CEST49701443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:31.939728975 CEST44349701207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.143419027 CEST44349701207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.143485069 CEST44349701207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.143570900 CEST49701443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:32.144095898 CEST49701443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:32.144114971 CEST44349701207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.145222902 CEST49702443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:32.145334959 CEST44349702207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.145448923 CEST49702443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:32.145658016 CEST49702443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:32.145690918 CEST44349702207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.352907896 CEST44349702207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.354593992 CEST49702443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:32.354619980 CEST44349702207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.558614016 CEST44349702207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.558681011 CEST44349702207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.559202909 CEST49702443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:32.559274912 CEST44349702207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:32.559315920 CEST49702443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:34.569626093 CEST49704443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:34.569678068 CEST44349704207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:34.569737911 CEST49704443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:34.570342064 CEST49704443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:34.570365906 CEST44349704207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:34.784703970 CEST44349704207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:34.786119938 CEST49704443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:34.786156893 CEST44349704207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.001564980 CEST44349704207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.001625061 CEST44349704207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.001724958 CEST49704443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.002182007 CEST49704443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.002219915 CEST44349704207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.003362894 CEST49705443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.003406048 CEST44349705207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.003493071 CEST49705443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.003730059 CEST49705443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.003743887 CEST44349705207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.220841885 CEST44349705207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.222374916 CEST49705443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.222398996 CEST44349705207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.803325891 CEST44349705207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.803392887 CEST44349705207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:35.803441048 CEST49705443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.803940058 CEST49705443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:35.803956032 CEST44349705207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:37.819183111 CEST49710443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:37.819257975 CEST44349710207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:37.819361925 CEST49710443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:37.819628000 CEST49710443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:37.819643974 CEST44349710207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:39.714845896 CEST44349710207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:39.716262102 CEST49710443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:39.716293097 CEST44349710207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:39.920748949 CEST44349710207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:39.920804977 CEST44349710207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:39.920881987 CEST49710443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:39.921363115 CEST49710443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:39.921385050 CEST44349710207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:39.922607899 CEST49713443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:39.922645092 CEST44349713207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:39.922739029 CEST49713443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:39.922961950 CEST49713443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:39.922976017 CEST44349713207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:40.129374027 CEST44349713207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:40.130836010 CEST49713443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:40.130858898 CEST44349713207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:40.331583977 CEST44349713207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:40.331639051 CEST44349713207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:40.331681967 CEST49713443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:40.332163095 CEST49713443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:40.332176924 CEST44349713207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.336349964 CEST49717443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.336394072 CEST44349717207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.336520910 CEST49717443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.337030888 CEST49717443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.337044954 CEST44349717207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.545840025 CEST44349717207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.547354937 CEST49717443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.547364950 CEST44349717207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.752444029 CEST44349717207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.752506018 CEST44349717207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.752556086 CEST49717443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.753072023 CEST49717443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.753086090 CEST44349717207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.754185915 CEST49718443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.754225969 CEST44349718207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:42.754301071 CEST49718443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.754579067 CEST49718443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:42.754590034 CEST44349718207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:43.370428085 CEST44349718207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:43.371778011 CEST49718443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:43.371798992 CEST44349718207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:43.576544046 CEST44349718207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:43.576612949 CEST44349718207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:43.576931953 CEST49718443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:43.577069044 CEST49718443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:43.577091932 CEST44349718207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:45.622059107 CEST49720443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:45.622128010 CEST44349720207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:45.622313023 CEST49720443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:45.622755051 CEST49720443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:45.622776031 CEST44349720207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:45.832626104 CEST44349720207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:45.839829922 CEST49720443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:45.839864969 CEST44349720207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.041433096 CEST44349720207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.041502953 CEST44349720207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.041569948 CEST49720443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.042027950 CEST49720443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.042049885 CEST44349720207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.043034077 CEST49722443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.043080091 CEST44349722207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.043195009 CEST49722443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.043457031 CEST49722443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.043472052 CEST44349722207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.248925924 CEST44349722207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.250418901 CEST49722443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.250443935 CEST44349722207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.767703056 CEST44349722207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.767767906 CEST44349722207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:46.768013000 CEST49722443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.768625021 CEST49722443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:46.768646002 CEST44349722207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:48.772996902 CEST49724443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:48.773051023 CEST44349724207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:48.773124933 CEST49724443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:48.773505926 CEST49724443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:48.773516893 CEST44349724207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:48.983617067 CEST44349724207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:48.985091925 CEST49724443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:48.985127926 CEST44349724207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.191389084 CEST44349724207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.191448927 CEST44349724207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.191498995 CEST49724443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.192078114 CEST49724443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.192094088 CEST44349724207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.193397045 CEST49725443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.193434000 CEST44349725207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.193512917 CEST49725443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.193778992 CEST49725443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.193794966 CEST44349725207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.407793999 CEST44349725207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.409394979 CEST49725443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.409434080 CEST44349725207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.620815039 CEST44349725207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.620868921 CEST44349725207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:49.621017933 CEST49725443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.621412992 CEST49725443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:49.621428967 CEST44349725207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:51.631818056 CEST49726443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:51.631866932 CEST44349726207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:51.632105112 CEST49726443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:51.632405043 CEST49726443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:51.632421970 CEST44349726207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:51.846779108 CEST44349726207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:51.848418951 CEST49726443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:51.848439932 CEST44349726207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.062406063 CEST44349726207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.062453032 CEST44349726207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.062591076 CEST49726443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.063138008 CEST49726443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.063154936 CEST44349726207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.064634085 CEST49727443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.064680099 CEST44349727207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.064807892 CEST49727443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.065018892 CEST49727443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.065032005 CEST44349727207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.276380062 CEST44349727207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.277935982 CEST49727443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.277964115 CEST44349727207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.852157116 CEST44349727207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.852209091 CEST44349727207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:52.852267981 CEST49727443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.852699995 CEST49727443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:52.852720022 CEST44349727207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:54.865987062 CEST49730443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:54.866030931 CEST44349730207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:54.866139889 CEST49730443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:54.866444111 CEST49730443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:54.866466045 CEST44349730207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:55.080588102 CEST44349730207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:55.082138062 CEST49730443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:55.082159996 CEST44349730207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:55.307574987 CEST44349730207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:55.307640076 CEST44349730207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:55.307854891 CEST49730443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:55.308367968 CEST49730443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:55.308387041 CEST44349730207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:55.309463024 CEST49731443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:55.309519053 CEST44349731207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:55.309617996 CEST49731443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:55.309834957 CEST49731443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:55.309849024 CEST44349731207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:56.533096075 CEST44349731207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:56.534792900 CEST49731443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:56.534818888 CEST44349731207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:56.745934010 CEST44349731207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:56.745995045 CEST44349731207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:56.746134996 CEST49731443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:56.752371073 CEST49731443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:56.752392054 CEST44349731207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:58.756645918 CEST49734443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:58.756689072 CEST44349734207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:58.756776094 CEST49734443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:58.757044077 CEST49734443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:58.757060051 CEST44349734207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:58.969472885 CEST44349734207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:58.970988989 CEST49734443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:58.971002102 CEST44349734207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:59.805560112 CEST44349734207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:59.805620909 CEST44349734207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:59.805727959 CEST49734443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:59.866060972 CEST49734443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:59.866087914 CEST44349734207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:59.867005110 CEST49735443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:59.867052078 CEST44349735207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:04:59.867157936 CEST49735443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:59.867353916 CEST49735443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:04:59.867364883 CEST44349735207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:00.073111057 CEST44349735207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:00.079651117 CEST49735443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:00.079659939 CEST44349735207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:00.712165117 CEST44349735207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:00.712239027 CEST44349735207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:00.712342978 CEST49735443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:00.712729931 CEST49735443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:00.712748051 CEST44349735207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:02.732656002 CEST49738443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:02.732723951 CEST44349738207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:02.732817888 CEST49738443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:02.733153105 CEST49738443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:02.733172894 CEST44349738207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:02.940393925 CEST44349738207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:02.941768885 CEST49738443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:02.941809893 CEST44349738207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:03.157448053 CEST44349738207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:03.157530069 CEST44349738207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:03.157732964 CEST49738443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:03.158152103 CEST49738443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:03.158169031 CEST44349738207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:03.159336090 CEST49739443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:03.159390926 CEST44349739207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:03.159465075 CEST49739443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:03.159698963 CEST49739443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:03.159719944 CEST44349739207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:04.014348030 CEST44349739207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:04.015760899 CEST49739443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:04.015782118 CEST44349739207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:04.903966904 CEST44349739207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:04.904042959 CEST44349739207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:04.904186010 CEST49739443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:04.904506922 CEST49739443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:04.904525042 CEST44349739207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:06.913140059 CEST49740443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:06.913193941 CEST44349740207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:06.913286924 CEST49740443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:06.913554907 CEST49740443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:06.913567066 CEST44349740207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:07.126566887 CEST44349740207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:07.128077984 CEST49740443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:07.128114939 CEST44349740207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:07.705099106 CEST44349740207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:07.705164909 CEST44349740207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:07.705225945 CEST49740443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:07.705729008 CEST49740443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:07.705746889 CEST44349740207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:07.706928968 CEST49741443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:07.706976891 CEST44349741207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:07.707082033 CEST49741443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:07.707321882 CEST49741443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:07.707333088 CEST44349741207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:09.031898975 CEST44349741207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:09.033467054 CEST49741443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:09.033503056 CEST44349741207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:09.235851049 CEST44349741207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:09.235920906 CEST44349741207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:09.236077070 CEST49741443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:09.236553907 CEST49741443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:09.236574888 CEST44349741207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:11.241369963 CEST49744443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:11.241419077 CEST44349744207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:11.241590023 CEST49744443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:11.241842985 CEST49744443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:11.241852999 CEST44349744207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:11.885459900 CEST44349744207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:11.886964083 CEST49744443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:11.886980057 CEST44349744207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.102662086 CEST44349744207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.102716923 CEST44349744207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.102787971 CEST49744443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.103239059 CEST49744443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.103254080 CEST44349744207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.104262114 CEST49745443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.104300022 CEST44349745207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.104367971 CEST49745443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.104643106 CEST49745443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.104655981 CEST44349745207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.319545984 CEST44349745207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.321274042 CEST49745443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.321300983 CEST44349745207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.907711029 CEST44349745207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.907780886 CEST44349745207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:12.907838106 CEST49745443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.908348083 CEST49745443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:12.908365965 CEST44349745207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:14.913203955 CEST49746443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:14.913254023 CEST44349746207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:14.913363934 CEST49746443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:14.913831949 CEST49746443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:14.913844109 CEST44349746207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.535664082 CEST44349746207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.537362099 CEST49746443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:15.537377119 CEST44349746207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.753870964 CEST44349746207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.753940105 CEST44349746207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.754120111 CEST49746443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:15.754465103 CEST49746443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:15.754481077 CEST44349746207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.755620003 CEST49747443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:15.755649090 CEST44349747207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.755810976 CEST49747443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:15.756059885 CEST49747443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:15.756072044 CEST44349747207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.969257116 CEST44349747207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:15.970786095 CEST49747443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:15.970803976 CEST44349747207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:16.177592993 CEST44349747207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:16.177663088 CEST44349747207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:16.177824974 CEST49747443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:16.178272009 CEST49747443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:16.178292036 CEST44349747207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:18.196717978 CEST49750443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:18.196763039 CEST44349750207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:18.197010994 CEST49750443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:18.197283030 CEST49750443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:18.197299004 CEST44349750207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:20.975414038 CEST44349750207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:20.978137016 CEST49750443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:20.978152037 CEST44349750207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:21.180007935 CEST44349750207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:21.180061102 CEST44349750207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:21.180107117 CEST49750443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:21.180677891 CEST49750443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:21.180692911 CEST44349750207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:21.182159901 CEST49752443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:21.182198048 CEST44349752207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:21.182265997 CEST49752443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:21.182636976 CEST49752443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:21.182650089 CEST44349752207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:22.426817894 CEST44349752207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:22.454670906 CEST49752443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:22.454699993 CEST44349752207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:22.971255064 CEST44349752207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:22.971313953 CEST44349752207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:22.971358061 CEST49752443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:22.971980095 CEST49752443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:22.971995115 CEST44349752207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:24.851037025 CEST49755443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:24.851082087 CEST44349755207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:24.851139069 CEST49755443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:24.851588964 CEST49755443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:24.851597071 CEST44349755207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.072901964 CEST44349755207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.114808083 CEST49755443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.156610966 CEST49755443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.156625986 CEST44349755207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.286732912 CEST44349755207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.286793947 CEST44349755207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.286842108 CEST49755443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.370594025 CEST49755443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.370635986 CEST44349755207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.375230074 CEST49756443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.375281096 CEST44349756207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.375340939 CEST49756443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.379383087 CEST49756443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.379411936 CEST44349756207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.596996069 CEST44349756207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.598440886 CEST49756443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.598490000 CEST44349756207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.814085007 CEST44349756207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.814171076 CEST44349756207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:25.814785957 CEST49756443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.815169096 CEST49756443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:25.815181017 CEST44349756207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:27.569675922 CEST49758443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:27.569741011 CEST44349758207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:27.569998980 CEST49758443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:27.574244022 CEST49758443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:27.574259996 CEST44349758207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.429446936 CEST44349758207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.431225061 CEST49758443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:28.431258917 CEST44349758207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.635179043 CEST44349758207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.635256052 CEST44349758207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.635313034 CEST49758443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:28.635814905 CEST49758443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:28.635832071 CEST44349758207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.637154102 CEST49759443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:28.637191057 CEST44349759207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.637254000 CEST49759443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:28.637578964 CEST49759443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:28.637588978 CEST44349759207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.845272064 CEST44349759207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:28.846630096 CEST49759443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:28.846642017 CEST44349759207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:29.059205055 CEST44349759207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:29.059269905 CEST44349759207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:29.059318066 CEST49759443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:29.059901953 CEST49759443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:29.059919119 CEST44349759207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:30.694547892 CEST49760443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:30.694602966 CEST44349760207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:30.694674969 CEST49760443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:30.694988966 CEST49760443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:30.695002079 CEST44349760207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:31.918390989 CEST44349760207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:31.922858953 CEST49760443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:31.922882080 CEST44349760207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.126728058 CEST44349760207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.126780033 CEST44349760207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.131742001 CEST49760443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.134161949 CEST49760443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.134183884 CEST44349760207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.142563105 CEST49761443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.142612934 CEST44349761207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.142868042 CEST49761443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.146764040 CEST49761443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.146791935 CEST44349761207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.353912115 CEST44349761207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.355129957 CEST49761443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.355149031 CEST44349761207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.868926048 CEST44349761207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.868995905 CEST44349761207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:32.869056940 CEST49761443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.869560003 CEST49761443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:32.869591951 CEST44349761207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.398178101 CEST49763443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.398277044 CEST44349763207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.401326895 CEST49763443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.404181957 CEST49763443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.404196024 CEST44349763207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.612169027 CEST44349763207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.645239115 CEST49763443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.645265102 CEST44349763207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.826386929 CEST44349763207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.826438904 CEST44349763207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.826520920 CEST49763443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.831779957 CEST49763443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.831794024 CEST44349763207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.844707012 CEST49764443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.844744921 CEST44349764207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:34.844882011 CEST49764443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.845165968 CEST49764443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:34.845179081 CEST44349764207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:35.693021059 CEST44349764207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:35.694576979 CEST49764443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:35.694607973 CEST44349764207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:35.906373024 CEST44349764207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:35.906435013 CEST44349764207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:35.906485081 CEST49764443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:35.906889915 CEST49764443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:35.906903982 CEST44349764207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:37.336097002 CEST49765443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:37.336148977 CEST44349765207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:37.336275101 CEST49765443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:37.336548090 CEST49765443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:37.336565971 CEST44349765207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:38.668046951 CEST44349765207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:38.671497107 CEST49765443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:38.671526909 CEST44349765207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.007731915 CEST44349765207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.007788897 CEST44349765207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.008241892 CEST49765443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.008338928 CEST49765443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.008357048 CEST44349765207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.012168884 CEST49767443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.012212992 CEST44349767207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.016335964 CEST49767443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.020270109 CEST49767443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.020282984 CEST44349767207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.650726080 CEST44349767207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.652306080 CEST49767443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.652333021 CEST44349767207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.858023882 CEST44349767207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.858088970 CEST44349767207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:39.858133078 CEST49767443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.858568907 CEST49767443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:39.858581066 CEST44349767207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:41.194160938 CEST49768443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:41.194197893 CEST44349768207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:41.194586992 CEST49768443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:41.194586992 CEST49768443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:41.194612980 CEST44349768207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:41.417588949 CEST44349768207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:41.419118881 CEST49768443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:41.419131041 CEST44349768207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:42.014833927 CEST44349768207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:42.014892101 CEST44349768207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:42.014955044 CEST49768443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:42.015381098 CEST49768443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:42.015398026 CEST44349768207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:42.016611099 CEST49769443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:42.016638041 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:42.016705036 CEST49769443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:42.016988039 CEST49769443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:42.016994953 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:42.657571077 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:42.661616087 CEST49769443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:42.661642075 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:43.190596104 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:43.190658092 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:43.191113949 CEST49769443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:43.191126108 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:43.396267891 CEST44349769207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:43.396342993 CEST49769443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:44.428711891 CEST49770443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:44.428749084 CEST44349770207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:44.428812027 CEST49770443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:44.429151058 CEST49770443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:44.429164886 CEST44349770207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.302228928 CEST44349770207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.304193974 CEST49770443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.304209948 CEST44349770207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.516383886 CEST44349770207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.516441107 CEST44349770207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.516495943 CEST49770443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.516921997 CEST49770443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.516940117 CEST44349770207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.518096924 CEST49771443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.518130064 CEST44349771207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.518199921 CEST49771443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.518548012 CEST49771443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.518556118 CEST44349771207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.728529930 CEST44349771207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.730240107 CEST49771443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.730252028 CEST44349771207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.945183992 CEST44349771207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.945293903 CEST44349771207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:45.945410013 CEST49771443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.945811987 CEST49771443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:45.945831060 CEST44349771207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:47.100290060 CEST49773443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:47.100325108 CEST44349773207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:47.101311922 CEST49773443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:47.101716042 CEST49773443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:47.101730108 CEST44349773207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:48.335457087 CEST44349773207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:48.351535082 CEST49773443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:48.351638079 CEST44349773207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:48.351696968 CEST49773443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:49.446146965 CEST49775443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:49.446175098 CEST44349775207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:49.446438074 CEST49775443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:49.446726084 CEST49775443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:49.446733952 CEST44349775207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:53.242016077 CEST44349775207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:53.242113113 CEST49775443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:54.781651020 CEST49775443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:54.781671047 CEST44349775207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:54.782033920 CEST44349775207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:54.785893917 CEST49775443192.168.2.7207.174.26.219
                                            Mar 30, 2025 18:05:54.785943031 CEST44349775207.174.26.219192.168.2.7
                                            Mar 30, 2025 18:05:54.785999060 CEST49775443192.168.2.7207.174.26.219
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 30, 2025 18:04:17.558356047 CEST6403853192.168.2.71.1.1.1
                                            Mar 30, 2025 18:04:17.664057016 CEST53640381.1.1.1192.168.2.7
                                            Mar 30, 2025 18:04:54.561300993 CEST5363077162.159.36.2192.168.2.7
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Mar 30, 2025 18:04:17.558356047 CEST192.168.2.71.1.1.10x661eStandard query (0)i.ibb.coA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Mar 30, 2025 18:04:17.664057016 CEST1.1.1.1192.168.2.70x661eNo error (0)i.ibb.co207.174.26.219A (IP address)IN (0x0001)false
                                            • i.ibb.co
                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            0192.168.2.749684207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:17 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            1192.168.2.749685207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:18 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            2192.168.2.749687207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:20 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            3192.168.2.749688207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:21 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            4192.168.2.749689207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:24 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            5192.168.2.749690207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:24 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            6192.168.2.749693207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:27 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            7192.168.2.749694207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:28 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            8192.168.2.749701207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:31 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            9192.168.2.749702207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:32 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            10192.168.2.749704207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:34 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            11192.168.2.749705207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:35 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            12192.168.2.749710207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:39 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            13192.168.2.749713207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:40 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            14192.168.2.749717207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:42 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            15192.168.2.749718207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:43 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            16192.168.2.749720207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:45 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            17192.168.2.749722207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:46 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            18192.168.2.749724207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:48 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            19192.168.2.749725207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:49 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            20192.168.2.749726207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:51 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            21192.168.2.749727207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:52 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            22192.168.2.749730207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:55 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            23192.168.2.749731207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:56 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            24192.168.2.749734207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:04:58 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            25192.168.2.749735207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:00 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            26192.168.2.749738207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:02 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            27192.168.2.749739207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:04 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            28192.168.2.749740207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:07 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            29192.168.2.749741207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:09 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            30192.168.2.749744207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:11 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            31192.168.2.749745207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:12 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            32192.168.2.749746207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:15 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            33192.168.2.749747207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:15 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            34192.168.2.749750207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:20 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            35192.168.2.749752207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:22 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            36192.168.2.749755207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:25 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            37192.168.2.749756207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:25 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            38192.168.2.749758207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:28 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            39192.168.2.749759207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:28 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            40192.168.2.749760207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:31 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            41192.168.2.749761207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:32 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            42192.168.2.749763207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:34 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            43192.168.2.749764207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:35 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            44192.168.2.749765207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:38 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            45192.168.2.749767207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:39 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            46192.168.2.749768207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:41 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            47192.168.2.749769207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:42 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            48192.168.2.749770207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:45 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            49192.168.2.749771207.174.26.2194436276C:\Users\user\Desktop\WizClient.exe
                                            TimestampBytes transferredDirectionData
                                            2025-03-30 16:05:45 UTC75OUTGET /Dwrj41N/Image.png HTTP/1.1
                                            Host: i.ibb.co
                                            Connection: Keep-Alive


                                            050100s020406080100

                                            Click to jump to process

                                            050100s0.0010203040MB

                                            Click to jump to process

                                            • File
                                            • Registry
                                            • Network

                                            Click to dive into process behavior distribution

                                            Click to jump to process

                                            Target ID:0
                                            Start time:12:04:07
                                            Start date:30/03/2025
                                            Path:C:\Users\user\Desktop\WizClient.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Users\user\Desktop\WizClient.exe"
                                            Imagebase:0x7d0000
                                            File size:31'232 bytes
                                            MD5 hash:51DC79AC2451E7AD8809D28EE07602B4
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: 00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                            • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: 00000000.00000000.934418415.00000000007D2000.00000002.00000001.01000000.00000003.sdmp, Author: ditekSHen
                                            Reputation:low
                                            Has exited:true
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                            Target ID:13
                                            Start time:12:05:49
                                            Start date:30/03/2025
                                            Path:C:\Windows\System32\WerFault.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\WerFault.exe -u -p 6276 -s 2280
                                            Imagebase:0x7ff612c70000
                                            File size:570'736 bytes
                                            MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high
                                            Has exited:true
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                                            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                                            Executed Functions

                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 229de08d9d26d16a57897b9eef0eabbfb33f14446597d0d4c58cfbd5e299e640
                                            • Instruction ID: 56b569fa8c0439ec14376d08f21fbb2c71e493d6568d5fcb86e0da74c794d536
                                            • Opcode Fuzzy Hash: 229de08d9d26d16a57897b9eef0eabbfb33f14446597d0d4c58cfbd5e299e640
                                            • Instruction Fuzzy Hash: 3B9148B1A1CA898FE369DB78C8552BD7BD5EF95715F0401BEE04DC72D2DE246842CB80
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: N_^
                                            • API String ID: 0-884294832
                                            • Opcode ID: 0afacb9b35194cf5938334e57ad09c5f04fb8c9fbfe92be6cabb9b887c3e9fdf
                                            • Instruction ID: 69cab648228e8940c65467609f8c64d2ba3a5210e88058c827d198a5c0806c52
                                            • Opcode Fuzzy Hash: 0afacb9b35194cf5938334e57ad09c5f04fb8c9fbfe92be6cabb9b887c3e9fdf
                                            • Instruction Fuzzy Hash: 71813CE1B1CA4A4FE7A8EB7CC4552BD7AD1EFA8714B5405BDD04DD32C7DD2868028781
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: b7d4164622240614ecc011b3f47e786b460b0000fc3a00bce7b17f6f3bf34e2a
                                            • Instruction ID: 34ce9bb273d9f825550e6fe25fdd0bee992b4df4b555344b4e332939d9ea03f3
                                            • Opcode Fuzzy Hash: b7d4164622240614ecc011b3f47e786b460b0000fc3a00bce7b17f6f3bf34e2a
                                            • Instruction Fuzzy Hash: A7A16CA1A1CA8A0FE759977CC8552AD7FD1EFA5764F5401FDD089C32C7CD2868038781
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 767f2b933079aaeec6500bf577280a41b6ddabe362cb92636cc5631444487c1b
                                            • Instruction ID: d0381e22df56b76d21d522df35a3874e8698114f435dcb0a5737d83c2795fdbd
                                            • Opcode Fuzzy Hash: 767f2b933079aaeec6500bf577280a41b6ddabe362cb92636cc5631444487c1b
                                            • Instruction Fuzzy Hash: A4811CE1B18A0A0FE798EB7CC4552BD7BD5EFA8754B5405BDD04ED32C6DD286C028781
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: be6f3db4f25dd174feda8e35bc1987e3c8ca604f9e37d3f40a2fcb5b18595193
                                            • Instruction ID: 2c9b0d749e7368f2dbcc64da5f35eb1d8c46ded9c4ca583a12af6137b3b6e039
                                            • Opcode Fuzzy Hash: be6f3db4f25dd174feda8e35bc1987e3c8ca604f9e37d3f40a2fcb5b18595193
                                            • Instruction Fuzzy Hash: BF61F4B1D0C6498FD759DB78C855AB8BBE4EF66320F0841BBD048C71D3DA29A846CB91
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 1cfd02f5c85b396d38f37416f658dbd15c84fd71291eac9b7603bf2e2ccbe5a4
                                            • Instruction ID: 6ad6bf9edcca0174af718d030d719439d1df4d10d7546e592377b132bed55c7b
                                            • Opcode Fuzzy Hash: 1cfd02f5c85b396d38f37416f658dbd15c84fd71291eac9b7603bf2e2ccbe5a4
                                            • Instruction Fuzzy Hash: A8513AA2B0C6850FE354EBBCD8692B87BC1EF85214B0840FFE08DC71E7DD18A8468385
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 755be6e727317fecb98330390a3da9de0967c91b532b5489d18951bc5f9abde6
                                            • Instruction ID: b824b9ffa57bae9da1dd9ec988f9d1683365a9d13fb0ca56af548e96c3589316
                                            • Opcode Fuzzy Hash: 755be6e727317fecb98330390a3da9de0967c91b532b5489d18951bc5f9abde6
                                            • Instruction Fuzzy Hash: E4515A61B1CA860FE7A6A778C8565797FD1DF96620B0840FAD48DC32D3DC1CAC438791
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 22e2e33bed19b419499a5c876049494beae94a6c1f1a72a797deeedb445e8ca4
                                            • Instruction ID: dd31f829ad826298853e0f173fda9533fa77799531c354bca17b95c1de8e0316
                                            • Opcode Fuzzy Hash: 22e2e33bed19b419499a5c876049494beae94a6c1f1a72a797deeedb445e8ca4
                                            • Instruction Fuzzy Hash: E3517BA1A28A4E1FE7A8FB78C8595BD7BA1FF54760B4045BDD04EC31CBDD68A8018780
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: b44c0c5b1224ed07c66e9cf395880d023417061debc99f615bffd49ab8c060f9
                                            • Instruction ID: d95049b16a2d12c9e7dc9b5aa4be01fe61deb0be42b2b509827fcd749751e8e7
                                            • Opcode Fuzzy Hash: b44c0c5b1224ed07c66e9cf395880d023417061debc99f615bffd49ab8c060f9
                                            • Instruction Fuzzy Hash: D741E6A1B1CA894FD798AB7C8869275BBD5DF9A215F0801FEE08DC32D7CD189C46C345
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: cf4af0d0b0f8a0058f59e8a0e30fe6f56565fbe9933c79945a82f39258e36c85
                                            • Instruction ID: a5cda99176c2db3bca42233ab5f3113e04f64ceba4166017d5712d9b143b06e0
                                            • Opcode Fuzzy Hash: cf4af0d0b0f8a0058f59e8a0e30fe6f56565fbe9933c79945a82f39258e36c85
                                            • Instruction Fuzzy Hash: 294182B4908A1C8FDB68EF68D459BA9BBE0FF65311F0042AED44AD3691CB35A841CB41
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: d3d4522fecfb4f153c70c9a3d008663ac06c0bab824b5c21fc7d146d1e8f06ec
                                            • Instruction ID: 224e216628cb43ad686743033deb4a072ec89e1dec9c5e7c1704db134a3e4eef
                                            • Opcode Fuzzy Hash: d3d4522fecfb4f153c70c9a3d008663ac06c0bab824b5c21fc7d146d1e8f06ec
                                            • Instruction Fuzzy Hash: 384182B460891C8FEB68EF68D495BA9BBE5FB64711F0001BED40AD3691CB75E841CB80
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: a6546cb9c278f26fd486709182fd2cc3e5abaf9e092868a3b1493b5ff1cdbd8c
                                            • Instruction ID: 1fac166b4cd389dd0a846dc3048d4824e98bea4428e6588978bb82534551f870
                                            • Opcode Fuzzy Hash: a6546cb9c278f26fd486709182fd2cc3e5abaf9e092868a3b1493b5ff1cdbd8c
                                            • Instruction Fuzzy Hash: 8A31D5A1B189494FE798EB7CC85A279B7C6EF99715F0401BEE04EC32D7CD189C428345
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: e96a1cd642f74330ec052cc691479a36612f8cf46597f8536e7acb4d2ac4a253
                                            • Instruction ID: a6818c0004588fae04f4695a6cc04c50258e91ab3240374a8b73198f7fdcb3a7
                                            • Opcode Fuzzy Hash: e96a1cd642f74330ec052cc691479a36612f8cf46597f8536e7acb4d2ac4a253
                                            • Instruction Fuzzy Hash: CF31E791B18A0A4FE744BBFCDC593BD7AD5EF98751F0441BAE00CC32D6DE18A8418781
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 6e30326610a0d7c9f4547d13c63a99f5ccaa70bfc14ad58b9e83a9149244a4da
                                            • Instruction ID: 0ab387b532475b8d7429ccdf34d976ccbc62fa19a3a3356768f4e775aa7c5224
                                            • Opcode Fuzzy Hash: 6e30326610a0d7c9f4547d13c63a99f5ccaa70bfc14ad58b9e83a9149244a4da
                                            • Instruction Fuzzy Hash: 9E4194B4A18A0E9FD744EBB8C8956FD7BB1FF88310F504579D149D32CACD2868418B90
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: b8a9cbb7530af588dfb4b262e45aa4778ccde60bd9b7af68a2f2fe0a0c406336
                                            • Instruction ID: 907612942e792a0c1c78bbb1756846e55c2a7c1a3c26800f7e4561a6a2adc3aa
                                            • Opcode Fuzzy Hash: b8a9cbb7530af588dfb4b262e45aa4778ccde60bd9b7af68a2f2fe0a0c406336
                                            • Instruction Fuzzy Hash: 182109E1E0C6034BF7A4A778C45627D3A96AFA0710F5450F9D00DC71C7DE6CA8434785
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: d8e8b55c0f8bf837ca4cbe90663d3a73cadb65283f9b24d9a291a5632356dcd1
                                            • Instruction ID: b071d9892bfe8932191173db8f5953e3d0d2fd3f03fd77789f1c0f916dcb5af9
                                            • Opcode Fuzzy Hash: d8e8b55c0f8bf837ca4cbe90663d3a73cadb65283f9b24d9a291a5632356dcd1
                                            • Instruction Fuzzy Hash: 891120F1958A8E9FE388DB3888961B93FF1EBA4212B4441FFC849D3695CA3011018780
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 2ae83ba676c1168a1803a0d607dfec81aeeef79ab134d5ab810a4e91d1e9359a
                                            • Instruction ID: 03ddb4adb5b2e02e5cdfc2d973bb8030f9a053d564bd48fc63beeacd4e918615
                                            • Opcode Fuzzy Hash: 2ae83ba676c1168a1803a0d607dfec81aeeef79ab134d5ab810a4e91d1e9359a
                                            • Instruction Fuzzy Hash: 1B0149A2F1CD560BE769A3BCA4650FCA7C1DF58660B0841BDD05EC31C7CE59A8425789
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: f9d9ebfd2567ddcf4cc333c9db8f63aacbb106272c47f0b263ad18a2e842deb8
                                            • Instruction ID: 1a6c46b348825030d74bac0d1b741a94437a7cc4fb68ff0f0c1928d492319e3f
                                            • Opcode Fuzzy Hash: f9d9ebfd2567ddcf4cc333c9db8f63aacbb106272c47f0b263ad18a2e842deb8
                                            • Instruction Fuzzy Hash: 4A01ADD0E0D6864FF7A4A378C46A27C3E95EFA4604F4411F9D04AC79C7EE5CA8428745
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 40f34c9a13aa9e426ce26f5bf8a249337bb4ea370831410cb64fadbe7ab7888e
                                            • Instruction ID: 32c1b4bd80c84660bad9e79bec5061d15dba5266f0d3f2e42809afaccebd2a30
                                            • Opcode Fuzzy Hash: 40f34c9a13aa9e426ce26f5bf8a249337bb4ea370831410cb64fadbe7ab7888e
                                            • Instruction Fuzzy Hash: 99E092B120C51C5FDB54FB65EC4EAEA3B6CFB81335F00112FE80EC2142E525A126C7A1
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: e6e393bed137ef7733aaa9029c4900fe6e3c9feaf9c6ffa7691916047df5c3b9
                                            • Instruction ID: 9035ba9a2ef6a2dea02faad8ab94ca2ea150da267af5731fc3c3f019059d854a
                                            • Opcode Fuzzy Hash: e6e393bed137ef7733aaa9029c4900fe6e3c9feaf9c6ffa7691916047df5c3b9
                                            • Instruction Fuzzy Hash: 57F049E4D0C5168BF375E774C54927D7AAAAFA1B20F9096B8D01DC31D2DE28B8538A80
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: f84d8e6657066afb7a2dad7ea631b2fe1a2771d3ac37f672c3414afdbf81864e
                                            • Instruction ID: 8d0310508247d7da8954cf7b1ce2e29b0c3a3374ee59dc3ab2d82fc34f49871b
                                            • Opcode Fuzzy Hash: f84d8e6657066afb7a2dad7ea631b2fe1a2771d3ac37f672c3414afdbf81864e
                                            • Instruction Fuzzy Hash: 76D0C780C0E2C20BE32B23B40C829847F288E132A0B9942E2D480C70D3E88D249B8372
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.2000127391.00007FFB9AA60000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFB9AA60000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ffb9aa60000_WizClient.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 028b367c0bcd80a34a834283f7117496f09d4f6f892adb74ea87f37949aafd97
                                            • Instruction ID: 8ee7554561b7a9dd2935af00434e2e08fb75d2b21f76124181c9ad90578711c7
                                            • Opcode Fuzzy Hash: 028b367c0bcd80a34a834283f7117496f09d4f6f892adb74ea87f37949aafd97
                                            • Instruction Fuzzy Hash: B6D02B72C2938D8FD7516B7084161DA7730FF84300F85069BE41C82051EF2462158792